Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-48389

DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
DNG SDK
Provider severity
HIGH
Conflicts
0

CVE-2026-48388

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running the installer. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Photoshop Installer
Provider severity
HIGH
Conflicts
0

CVE-2026-4838

A flaw has been found in SourceCodester Malawi Online Market 1.0. The impacted element is an unknown function of the file /display.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Malawi Online Market
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-48374

Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Adobe Bridge, Adobe Bridge
Provider severity
HIGH
Conflicts
1

CVE-2026-48373

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
Acrobat Reader
Provider severity
HIGH
Conflicts
0

CVE-2026-48372

Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
Format Plugins
Provider severity
HIGH
Conflicts
0

CVE-2026-48371

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe, Adobe
Product
Adobe Commerce, Adobe Commerce Webhooks Plugin, Adobe Commerce B2B, Magento Open Source
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48370

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Adobe Media Encoder, Adobe Media Encoder
Provider severity
HIGH
Conflicts
1

CVE-2026-4837

An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via a crafted beacon response. Because the Agent uses mutual TLS (mTLS) to verify commands from the Rapid7 Platform, it is unlikely that the eval() function could be exploited remotely without prior, highly privileged access to the backend platform.

PUBLISHED
Vendor
Rapid7
Product
Insight Agent
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48369

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Premiere, Premiere
Provider severity
HIGH
Conflicts
1

CVE-2026-48368

Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Audition, Audition
Provider severity
HIGH
Conflicts
1

CVE-2026-48367

After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
After Effects, After Effects
Provider severity
HIGH
Conflicts
1

CVE-2026-48366

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Adobe Media Encoder, Adobe Media Encoder
Provider severity
HIGH
Conflicts
1

CVE-2026-48365

Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Audition, Audition
Provider severity
HIGH
Conflicts
1

CVE-2026-48364

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
ColdFusion
Provider severity
HIGH
Conflicts
0

CVE-2026-48363

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
ColdFusion
Provider severity
HIGH
Conflicts
0

CVE-2026-4836

A vulnerability was detected in code-projects Accounting System 1.0. The affected element is an unknown function of the file /my_account/delete.php. Performing a manipulation of the argument cos_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
code-projects
Product
Accounting System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-48359

Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to read sensitive files, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, Adobe Experience Manager as a Cloud Service
Provider severity
CRITICAL
Conflicts
1

CVE-2026-48358

Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe, Adobe
Product
Adobe Commerce B2B, Magento Open Source, Adobe Commerce Webhooks Plugin, Adobe Commerce
Provider severity
CRITICAL
Conflicts
1

CVE-2026-48357

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Content Credentials JS SDK, Content Credentials Rust SDK, Content Credentials Command-Line Tool
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48356

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe, Adobe
Product
Magento Open Source, Adobe Commerce Webhooks Plugin, Adobe Commerce, Adobe Commerce B2B
Provider severity
CRITICAL
Conflicts
1

CVE-2026-48355

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, Adobe Experience Manager as a Cloud Service
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48354

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Content Credentials JS SDK, Content Credentials Command-Line Tool, Content Credentials Rust SDK
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48353

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Content Credentials Rust SDK, Content Credentials JS SDK, Content Credentials Command-Line Tool
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48352

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Content Credentials JS SDK, Content Credentials Rust SDK, Content Credentials Command-Line Tool
Provider severity
HIGH
Conflicts
1

CVE-2026-48351

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Content Credentials Command-Line Tool, Content Credentials JS SDK, Content Credentials Rust SDK
Provider severity
HIGH
Conflicts
1

CVE-2026-48350

Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to access sensitive files or directories outside the intended restrictions. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
Adobe Animate 2023, Adobe Animate 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-4835

A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of the file /my_account/add_costumer.php of the component Web Application Interface. Such manipulation of the argument costumer_name leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
code-projects
Product
Accounting System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-48349

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
Adobe Animate 2023, Adobe Animate 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-48348

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
Adobe Animate 2023, Adobe Animate 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-48347

Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
Adobe Animate 2024, Adobe Animate 2023
Provider severity
HIGH
Conflicts
1

CVE-2026-48346

Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
Adobe Animate 2023, Adobe Animate 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-48345

Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
Adobe Animate 2023, Adobe Animate 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-48344

Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Creative Cloud Desktop
Provider severity
HIGH
Conflicts
0

CVE-2026-48343

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Adobe Bridge, Adobe Bridge
Provider severity
HIGH
Conflicts
1

CVE-2026-48342

Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Adobe Bridge, Adobe Bridge
Provider severity
HIGH
Conflicts
1

CVE-2026-48341

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Adobe Bridge, Adobe Bridge
Provider severity
HIGH
Conflicts
1

CVE-2026-48340

Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Adobe Bridge, Adobe Bridge
Provider severity
HIGH
Conflicts
1

CVE-2026-4834

The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to, and including, 1.5.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PUBLISHED
Vendor
weDevs
Product
WP ERP Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-48339

Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Adobe Bridge, Adobe Bridge
Provider severity
HIGH
Conflicts
1

CVE-2026-48338

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
ColdFusion 2023, ColdFusion 2025
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48337

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Illustrator Desktop 2026, Illustrator Desktop 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-48336

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Illustrator Desktop 2025, Illustrator Desktop 2026
Provider severity
HIGH
Conflicts
1

CVE-2026-48335

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Illustrator Desktop 2026, Illustrator Desktop 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-48334

Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
Illustrator Desktop 2026, Illustrator Desktop 2025
Provider severity
CRITICAL
Conflicts
1

CVE-2026-48333

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction.

PUBLISHED
Vendor
Adobe
Product
Adobe Campaign Classic
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48332

ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
ColdFusion 2025, ColdFusion 2023
Provider severity
HIGH
Conflicts
1

CVE-2026-48331

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Campaign Classic
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48330

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the application. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Campaign Classic
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4833

A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdown.c of the component Markdown Handler. This manipulation causes uncontrolled recursion. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project maintainer confirms: "[I]f you feed it an infinitely deep blockquote input it will crash. (...) [T]his is a duplicate of an old bug that I've been workin

PUBLISHED
Vendor
Orc
Product
discount
Provider severity
LOW, MEDIUM
Conflicts
2