Skip to content
Signals
Monitoring NVD, CISA KEV, EPSS and the Dragons Community ransomware tracker in near-real timeMonitoring NVD, CISA KEV, EPSS and the Dragons Community ransomware tracker in near-real time

Vendors · adobe

adobe

· 257 Critical

Total CVEs

7,242

Critical

257

Products

180

Search All CVEs →

7,242

Products (180)

acrobat reader dc1,795 CVEsacrobat dc1,795 CVEsacrobat1,379 CVEsexperience manager1,127 CVEsacrobat reader1,087 CVEsflash player1,084 CVEsair413 CVEsair sdk409 CVEsair sdk \& compiler365 CVEsreader359 CVEsflash player desktop runtime294 CVEscoldfusion215 CVEsindesign191 CVEscommerce184 CVEsexperience manager cloud service183 CVEsshockwave player174 CVEsillustrator173 CVEsmagento161 CVEsadobe air146 CVEsbridge136 CVEsafter effects125 CVEsframemaker118 CVEsdimension116 CVEscommerce b2b111 CVEsanimate102 CVEsadobe air sdk96 CVEsphotoshop92 CVEsair desktop runtime88 CVEssubstance 3d stager87 CVEssubstance 3d painter78 CVEsphotoshop cc77 CVEsconnect74 CVEsdigital editions71 CVEsincopy62 CVEsmedia encoder60 CVEssubstance 3d designer43 CVEsaudition42 CVEspremiere pro39 CVEssubstance 3d modeler39 CVEsflash player for android35 CVEsmagento open source32 CVEssubstance 3d sampler29 CVEsxmp toolkit software development kit28 CVEsphotoshop 202024 CVEscreative cloud24 CVEspremiere rush23 CVEsadobe commerce23 CVEsc2pa-web22 CVEsc2pa22 CVEsdreamweaver22 CVEsflash player for linux21 CVEsprelude20 CVEsrobohelp server17 CVEsrobohelp16 CVEscharacter animator15 CVEsflex15 CVEsdng software development kit15 CVEscreative cloud desktop application14 CVEspremiere elements14 CVEsbridge cc14 CVEsadobe air sdk and compiler13 CVEsflash media server13 CVEssubstance 3d viewer12 CVEscampaign12 CVEsformat plugins11 CVEsconnect desktop application11 CVEscommerce webhooks10 CVEsdigital negative software development kit9 CVEslightroom8 CVEsexperience manager forms8 CVEsillustrator cc8 CVEsphonegap8 CVEsillustrator on ipad7 CVEsdownload manager7 CVEsflash media server 27 CVEsillustrator cs5.56 CVEscaptivate6 CVEsphotoshop elements6 CVEsjrun5 CVEslivecycle data services5 CVEsexperience manager screens5 CVEspagemaker5 CVEslivecycle5 CVEsgenuine service5 CVEsdocument server5 CVEsconnect enterprise server4 CVEsphotoshop cs44 CVEscreative suite4 CVEsacrobat reader 20174 CVEsacrobat 20174 CVEsacrobat 3d4 CVEsversion cue4 CVEsframemaker publishing server4 CVEsflex sdk3 CVEsreader xi3 CVEsadobe content server3 CVEsblazeds3 CVEsacrobat xi3 CVEsphotoshop cs5.53 CVEsbrackets3 CVEsgolive2 CVEsdirector2 CVEscontribute2 CVEscss-tools2 CVEspresenter2 CVEscampaign classic2 CVEsxd2 CVEsphotoshop cs62 CVEscamera raw2 CVEsdng converter2 CVEsadobe reader2 CVEspremiere2 CVEsflash2 CVEsmagento commerce2 CVEsstock api integration2 CVEsphotoshop cs5.11 CVEsprelude cc1 CVEspremier pro cs41 CVEspremiere clip1 CVEsapplication manager1 CVEsanimate cc1 CVEspremiere pro cc1 CVEspremiere pro cs41 CVEsanalytics appmeasurement for flash library1 CVEspush notifications1 CVEsaero1 CVEsadobe php ria sdk1 CVEsshockwave1 CVEsstudio1 CVEsextendedscript toolkit cs51 CVEsacs aem commons1 CVEsacrobat business tools1 CVEssvg-native-viewer1 CVEssvg viewer1 CVEstechnical communications suite1 CVEsweb content management core components1 CVEsexperience manager forms add-on1 CVEsadobe consulting services commons1 CVEsextension manager cs51 CVEsfireworks1 CVEsflash cs31 CVEsflash cs41 CVEsflash cs5.51 CVEselicensing1 CVEsflash player extended support release1 CVEsdispatcher1 CVEsflash player installer1 CVEsflex builder1 CVEsflex data services1 CVEsform client1 CVEsform designer1 CVEsdevice central cs51 CVEsdevice central cs41 CVEsfreehand1 CVEsgenuine integrity service1 CVEsgit-server1 CVEsgraphics server1 CVEsxmp toolkit1 CVEsindesign cs31 CVEsindesign cs41 CVEsindesign server1 CVEslivecycle designer1 CVEslivecycle designer es21 CVEslivecycle es41 CVEslivecycle form manager1 CVEslivecycle workflow1 CVEscoldfusion builder1 CVEsmarketo sales insight1 CVEsmedium1 CVEsonlocation cs41 CVEsops-cli1 CVEspass authentication1 CVEspdf library sdk1 CVEsphotodeluxe1 CVEsbreeze licensed server1 CVEsphotoshop 20211 CVEsphotoshop 20221 CVEsphotoshop 20231 CVEsphotoshop 20241 CVEsphotoshop cs51 CVEs

Recent Vulnerabilities

View all 7,242
CVE-2026-47905MEDIUM 6.2

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

CVE-2026-47904MEDIUM 6.2

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

CVE-2026-47903MEDIUM 6.2

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

CVE-2026-47902MEDIUM 6.2

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

CVE-2026-34713HIGH 7.5

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

CVE-2026-34712HIGH 7.5

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

CVE-2026-34711HIGH 7.5

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

CVE-2026-34657MEDIUM 5.5

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in an arbitrary file system write. An attacker could leverage this vulnerability to write to unauthorized files or directories outside of intended restrictions. Exploitation of this issue requires user interaction in that a victim must extract a maliciously crafted file.

CVE-2026-48303CRITICAL 10.0

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48292HIGH 7.8

Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48291HIGH 7.8

Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-47961MEDIUM 5.5

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-47960HIGH 7.4

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-47959HIGH 7.8

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-47955HIGH 7.8

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-47952HIGH 7.8

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-47937HIGH 7.4

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-47933MEDIUM 4.8

ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

CVE-2026-47932HIGH 8.8

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-47931HIGH 8.4

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-47930HIGH 8.1

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction.

CVE-2026-47929HIGH 8.4

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-47928CRITICAL 9.6

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-47926MEDIUM 5.5

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-47925MEDIUM 5.5

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.