Adobe Systems Incorporated

First CVE: Oct 13, 2009Active for: 17 years
7,256
CVEs Published
More CVEs Published than 98% of tracked CNAs
403.1
Avg CVEs / Year
More Avg CVEs / Year than 97% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 65% of tracked CNAs
1.0%
In CISA KEV
Higher KEV Rate than 88% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Adobe Systems Incorporated as a CNA, 97.7% affect products that Adobe Systems Incorporated develops as a vendor.

97.7%
Self-reported: 7,087Third-party: 169

Of all the CVEs published that affect products developed by Adobe Systems Incorporated, 95.4% are self-published by Adobe Systems Incorporated as a CNA.

95.4%
Self-published: 7,087Published by other CNAs: 339

Trends Over Time

The number and severity of CVEs published by Adobe Systems Incorporated over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 13, 2009
16 years ago
Most Recent CVE
Jul 20, 2026
4 days ago

Top CVEs

All CVEs published by Adobe Systems Incorporated as a CNA, regardless of affected vendor or product.

7,256 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation
Sep 25, 20189.899YESYES
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parame
Aug 11, 20109.899YESYES
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attac
Sep 9, 20259.198YESYES
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could re
Jun 13, 20249.898YESYES
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage
Mar 18, 20247.498YESYES
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could
Jul 12, 20239.898YESYES
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code
Mar 23, 20239.898YESYES
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of th
Feb 16, 20229.898YESYES
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
May 11, 20169.898YESYES
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 1
Jul 14, 20159.898YESYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA7,256 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local2,460 (33.9%)
Network3,567 (49.2%)
Unknown1,203 (16.6%)
Physical4 (0.1%)
Adjacent Network22 (0.3%)
Attack Complexity
Low5,968 (82.2%)
High85 (1.2%)
Unknown1,203 (16.6%)
User Interaction
None1,417 (19.5%)
Unknown1,203 (16.6%)
Required4,636 (63.9%)
Privileges Required
Low1,273 (17.5%)
High215 (3.0%)
None4,565 (62.9%)
Unknown1,203 (16.6%)

Exploit Exposure

Signals from CVEs in this cna scope (7256 CVEs).

CISA KEV
74 CVEs
1.0% of CVEs· 88th percentile
Metasploit
48 CVEs
0.7% of CVEs· 84th percentile
Nuclei
25 CVEs
0.3% of CVEs· 73rd percentile
ExploitDB
251 CVEs
3.5% of CVEs· 92nd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Adobe Systems Incorporated as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Adobe Systems Incorporated as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs