Adobe vendor intelligence
Adobe Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Adobe products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 100
- Known exploited vulnerabilities affecting Adobe products
- In CISA KEV
- 82
- Records also listed in the official catalog
- Beyond CISA KEV
- 18
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 6
- Adobe KEVs with sensor-observed exploitation activity
The catalog gap matters for Adobe exposure
Eighteen of the 100 exploited Adobe vulnerabilities tracked by Previdian are not in CISA KEV. Teams relying on the official catalog alone would miss 18% of this vendor portfolio.
- 82%
- Covered by CISA
- 18%
- Beyond CISA
- 26
- Product families
Attested Adobe vulnerabilities
100 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2013-0625
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute... |
ColdFusion | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2013-0629
Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified... |
ColdFusion | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2013-0631
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in... |
ColdFusion | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2009-0927
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute... |
Reader and Acrobat | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2010-2861
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read... |
ColdFusion | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2016-4171
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as... |
Flash Player | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2016-7892
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField... |
Adobe Flash Player 23.0.0.207 and earlier, 11.2.202.644 and earlier | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2012-2034
Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on... |
Flash Player | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2013-2729
Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary... |
Reader and Acrobat | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2014-9163
Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2015-0311
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2015-0313
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2015-3113
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2015-5122
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2015-5123
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2018-5002
Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to... |
Adobe Flash Player 29.0.0.171 and earlier versions | Confirmed | In CISA | 23 May 2022 |
|
CVE-2014-0546
Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and... |
Reader and Acrobat | Confirmed | In CISA | 25 May 2022 |
|
CVE-2014-8439
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before... |
Flash Player | Confirmed | In CISA | 25 May 2022 |
|
CVE-2015-8651
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux,... |
Flash Player | Confirmed | In CISA | 25 May 2022 |
|
CVE-2015-0310
Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly... |
Flash Player | Confirmed | In CISA | 25 May 2022 |
|
CVE-2016-0984
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before... |
Flash Player | Confirmed | In CISA | 25 May 2022 |
|
CVE-2016-1010
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on... |
Flash Player | Confirmed | In CISA | 25 May 2022 |
|
CVE-2007-5659
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long... |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2008-0655
Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors. |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2009-1862
Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87,... |
["Reader", "Acrobat", "Flash Player"] | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2009-3953
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote... |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2009-4324
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on... |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2010-1297
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and... |
Flash Player, AIR, Reader, Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2010-2883
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote... |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2011-0609
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on... |
Flash Player | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2011-2462
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through... |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2012-0754
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and... |
Flash Player | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2012-0767
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and... |
Flash Player | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2012-5054
Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute... |
Flash Player | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2018-4990
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free... |
Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2023-26360
Adobe ColdFusion Improper Access Control Arbitrary code execution |
ColdFusion | Confirmed | In CISA | 15 Mar 2023 |
|
CVE-2023-38205
ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298 |
ColdFusion | Confirmed | In CISA | 20 Jul 2023 |
|
CVE-2023-29298
Adobe ColdFusion Improper Access Control Security feature bypass |
ColdFusion | Confirmed | In CISA | 20 Jul 2023 |
|
CVE-2023-26359
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution |
ColdFusion | Confirmed | In CISA | 21 Aug 2023 |
|
CVE-2023-26369
[Google Project Zero] Adobe Acrobat DC OOBW 0-day actively exploited in the wild |
Acrobat Reader | Confirmed | In CISA | 14 Sep 2023 |
|
CVE-2023-21608
Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability |
Acrobat Reader | Confirmed | In CISA | 10 Oct 2023 |
|
CVE-2023-38203
Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE |
ColdFusion | Confirmed | In CISA | 08 Jan 2024 |
|
CVE-2023-29300
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution |
ColdFusion | Confirmed | In CISA | 08 Jan 2024 |
|
CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access |
Adobe Commerce | Confirmed | In CISA | 13 Jun 2024 |
|
CVE-2014-0497
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before... |
Flash Player | Confirmed | In CISA | 17 Sep 2024 |
|
CVE-2013-0643
The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x... |
Flash Player | Confirmed | In CISA | 17 Sep 2024 |
|
CVE-2013-0648
Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171... |
Flash Player | Confirmed | In CISA | 17 Sep 2024 |
|
CVE-2014-0502
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before... |
Flash Player | Confirmed | In CISA | 17 Sep 2024 |
|
CVE-2024-20767
ColdFusion | Improper Access Control (CWE-284) |
ColdFusion | Confirmed | In CISA | 16 Dec 2024 |
|
CVE-2017-3066
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization... |
Adobe ColdFusion ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier | Confirmed | In CISA | 24 Feb 2025 |
No Adobe vulnerabilities match this search or filter.
Showing 50 of 50 on this page (100 Adobe known exploited vulnerabilities).
Recurring weakness patterns
Use after free, out-of-bounds write, and restriction account for 35 mapped occurrences across this Adobe KEV portfolio.
CWE-416
Use After Free
CWE-787
Out-of-bounds Write
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CWE-502
Deserialization of Untrusted Data
CWE-284
Improper Access Control
CWE-190
Integer Overflow or Wraparound
CWE-20
Improper Input Validation
CWE-121
Stack-based Buffer Overflow