Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2026-75650 | Adobe | Commerce and Magento | Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code. | 10.0 CNA | 2026-09-08 | 2026-09-11 | Unknown |
| CVE-2026-48282 | Adobe | ColdFusion | Adobe ColdFusion Path Traversal Vulnerability Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. | 10.0 CNA | 2026-07-07 | 2026-07-10 | Unknown |
| CVE-2009-3459 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption. | 8.8 CISA | 2026-05-20 | 2026-06-03 | Unknown |
| CVE-2026-34621 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Prototype Pollution Vulnerability Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. | 8.6 CNA | 2026-04-13 | 2026-04-27 | Unknown |
| CVE-2020-9715 | Adobe | Acrobat | Adobe Acrobat Use-After-Free Vulnerability Adobe Acrobat contains a use-after-free vulnerability that allows for code execution | 7.8 CISA | 2026-04-13 | 2026-04-27 | Unknown |
| CVE-2025-54236 | Adobe | Commerce and Magento | Adobe Commerce and Magento Improper Input Validation Vulnerability Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API. | 9.1 CNA | 2025-10-24 | 2025-11-14 | Unknown |
| CVE-2025-54253 | Adobe | Experience Manager (AEM) Forms | Adobe Experience Manager Forms Code Execution Vulnerability Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution. | 10.0 CNA | 2025-10-15 | 2025-11-05 | Unknown |
| CVE-2017-3066 | Adobe | ColdFusion | Adobe ColdFusion Deserialization Vulnerability Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution. | 9.8 CISA | 2025-02-24 | 2025-03-17 | Unknown |
| CVE-2024-20767 | Adobe | ColdFusion | Adobe ColdFusion Improper Access Control Vulnerability Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel. | 7.4 CNA | 2024-12-16 | 2025-01-06 | Unknown |
| CVE-2014-0497 | Adobe | Flash Player | Adobe Flash Player Integer Underflow Vulnerablity Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code. | 8.8 CISA | 2024-09-17 | 2024-10-08 | Unknown |
| CVE-2013-0643 | Adobe | Flash Player | Adobe Flash Player Incorrect Default Permissions Vulnerability Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content. | 8.8 CISA | 2024-09-17 | 2024-10-08 | Unknown |
| CVE-2013-0648 | Adobe | Flash Player | Adobe Flash Player Code Execution Vulnerability Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content. | 8.8 CISA | 2024-09-17 | 2024-10-08 | Unknown |
| CVE-2014-0502 | Adobe | Flash Player | Adobe Flash Player Double Free Vulnerablity Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code. | 8.8 CISA | 2024-09-17 | 2024-10-08 | Unknown |
| CVE-2024-34102 | Adobe | Commerce and Magento Open Source | Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution. | 9.8 CNA | 2024-07-17 | 2024-08-07 | Unknown |
| CVE-2023-38203 | Adobe | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. | 9.8 CNA | 2024-01-08 | 2024-01-29 | Known |
| CVE-2023-29300 | Adobe | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. | 9.8 CNA | 2024-01-08 | 2024-01-29 | Known |
| CVE-2023-21608 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Use-After-Free Vulnerability Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user. | 7.8 CNA | 2023-10-10 | 2023-10-31 | Unknown |
| CVE-2023-26369 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution. | 7.8 CNA | 2023-09-14 | 2023-10-05 | Unknown |
| CVE-2023-26359 | Adobe | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user. | 9.8 CNA | 2023-08-21 | 2023-09-11 | Unknown |
| CVE-2023-38205 | Adobe | ColdFusion | Adobe ColdFusion Improper Access Control Vulnerability Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. | 7.5 CNA | 2023-07-20 | 2023-08-10 | Unknown |
| CVE-2023-29298 | Adobe | ColdFusion | Adobe ColdFusion Improper Access Control Vulnerability Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. | 7.5 CNA | 2023-07-20 | 2023-08-10 | Unknown |
| CVE-2023-26360 | Adobe | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution. | 8.6 CNA | 2023-03-15 | 2023-04-05 | Unknown |
| CVE-2007-5659 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Buffer Overflow Vulnerability Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods. | 7.8 CISA | 2022-06-08 | 2022-06-22 | Unknown |
| CVE-2008-0655 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Unspecified Vulnerability Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times. | 8.8 CISA | 2022-06-08 | 2022-06-22 | Unknown |
| CVE-2009-1862 | Adobe | Acrobat and Reader, Flash Player | Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS). | 7.8 CISA | 2022-06-08 | 2022-06-22 | Unknown |
