Adobe Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Adobe products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

97

In CISA KEV

80

Beyond CISA KEV

17

Sensor Observed

2

Virtual Patch Available

2

Adobe KEVs Added by Year

Loading...

97 Adobe KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2018-4939

Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data...

Confirmed In CISA 03 Nov 2021
CVE-2021-28550

Adobe Acrobat Reader use after free vulnerability could lead to arbitrary code execution

Confirmed In CISA 03 Nov 2021
CVE-2021-21017

Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution

Confirmed In CISA 03 Nov 2021
CVE-2018-15982

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to...

Confirmed In CISA 15 Feb 2022
CVE-2022-24086

Adobe Commerce checkout improper input validation leads to remote code execution

Confirmed In CISA 15 Feb 2022
CVE-2008-2992

Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that...

Confirmed In CISA 03 Mar 2022
CVE-2010-0188

Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service...

Confirmed In CISA 03 Mar 2022
CVE-2011-0611

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140;...

Confirmed In CISA 03 Mar 2022
CVE-2012-1535

Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote...

Confirmed In CISA 03 Mar 2022
CVE-2013-0632

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary...

Confirmed In CISA 03 Mar 2022
CVE-2013-0640

Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a...

Confirmed In CISA 03 Mar 2022
CVE-2013-0641

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute...

Confirmed In CISA 03 Mar 2022
CVE-2013-3346

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial...

Confirmed In CISA 03 Mar 2022
CVE-2014-0496

Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to...

Confirmed In CISA 03 Mar 2022
CVE-2015-3043

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers...

Confirmed In CISA 03 Mar 2022
CVE-2015-5119

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and...

Confirmed In CISA 03 Mar 2022
CVE-2015-7645

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote...

Confirmed In CISA 03 Mar 2022
CVE-2016-1019

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary...

Confirmed In CISA 03 Mar 2022
CVE-2016-4117

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in...

Confirmed In CISA 03 Mar 2022
CVE-2016-7855

Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers...

Confirmed In CISA 03 Mar 2022
CVE-2017-11292

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in...

Confirmed In CISA 03 Mar 2022
CVE-2009-3960

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0,...

Confirmed In CISA 07 Mar 2022
CVE-2013-0625

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute...

Confirmed In CISA 07 Mar 2022
CVE-2013-0629

Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified...

Confirmed In CISA 07 Mar 2022
CVE-2013-0631

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in...

Confirmed In CISA 07 Mar 2022

Common Vulnerability Classes (CWE)

  • CWE-416 — Use After Free 15
  • CWE-787 — Out-of-bounds Write 11
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 9
  • CWE-502 — Deserialization of Untrusted Data 6
  • CWE-190 — Integer Overflow or Wraparound 4
  • CWE-284 — Improper Access Control 4
  • CWE-20 — Improper Input Validation 4
  • CWE-121 — Stack-based Buffer Overflow 3

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology