Adobe Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Adobe products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
97
In CISA KEV
80
Beyond CISA KEV
17
Sensor Observed
2
Virtual Patch Available
2
Adobe KEVs Added by Year
97 Adobe KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2018-4939
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data... |
Adobe ColdFusion ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-28550
Adobe Acrobat Reader use after free vulnerability could lead to arbitrary code execution |
Acrobat Reader | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-21017
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution |
Acrobat Reader | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2018-15982
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to... |
Flash Player | Confirmed | In CISA | 15 Feb 2022 |
|
CVE-2022-24086
Adobe Commerce checkout improper input validation leads to remote code execution |
Magento Commerce | Confirmed | In CISA | 15 Feb 2022 |
|
CVE-2008-2992
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that... |
Acrobat and Reader | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2010-0188
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service... |
Reader and Acrobat | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2011-0611
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140;... |
Flash Player, AIR, Reader, Acrobat | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2012-1535
Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote... |
Flash Player | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2013-0632
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary... |
ColdFusion | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2013-0640
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a... |
Reader and Acrobat | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2013-0641
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute... |
Reader and Acrobat | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2013-3346
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial... |
Reader and Acrobat | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2014-0496
Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to... |
Reader and Acrobat | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2015-3043
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers... |
Flash Player | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2015-5119
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and... |
Flash Player | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2015-7645
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote... |
Flash Player | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2016-1019
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary... |
Flash Player | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2016-4117
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in... |
Flash Player | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2016-7855
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers... |
Flash Player | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-11292
Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in... |
Adobe Flash Player version 27.0.0.159 and earlier | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2009-3960
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0,... |
BlazeDS | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2013-0625
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute... |
ColdFusion | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2013-0629
Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified... |
ColdFusion | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2013-0631
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in... |
ColdFusion | Confirmed | In CISA | 07 Mar 2022 |
Common Vulnerability Classes (CWE)
- CWE-416 — Use After Free 15
- CWE-787 — Out-of-bounds Write 11
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 9
- CWE-502 — Deserialization of Untrusted Data 6
- CWE-190 — Integer Overflow or Wraparound 4
- CWE-284 — Improper Access Control 4
- CWE-20 — Improper Input Validation 4
- CWE-121 — Stack-based Buffer Overflow 3
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology