Experience Manager Cloud Service
Vendor:
First CVE: Dec 10, 2020 · Active for 5 years
183
Total CVEs
More Total CVEs than 99% of tracked products
45.8
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Experience Manager Cloud Service over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 10, 2020
5 years ago
Most Recent CVE
Dec 15, 2023
955 days ago
CVE Severity & Scoring
Experience Manager Cloud Service183 CVEs
98%
All CVEs352,727 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network183 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low182 (99.5%)
High1 (0.5%)
Unknown0 (0.0%)
User Interaction
None5 (2.7%)
Unknown0 (0.0%)
Required178 (97.3%)
Privileges Required
Low175 (95.6%)
High0 (0.0%)
None8 (4.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (183 CVEs).
183 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40722CRITICAL AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker t | Jan 13, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-24445CRITICAL AEM's Cloud Service offering, as well as version 6.5.6.0 (and below), are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to injec | Dec 10, 2020 | 9.0 | 28 | NO | NO |
CVE-2021-21083HIGH AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by an Improper Access Control vulnerability. An unau | Jun 28, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-43762MEDIUM AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a dispatcher bypass vulnerability that could be abused to evade security controls. Sensitive a | Jan 13, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-44510MEDIUM Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim | Dec 22, 2022 | 5.4 | 21 | NO | NO |
CVE-2022-44463MEDIUM Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim | Dec 19, 2022 | 5.4 | 21 | NO | NO |
CVE-2021-44178MEDIUM AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a reflected Cross-Site Scripting (XSS) vulnerability via the itemResourceType parameter. If an | Jan 13, 2022 | 6.1 | 21 | NO | NO |
CVE-2021-44177MEDIUM AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to injec | Jan 13, 2022 | 6.1 | 21 | NO | NO |
CVE-2021-44176MEDIUM AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to injec | Jan 13, 2022 | 6.1 | 21 | NO | NO |
CVE-2021-43765MEDIUM AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to injec | Jan 13, 2022 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (183 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (183 CVEs).
Media Mentions
Signals from CVEs in this product scope (183 CVEs).
Top CNAs Publishing CVEs For Experience Manager Cloud Service
Top CWEs
Versions
No cataloged versions.