Vulnerabilities > Adobe > Coldfusion > 2016
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-11-17 | CVE-2023-26347 | Improper Access Control vulnerability in Adobe Coldfusion Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. | 7.5 |
2023-11-17 | CVE-2023-44350 | Deserialization of Untrusted Data vulnerability in Adobe Coldfusion Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. | 9.8 |
2023-11-17 | CVE-2023-44351 | Deserialization of Untrusted Data vulnerability in Adobe Coldfusion Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. | 9.8 |
2023-11-17 | CVE-2023-44352 | Cross-site Scripting vulnerability in Adobe Coldfusion Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. | 6.1 |
2023-11-17 | CVE-2023-44353 | Deserialization of Untrusted Data vulnerability in Adobe Coldfusion Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. | 9.8 |
2023-11-17 | CVE-2023-44355 | Improper Input Validation vulnerability in Adobe Coldfusion Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. | 4.3 |
2023-09-07 | CVE-2021-40698 | Use of Inherently Dangerous Function vulnerability in Adobe Coldfusion ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an Use of Inherently Dangerous Function vulnerability that can lead to a security feature bypass??. | 7.4 |
2023-09-07 | CVE-2021-40699 | Unspecified vulnerability in Adobe Coldfusion ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when checking permissions in the CFIDE path. | 7.4 |
2022-05-12 | CVE-2022-28818 | Cross-site Scripting vulnerability in Adobe Coldfusion ColdFusion versions CF2021U3 (and earlier) and CF2018U13 are affected by a reflected Cross-Site Scripting (XSS) vulnerability. | 6.1 |
2021-05-27 | CVE-2020-10145 | Incorrect Default Permissions vulnerability in Adobe Coldfusion 2016/2018/2021 The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. | 7.2 |