Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-48329

ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.

PUBLISHED
Vendor
Adobe, Adobe
Product
ColdFusion 2023, ColdFusion 2025
Provider severity
LOW
Conflicts
1

CVE-2026-48328

ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
ColdFusion 2025, ColdFusion 2023
Provider severity
HIGH
Conflicts
1

CVE-2026-48327

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
ColdFusion 2023, ColdFusion 2025
Provider severity
CRITICAL
Conflicts
1

CVE-2026-48326

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Campaign Classic
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48325

ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
ColdFusion 2023, ColdFusion 2025
Provider severity
CRITICAL
Conflicts
1

CVE-2026-48324

ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
ColdFusion 2023, ColdFusion 2025
Provider severity
CRITICAL
Conflicts
1

CVE-2026-48323

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Campaign Classic
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48322

ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
ColdFusion 2025, ColdFusion 2023
Provider severity
CRITICAL
Conflicts
1

CVE-2026-48321

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
ColdFusion 2023, ColdFusion 2025
Provider severity
CRITICAL
Conflicts
1

CVE-2026-48320

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
ColdFusion 2023, ColdFusion 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-4832

CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauthenticated attacker is able to interrogate the SNMP port.

PUBLISHED
Vendor
Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric
Product
Easergy MiCOM P443, P445, P446, P543, P544, P545, P546, Easergy MiCOM P841, Easergy MiCOM P746, Easergy MiCOM P342, P343, P344, P345, Easergy MiCOM P849, Easergy MiCOM P14x, Easergy MiCOM P24x, Easergy MiCOM P741, P742, P743, Easergy MiCOM P643, Easergy MiCOM P642, P645, Easergy MiCOM P341, Easergy MiCOM P442, P444
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48319

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
ColdFusion 2023, ColdFusion 2025
Provider severity
CRITICAL
Conflicts
1

CVE-2026-48318

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
ColdFusion 2023, ColdFusion 2025
Provider severity
CRITICAL
Conflicts
1

CVE-2026-48317

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Campaign Classic
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48316

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
ColdFusion
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48315

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
ColdFusion
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48314

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain limited read and write access to unauthorized files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction.

PUBLISHED
Vendor
Adobe
Product
ColdFusion
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48313

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
ColdFusion
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48312

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Content Credentials Command-Line Tool, Content Credentials JS SDK, Content Credentials Rust SDK
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48311

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Adobe Bridge, Adobe Bridge
Provider severity
HIGH
Conflicts
1

CVE-2026-48310

Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, Adobe Experience Manager as a Cloud Service
Provider severity
HIGH
Conflicts
1

CVE-2026-4831

A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source-code/app/controller/explorer/auth.class.php of the component Password-protected Share Handler. Performing a manipulation results in improper authentication. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been released to the public and may be used for attacks. The vendor

PUBLISHED
Vendor
kalcaddle
Product
kodbox
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-48309

Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Audition, Audition
Provider severity
HIGH
Conflicts
1

CVE-2026-48308

Premiere Pro is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
Premiere, Premiere
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48307

ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially resulting in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious link. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
ColdFusion
Provider severity
HIGH
Conflicts
0

CVE-2026-48306

Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
Substance3D - Sampler
Provider severity
HIGH
Conflicts
0

CVE-2026-48305

Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
Substance3D - Sampler
Provider severity
HIGH
Conflicts
0

CVE-2026-48304

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48303

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Campaign Classic (ACC)
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48302

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Content Credentials Rust SDK, Content Credentials JS SDK, Content Credentials Command-Line Tool
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48301

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48300

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4830

A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php of the component Public Share Handler. Such manipulation leads to unrestricted upload. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any

PUBLISHED
Vendor
kalcaddle
Product
kodbox
Provider severity
MEDIUM
Conflicts
2

CVE-2026-48299

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48298

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Content Credentials Command-Line Tool, Content Credentials JS SDK, Content Credentials Rust SDK
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48297

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48296

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Content Credentials Rust SDK, Content Credentials JS SDK, Content Credentials Command-Line Tool
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48295

CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information. An attacker could leverage this vulnerability to gain unauthorized read access. Exploitation of this issue does not require user interaction.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Content Credentials JS SDK, Content Credentials Rust SDK, Content Credentials Command-Line Tool
Provider severity
HIGH
Conflicts
1

CVE-2026-48294

Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Acrobat PDF Extension (Chrome)
Provider severity
HIGH
Conflicts
0

CVE-2026-48293

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
InDesign Desktop
Provider severity
HIGH
Conflicts
0

CVE-2026-48292

Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
Format Plugins
Provider severity
HIGH
Conflicts
0

CVE-2026-48291

Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
Format Plugins
Provider severity
HIGH
Conflicts
0

CVE-2026-48290

CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Content Credentials Command-Line Tool, Content Credentials JS SDK, Content Credentials Rust SDK
Provider severity
HIGH
Conflicts
1

CVE-2026-4829

Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow.

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48289

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
LOW
Conflicts
0

CVE-2026-48288

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
LOW
Conflicts
0

CVE-2026-48287

CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Content Credentials Rust SDK, Content Credentials JS SDK, Content Credentials Command-Line Tool
Provider severity
HIGH
Conflicts
1

CVE-2026-48286

Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Campaign Classic (ACC)
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48285

ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
ColdFusion
Provider severity
HIGH
Conflicts
0

CVE-2026-48284

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
ColdFusion 2025, ColdFusion 2023
Provider severity
CRITICAL
Conflicts
1