Skip to content
Signals
NVD · CVE-2026-18907 · Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filenameNVD · CVE-2026-18897 · 8.8 · A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempENVD · CVE-2026-18896 · 6.3 · A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.phNVD · CVE-2026-18895 · 8.8 · A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-18907 · Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filenameNVD · CVE-2026-18897 · 8.8 · A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempENVD · CVE-2026-18896 · 6.3 · A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.phNVD · CVE-2026-18895 · 8.8 · A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · adobe

adobe

· 265 Critical

Total CVEs

7,265

Critical

265

Products

182

Search All CVEs →

7,265

Products (182)

acrobat dc1,795 CVEsacrobat reader dc1,795 CVEsacrobat1,379 CVEsexperience manager1,127 CVEsacrobat reader1,087 CVEsflash player1,084 CVEsair413 CVEsair sdk409 CVEsair sdk \& compiler365 CVEsreader359 CVEsflash player desktop runtime294 CVEscoldfusion221 CVEsindesign191 CVEscommerce191 CVEsexperience manager cloud service183 CVEsillustrator174 CVEsshockwave player174 CVEsmagento168 CVEsadobe air146 CVEsbridge144 CVEsafter effects125 CVEscommerce b2b118 CVEsframemaker118 CVEsdimension116 CVEsanimate102 CVEsadobe air sdk96 CVEsphotoshop92 CVEsair desktop runtime88 CVEssubstance 3d stager87 CVEssubstance 3d painter78 CVEsphotoshop cc77 CVEsconnect74 CVEsdigital editions71 CVEsincopy62 CVEsmedia encoder60 CVEssubstance 3d designer43 CVEsaudition42 CVEspremiere pro39 CVEssubstance 3d modeler39 CVEsflash player for android35 CVEsmagento open source32 CVEssubstance 3d sampler29 CVEsxmp toolkit software development kit28 CVEsphotoshop 202024 CVEscreative cloud24 CVEspremiere rush23 CVEsadobe commerce23 CVEsc2pa-web22 CVEsc2pa22 CVEsdreamweaver22 CVEsflash player for linux21 CVEsprelude20 CVEsrobohelp server17 CVEsrobohelp16 CVEscharacter animator15 CVEsflex15 CVEsdng software development kit15 CVEscreative cloud desktop application14 CVEspremiere elements14 CVEsbridge cc14 CVEsflash media server13 CVEsadobe air sdk and compiler13 CVEssubstance 3d viewer12 CVEscampaign12 CVEsformat plugins11 CVEsconnect desktop application11 CVEscommerce webhooks10 CVEsdigital negative software development kit9 CVEsexperience manager forms8 CVEsillustrator cc8 CVEslightroom8 CVEsphonegap8 CVEsflash media server 27 CVEsillustrator on ipad7 CVEsdownload manager7 CVEsi\/o events7 CVEsphotoshop elements6 CVEsillustrator cs5.56 CVEscaptivate6 CVEsjrun5 CVEspagemaker5 CVEsdocument server5 CVEsexperience manager screens5 CVEsgenuine service5 CVEslivecycle5 CVEslivecycle data services5 CVEsacrobat 3d4 CVEscreative suite4 CVEsacrobat reader 20174 CVEsversion cue4 CVEsphotoshop cs44 CVEsacrobat 20174 CVEsframemaker publishing server4 CVEsconnect enterprise server4 CVEsphotoshop cs5.53 CVEsacrobat xi3 CVEsblazeds3 CVEsreader xi3 CVEsadobe content server3 CVEsflex sdk3 CVEsbrackets3 CVEsdirector2 CVEsflash2 CVEsdng converter2 CVEscss-tools2 CVEsgolive2 CVEsxd2 CVEscontribute2 CVEsmagento commerce2 CVEscampaign classic2 CVEscamera raw2 CVEsphotoshop cs62 CVEspremiere2 CVEspresenter2 CVEsadobe reader2 CVEsstock api integration2 CVEslivecycle designer1 CVEslivecycle designer es21 CVEslivecycle es41 CVEslivecycle form manager1 CVEslivecycle workflow1 CVEscoldfusion builder1 CVEssvg-native-viewer1 CVEsdevice central cs41 CVEsmarketo sales insight1 CVEssvg viewer1 CVEsmedium1 CVEsonlocation cs41 CVEsops-cli1 CVEsform designer1 CVEspass authentication1 CVEspdf library sdk1 CVEsform client1 CVEsphotodeluxe1 CVEstechnical communications suite1 CVEsbreeze licensed server1 CVEsphotoshop 20211 CVEsphotoshop 20221 CVEsphotoshop 20231 CVEsphotoshop 20241 CVEsflex data services1 CVEsflex builder1 CVEsphotoshop cs51 CVEsphotoshop cs5.11 CVEsdevice central cs51 CVEsfireworks1 CVEsflash player installer1 CVEsphotoshop installer1 CVEsextendedscript toolkit cs51 CVEsprelude cc1 CVEspremier pro cs41 CVEsweb content management core components1 CVEspremiere clip1 CVEsapplication manager1 CVEsanimate cc1 CVEspremiere pro cc1 CVEspremiere pro cs41 CVEsanalytics appmeasurement for flash library1 CVEselicensing1 CVEspush notifications1 CVEsaero1 CVEsdispatcher1 CVEsexperience manager forms add-on1 CVEsadobe php ria sdk1 CVEsshockwave1 CVEsflash player extended support release1 CVEsextension manager cs51 CVEsstudio1 CVEsadobe consulting services commons1 CVEsacs aem commons1 CVEsflash cs5.51 CVEsflash cs41 CVEsacrobat business tools1 CVEsflash cs31 CVEsgraphics server1 CVEsindesign cs31 CVEsindesign cs41 CVEsindesign server1 CVEsgit-server1 CVEsxmp toolkit1 CVEsgenuine integrity service1 CVEsfreehand1 CVEs

Recent Vulnerabilities

View all 7,265
CVE-2026-48396HIGH 8.6

Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48395HIGH 8.6

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48394HIGH 7.8

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48393HIGH 7.8

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48392HIGH 7.8

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48391HIGH 8.2

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48390HIGH 8.2

Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48374HIGH 7.8

Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48334CRITICAL 9.3

Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48324CRITICAL 9.1

ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48319CRITICAL 9.1

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48358CRITICAL 9.1

Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48356CRITICAL 9.3

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

CVE-2026-47995HIGH 8.1

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

CVE-2026-47994HIGH 8.7

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

CVE-2026-48322CRITICAL 9.9

ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48321CRITICAL 9.3

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48320HIGH 8.5

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48284CRITICAL 9.6

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-47996MEDIUM 6.8

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A high-privileged attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-47988HIGH 8.6

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.

CVE-2026-47984HIGH 8.2

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction.

CVE-2026-47905MEDIUM 6.2

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

CVE-2026-47904MEDIUM 6.2

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

CVE-2026-47903MEDIUM 6.2

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.