| CVE-2009-3953 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution. | 8.8 CISA | 2022-06-08 | 2022-06-22 | Unknown |
| CVE-2009-4324 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file. | 7.8 CISA | 2022-06-08 | 2022-06-22 | Unknown |
| CVE-2010-1297 | Adobe | Flash Player | Adobe Flash Player Memory Corruption Vulnerability Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | 7.8 CISA | 2022-06-08 | 2022-06-22 | Unknown |
| CVE-2010-2883 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | 7.3 CISA | 2022-06-08 | 2022-06-22 | Unknown |
| CVE-2011-0609 | Adobe | Flash Player | Adobe Flash Player Unspecified Vulnerability Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | 7.8 CISA | 2022-06-08 | 2022-06-22 | Unknown |
| CVE-2011-2462 | Adobe | Reader and Acrobat | Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS). | 8.8 CISA | 2022-06-08 | 2022-06-22 | Unknown |
| CVE-2012-0754 | Adobe | Flash Player | Adobe Flash Player Memory Corruption Vulnerability Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | 7.8 CISA | 2022-06-08 | 2022-06-22 | Unknown |
| CVE-2012-0767 | Adobe | Flash Player | Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability Adobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web script or HTML. | 6.1 CISA | 2022-06-08 | 2022-06-22 | Unknown |
| CVE-2012-5054 | Adobe | Flash Player | Adobe Flash Player Integer Overflow Vulnerability Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments. | 8.8 CISA | 2022-06-08 | 2022-06-22 | Unknown |
| CVE-2018-4990 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Double Free Vulnerability Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution. | 8.8 CISA | 2022-06-08 | 2022-06-22 | Unknown |
| CVE-2014-0546 | Adobe | Reader and Acrobat | Adobe Reader and Acrobat Sandbox Bypass Vulnerability Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context. | 8.8 CISA | 2022-05-25 | 2022-06-15 | Unknown |
| CVE-2014-8439 | Adobe | Flash Player | Adobe Flash Player Dereferenced Pointer Vulnerability Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution. | 8.8 CISA | 2022-05-25 | 2022-06-15 | Unknown |
| CVE-2015-8651 | Adobe | Flash Player | Adobe Flash Player Integer Overflow Vulnerability Integer overflow in Adobe Flash Player allows attackers to execute code. | 8.8 CISA | 2022-05-25 | 2022-06-15 | Unknown |
| CVE-2015-0310 | Adobe | Flash Player | Adobe Flash Player ASLR Bypass Vulnerability Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism. | 7.8 CISA | 2022-05-25 | 2022-06-15 | Unknown |
| CVE-2016-0984 | Adobe | Flash Player and AIR | Adobe Flash Player and AIR Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code. | 8.8 CISA | 2022-05-25 | 2022-06-15 | Unknown |
| CVE-2016-1010 | Adobe | Flash Player and AIR | Adobe Flash Player and AIR Integer Overflow Vulnerability Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code. | 8.8 CISA | 2022-05-25 | 2022-06-15 | Unknown |
| CVE-2018-5002 | Adobe | Flash Player | Adobe Flash Player Stack-based Buffer Overflow Vulnerability Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution. | 7.8 CISA | 2022-05-23 | 2022-06-13 | Unknown |
| CVE-2014-9163 | Adobe | Flash Player | Adobe Flash Player Stack-Based Buffer Overflow Vulnerability Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely. | 7.8 CISA | 2022-04-13 | 2022-05-04 | Unknown |
| CVE-2015-0311 | Adobe | Flash Player | Adobe Flash Player Remote Code Execution Vulnerability Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code. | 7.8 CISA | 2022-04-13 | 2022-05-04 | Unknown |
| CVE-2015-0313 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code. | 7.8 CISA | 2022-04-13 | 2022-05-04 | Unknown |
| CVE-2015-3113 | Adobe | Flash Player | Adobe Flash Player Heap-Based Buffer Overflow Vulnerability Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code. | 7.8 CISA | 2022-04-13 | 2022-05-04 | Unknown |
| CVE-2015-5122 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). | 7.8 CISA | 2022-04-13 | 2022-05-04 | Unknown |
| CVE-2015-5123 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). | 7.8 CISA | 2022-04-13 | 2022-05-04 | Unknown |
| CVE-2012-2034 | Adobe | Flash Player | Adobe Flash Player Memory Corruption Vulnerability Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS). | 7.5 CISA | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2013-2729 | Adobe | Reader and Acrobat | Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code. | 8.8 CISA | 2022-03-28 | 2022-04-18 | Unknown |