target entity

Adobe

80 source-linked records in the current knowledge graph.

high

CVE-2026-48282: Adobe ColdFusion Path Traversal Vulnerability

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-48282EPSS 28.6%AdobeColdFusion
CISA KEV ↗ · unattributed attribution
high

CVE-2009-3459: Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2009-3459EPSS 86.6%Acrobat and ReaderAdobe
CISA KEV ↗ · unattributed attribution
high

CVE-2020-9715: Adobe Acrobat Use-After-Free Vulnerability

Adobe Acrobat contains a use-after-free vulnerability that allows for code execution Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2020-9715EPSS 48.4%AcrobatAdobe
CISA KEV ↗ · unattributed attribution
high

CVE-2026-34621: Adobe Acrobat and Reader Prototype Pollution Vulnerability

Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-34621EPSS 7.1%Acrobat and ReaderAdobe
CISA KEV ↗ · unattributed attribution
high

CVE-2025-54236: Adobe Commerce and Magento Improper Input Validation Vulnerability

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-54236EPSS 96.7%AdobeCommerce and Magento
CISA KEV ↗ · unattributed attribution
high

CVE-2025-54253: Adobe Experience Manager Forms Code Execution Vulnerability

Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-54253EPSS 87.5%AdobeExperience Manager (AEM) Forms
CISA KEV ↗ · unattributed attribution
high

CVE-2017-3066: Adobe ColdFusion Deserialization Vulnerability

Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2017-3066EPSS 90.6%AdobeColdFusion
CISA KEV ↗ · unattributed attribution
high

CVE-2024-20767: Adobe ColdFusion Improper Access Control Vulnerability

Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-20767EPSS 98.5%AdobeColdFusion
CISA KEV ↗ · unattributed attribution
high

CVE-2014-0502: Adobe Flash Player Double Free Vulnerablity

Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVE-2014-0502EPSS 24.2%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2013-0648: Adobe Flash Player Code Execution Vulnerability

Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVE-2013-0648EPSS 11.1%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2013-0643: Adobe Flash Player Incorrect Default Permissions Vulnerability

Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVE-2013-0643EPSS 10.5%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2014-0497: Adobe Flash Player Integer Underflow Vulnerablity

Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVE-2014-0497EPSS 99.9%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2024-34102: Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-34102EPSS 100.0%AdobeCommerce and Magento Open Source
CISA KEV ↗ · unattributed attribution
high

CVE-2023-21608: Adobe Acrobat and Reader Use-After-Free Vulnerability

Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-21608EPSS 61.5%Acrobat and ReaderAdobe
CISA KEV ↗ · unattributed attribution
high

CVE-2012-5054: Adobe Flash Player Integer Overflow Vulnerability

Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2012-5054EPSS 21.2%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2012-0754: Adobe Flash Player Memory Corruption Vulnerability

Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2012-0754EPSS 92.0%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2011-0609: Adobe Flash Player Unspecified Vulnerability

Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2011-0609EPSS 66.8%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2010-1297: Adobe Flash Player Memory Corruption Vulnerability

Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2010-1297EPSS 82.4%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2009-1862: Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability

Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS). Required action: For Adobe Acrobat and Reader, apply updates per vendor instructions. For Adobe Flash Player, the impacted product is end-of-life and should be disconnected if still in use.

CVE-2009-1862EPSS 25.0%Acrobat and Reader, Flash PlayerAdobe
CISA KEV ↗ · unattributed attribution
high

CVE-2008-0655: Adobe Acrobat and Reader Unspecified Vulnerability

Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times. Required action: Apply updates per vendor instructions.

CVE-2008-0655EPSS 36.8%Acrobat and ReaderAdobe
CISA KEV ↗ · unattributed attribution
high

CVE-2007-5659: Adobe Acrobat and Reader Buffer Overflow Vulnerability

Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods. Required action: Apply updates per vendor instructions.

CVE-2007-5659EPSS 94.2%Acrobat and ReaderAdobe
CISA KEV ↗ · unattributed attribution
high

CVE-2015-0310: Adobe Flash Player ASLR Bypass Vulnerability

Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2015-0310EPSS 15.2%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2015-5123: Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2015-5123EPSS 18.5%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2015-5122: Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2015-5122EPSS 93.7%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2012-2034: Adobe Flash Player Memory Corruption Vulnerability

Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2012-2034EPSS 7.8%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2016-7855: Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2016-7855EPSS 25.2%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2016-4117: Adobe Flash Player Arbitrary Code Execution Vulnerability

An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2016-4117EPSS 94.4%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2015-5119: Adobe Flash Player Use-After-Free Vulnerability

A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2015-5119EPSS 99.3%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2015-3043: Adobe Flash Player Memory Corruption Vulnerability

A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2015-3043EPSS 79.8%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2012-1535: Adobe Flash Player Arbitrary Code Execution Vulnerability

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2012-1535EPSS 70.4%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2011-0611: Adobe Flash Player Remote Code Execution Vulnerability

Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2011-0611EPSS 99.4%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2021-28550: Adobe Acrobat and Reader Use-After-Free Vulnerability

Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. Required action: Apply updates per vendor instructions.

CVE-2021-28550EPSS 52.0%Acrobat and ReaderAdobe
CISA KEV ↗ · unattributed attribution