VYPR

Lightroom Desktop

by Adobe Inc.

CVEs (19)

  • CVE-2026-48441HigAug 11, 2026
    risk 0.56cvss 8.6epss 0.00

    Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the…

  • CVE-2026-48397HigAug 11, 2026
    risk 0.56cvss 8.6epss 0.01

    Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user…

  • CVE-2026-48410HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48409HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48408HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48407HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48406HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48405HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48404HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-47940HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-21349HigFeb 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Lightroom Desktop versions 15.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-27197HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Lightroom Desktop versions 8.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2024-20754HigMar 18, 2024
    risk 0.51cvss 7.8epss 0.00

    Lightroom Desktop versions 7.1.2 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as programs, then an…

  • CVE-2021-43753HigSep 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Lightroom versions 4.4 (and earlier) are affected by a use-after-free vulnerability in the processing of parsing TIF files that could result in privilege escalation. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2020-9724HigAug 19, 2020
    risk 0.51cvss 7.8epss 0.03

    Adobe Lightroom versions 9.2.0.10 and earlier have an insecure library loading vulnerability. Successful exploitation could lead to privilege escalation.

  • CVE-2026-48447HigAug 11, 2026
    risk 0.50cvss 7.7epss 0.00

    Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's…

  • CVE-2020-24447HigDec 11, 2020
    risk 0.46cvss 7.0epss 0.01

    Adobe Lightroom Classic version 10.0 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2021-40776MedJun 15, 2022
    risk 0.40cvss 6.1epss 0.01

    Adobe Lightroom Classic 10.3 (and earlier) are affected by a privilege escalation vulnerability in the Offline Lightroom Classic installer. An authenticated attacker could leverage this vulnerability to escalate privileges. User interaction is required before product…

  • CVE-2024-45145MedOct 9, 2024
    risk 0.36cvss 5.5epss 0.00

    Lightroom Desktop versions 7.4.1, 13.5, 12.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires…