Connect
by Adobe Inc.
CVEs (86)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-0950 | Med | 0.35 | 5.3 | 0.02 | Feb 10, 2016 | Adobe Connect before 9.5.2 allows remote attackers to spoof the user interface via unspecified vectors. | ||
| CVE-2025-54196 | Med | 0.28 | 4.3 | 0.00 | Oct 14, 2025 | Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction in that a… | ||
| CVE-2024-54038 | Med | 0.28 | 4.3 | 0.01 | Dec 10, 2024 | Adobe Connect versions 12.6, 11.4.7 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on… | ||
| CVE-2021-28579 | Med | 0.28 | 4.3 | 0.01 | Jun 28, 2021 | Adobe Connect version 11.2.1 (and earlier) is affected by an Improper access control vulnerability that can lead to the elevation of privileges. An attacker with 'Learner' permissions can leverage this scenario to access the list of event participants. | ||
| CVE-2015-0344 | 0.00 | — | 0.02 | Jun 13, 2015 | Cross-site scripting (XSS) vulnerability in the web app in Adobe Connect before 9.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||
| CVE-2015-0343 | 0.00 | — | 0.03 | Jun 13, 2015 | Cross-site scripting (XSS) vulnerability in admin/home/homepage/search in the web app in Adobe Connect before 9.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter. |
- risk 0.35cvss 5.3epss 0.02
Adobe Connect before 9.5.2 allows remote attackers to spoof the user interface via unspecified vectors.
- risk 0.28cvss 4.3epss 0.00
Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction in that a…
- risk 0.28cvss 4.3epss 0.01
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on…
- risk 0.28cvss 4.3epss 0.01
Adobe Connect version 11.2.1 (and earlier) is affected by an Improper access control vulnerability that can lead to the elevation of privileges. An attacker with 'Learner' permissions can leverage this scenario to access the list of event participants.
- CVE-2015-0344Jun 13, 2015risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in the web app in Adobe Connect before 9.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2015-0343Jun 13, 2015risk 0.00cvss —epss 0.03
Cross-site scripting (XSS) vulnerability in admin/home/homepage/search in the web app in Adobe Connect before 9.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
Page 5 of 5