Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2009-0927 | Adobe | Reader and Acrobat | Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code. | 8.8 CISA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2010-2861 | Adobe | ColdFusion | Adobe ColdFusion Directory Traversal Vulnerability A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files. | 9.8 CISA | 2022-03-25 | 2022-04-15 | Known |
| CVE-2016-4171 | Adobe | Flash Player | Adobe Flash Player Remote Code Execution Vulnerability Unspecified vulnerability in Adobe Flash Player allows for remote code execution. | 7.8 CISA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2016-7892 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class. | 8.8 CISA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2009-3960 | Adobe | BlazeDS | Adobe BlazeDS Information Disclosure Vulnerability Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure. | 6.5 CISA | 2022-03-07 | 2022-09-07 | Known |
| CVE-2013-0625 | Adobe | ColdFusion | Adobe ColdFusion Authentication Bypass Vulnerability Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access. | 9.8 CISA | 2022-03-07 | 2022-09-07 | Unknown |
| CVE-2013-0629 | Adobe | ColdFusion | Adobe ColdFusion Directory Traversal Vulnerability Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories. | 7.5 CISA | 2022-03-07 | 2022-09-07 | Unknown |
| CVE-2013-0631 | Adobe | ColdFusion | Adobe ColdFusion Information Disclosure Vulnerability Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server. | 7.5 CISA | 2022-03-07 | 2022-09-07 | Unknown |
| CVE-2008-2992 | Adobe | Acrobat and Reader | Adobe Reader and Acrobat Input Validation Vulnerability Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution. | 7.8 CISA | 2022-03-03 | 2022-03-24 | Known |
| CVE-2010-0188 | Adobe | Reader and Acrobat | Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code. | 7.8 CISA | 2022-03-03 | 2022-03-24 | Known |
| CVE-2011-0611 | Adobe | Flash Player | Adobe Flash Player Remote Code Execution Vulnerability Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content. | 8.8 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2012-1535 | Adobe | Flash Player | Adobe Flash Player Arbitrary Code Execution Vulnerability Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content. | 7.8 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2013-0632 | Adobe | ColdFusion | Adobe ColdFusion Authentication Bypass Vulnerability An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access. | 9.8 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2013-0640 | Adobe | Reader and Acrobat | Adobe Reader and Acrobat Memory Corruption Vulnerability An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution. | 7.8 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2013-0641 | Adobe | Reader | Adobe Reader Buffer Overflow Vulnerability A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution. | 7.8 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2013-3346 | Adobe | Reader and Acrobat | Adobe Reader and Acrobat Memory Corruption Vulnerability Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service. | 8.8 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2014-0496 | Adobe | Reader and Acrobat | Adobe Reader and Acrobat Use-After-Free Vulnerability Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution. | 8.8 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2015-3043 | Adobe | Flash Player | Adobe Flash Player Memory Corruption Vulnerability A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution. | 7.8 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2015-5119 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution. | 7.8 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2015-7645 | Adobe | Flash Player | Adobe Flash Player Arbitrary Code Execution Vulnerability Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file. | 7.8 CISA | 2022-03-03 | 2022-03-24 | Known |
| CVE-2016-1019 | Adobe | Flash Player | Adobe Flash Player Arbitrary Code Execution Vulnerability Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code. | 7.8 CISA | 2022-03-03 | 2022-03-24 | Known |
| CVE-2016-4117 | Adobe | Flash Player | Adobe Flash Player Arbitrary Code Execution Vulnerability An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution. | 7.8 CISA | 2022-03-03 | 2022-03-24 | Known |
| CVE-2016-7855 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code. | 8.8 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2017-11292 | Adobe | Flash Player | Adobe Flash Player Type Confusion Vulnerability Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution. | 8.8 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2018-15982 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability | 7.8 CISA | 2022-02-15 | 2022-08-15 | Known |
| CVE-2022-24086 | Adobe | Commerce and Magento Open Source | Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution. | 9.8 CNA | 2022-02-15 | 2022-03-01 | Unknown |
| CVE-2018-4878 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution. | 7.8 CISA | 2021-11-03 | 2022-05-03 | Known |
| CVE-2018-15961 | Adobe | ColdFusion | Adobe ColdFusion Unrestricted File Upload Vulnerability Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2018-4939 | Adobe | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2021-28550 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Use-After-Free Vulnerability Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. | 9.6 CNA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-21017 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. | 8.8 CNA | 2021-11-03 | 2021-11-17 | Unknown |