VDB

GCVE-110-NCSC-2025-222

GCVE-110-NCSC-2025-222
Advisory PublishedCVSS 9.3/10
Vulnetix · Advisory published July 9, 2025
Adobe heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.

Weaknesses (CWE)

CWE-611Improper Restriction of XML External Entity ReferenceCWE-863Incorrect AuthorizationCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-91XML Injection (aka Blind XPath Injection)CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-918Server-Side Request Forgery (SSRF)CWE-284Improper Access ControlCWE-798Use of Hard-coded Credentials

Risk Scores

CVSS 3.1
9.3/10
Critical · CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H

Affected Products

VendorProductVersionsPlatforms
Adobevers:semver/<=2021.20
Adobevers:adobe/update3
Adobevers:adobe/<=update14
Adobevers:adobe/<=update20
Adobevers:adobe/update21
Adobevers:adobe/<=update2
Adobevers:adobe/update15

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,237 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›