Adobe Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Adobe products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
97
In CISA KEV
80
Beyond CISA KEV
17
Sensor Observed
2
Virtual Patch Available
2
Adobe KEVs Added by Year
97 Adobe KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2010-2883
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote... |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2011-0609
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on... |
Flash Player | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2011-2462
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through... |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2012-0754
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and... |
Flash Player | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2012-0767
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and... |
Flash Player | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2012-5054
Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute... |
Flash Player | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2018-4990
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free... |
Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2023-26360
Adobe ColdFusion Improper Access Control Arbitrary code execution |
ColdFusion | Confirmed | In CISA | 15 Mar 2023 |
|
CVE-2023-38205
ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298 |
ColdFusion | Confirmed | In CISA | 20 Jul 2023 |
|
CVE-2023-29298
Adobe ColdFusion Improper Access Control Security feature bypass |
ColdFusion | Confirmed | In CISA | 20 Jul 2023 |
|
CVE-2023-26359
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution |
ColdFusion | Confirmed | In CISA | 21 Aug 2023 |
|
CVE-2023-26369
[Google Project Zero] Adobe Acrobat DC OOBW 0-day actively exploited in the wild |
Acrobat Reader | Confirmed | In CISA | 14 Sep 2023 |
|
CVE-2023-21608
Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability |
Acrobat Reader | Confirmed | In CISA | 10 Oct 2023 |
|
CVE-2023-38203
Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE |
ColdFusion | Confirmed | In CISA | 08 Jan 2024 |
|
CVE-2023-29300
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution |
ColdFusion | Confirmed | In CISA | 08 Jan 2024 |
|
CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access |
Adobe Commerce | Confirmed | In CISA | 17 Jul 2024 |
|
CVE-2014-0497
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before... |
Flash Player | Confirmed | In CISA | 17 Sep 2024 |
|
CVE-2013-0643
The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x... |
Flash Player | Confirmed | In CISA | 17 Sep 2024 |
|
CVE-2013-0648
Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171... |
Flash Player | Confirmed | In CISA | 17 Sep 2024 |
|
CVE-2014-0502
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before... |
Flash Player | Confirmed | In CISA | 17 Sep 2024 |
|
CVE-2024-20767
ColdFusion | Improper Access Control (CWE-284) |
ColdFusion | Confirmed | In CISA | 16 Dec 2024 |
|
CVE-2017-3066
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization... |
Adobe ColdFusion ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier | Confirmed | In CISA | 24 Feb 2025 |
Common Vulnerability Classes (CWE)
- CWE-416 — Use After Free 15
- CWE-787 — Out-of-bounds Write 11
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 9
- CWE-502 — Deserialization of Untrusted Data 6
- CWE-190 — Integer Overflow or Wraparound 4
- CWE-284 — Improper Access Control 4
- CWE-20 — Improper Input Validation 4
- CWE-121 — Stack-based Buffer Overflow 3
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology