CVE Tools

Adobe-systems-incorporated

143 CVEs tracked since 2017. Since Aug 2017, none of them reached CISA KEV.

Adobe-systems-incorporated CVEs per month

Aug 2017 to Nov 2019. Point at a month, or focus the strip and use the arrow keys.
Adobe-systems-incorporated CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-08790
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11640

Products

The products that kept showing up in Adobe-systems-incorporated's monthly top three, with their CVEs summed over those months.

  1. Acrobat Reader651 month
  2. Magento 2521 month
  3. Digital Editions91 month
  4. Magento 181 month
  5. Experience Manager31 month
  6. Magento 1 & 231 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Adobe-systems-incorporated.

  1. CVE-2020-24445Cross-site Scripting Vulnerability in Commenting Function of Adobe Experience Manager (AEM)9.0
  2. CVE-2019-8132A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft malicious payload in the template Na...5.4
  3. CVE-2019-8145A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code into the ...5.4
  4. CVE-2019-8158An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rendering module that ...9.8
  5. CVE-2019-8157A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate downloadable link and cause an ...5.4
  6. CVE-2019-8156A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to modify store configu...7.2
  7. CVE-2019-8159A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with system data manipulation privileges can execute aribi...8.8
  8. CVE-2019-8227In Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code via import / export functionality when c...4.8
  9. CVE-2019-8228in Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code into transactional email page when creat...4.8
  10. CVE-2019-8229In Magento prior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit product attributes can execute arbitrary code through crafted layout updates.7.2
  11. CVE-2019-8230In Magentoprior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit configuration settings can execute arbitrary code through a crafted support/o...7.2
  12. CVE-2019-8231In Magento to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layout modification.7.2
  13. CVE-2019-8232In Magento prior to 1.9.4.3, Magento prior to 1.14.4.3, Magento 2.2 prior to 2.2.10, and Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an authenticated user with administrative privileges for the import ...6.6
  14. CVE-2019-8233In Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an unauthenticated user can inject arbitrary JavaScript code as a result of the sanitization engine ignoring HTML comments.6.1
  15. CVE-2019-8155Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to perform unauthorize...7.5

The record

Peak rank
#7 in Aug 2017
Busiest month shown
Aug 2017, 79 CVEs
Months with a KEV entry
0 since Aug 2017
Monthly snapshots
2 since 2017
Adobe-systems-incorporated's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store