VendorsAdobecoldfusion2018
Vulnerabilities

Adobe ColdFusion 2018

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

54CVEs
CVE-2018-15961
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2018-09-25 · Analyzed
10.0KEV1 PoCEPSS 1.000
CVE-2019-7816
ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 and earlier have a file upload restriction bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-05-24 · Modified
10.0EPSS 0.678
CVE-2019-7839
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-06-12 · Modified
10.0EPSS 0.441
CVE-2018-15957
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2018-09-25 · Modified
10.0EPSS 0.282
CVE-2018-15959
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2018-09-25 · Modified
10.0EPSS 0.259
CVE-2018-15965
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2018-09-25 · Modified
10.0EPSS 0.259
CVE-2018-15958
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2018-09-25 · Modified
10.0EPSS 0.259
CVE-2019-7091
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-05-24 · Modified
10.0EPSS 0.257
CVE-2019-8074
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Path Traversal vulnerability. Successful exploitation could lead to Access Control Bypass in the context of the current user.
Published 2019-09-27 · Modified
10.0EPSS 0.189
CVE-2019-7838
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-06-12 · Modified
10.0EPSS 0.174
CVE-2019-7840
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-06-12 · Modified
10.0EPSS 0.172
CVE-2019-8073
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the context of the current user.
Published 2019-09-27 · Modified
10.0EPSS 0.083
CVE-2020-3794
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Successful exploitation could lead to arbitrary code execution of files located in the webroot or its subdirectory.
Published 2020-03-25 · Modified
10.0EPSS 0.071
CVE-2023-29300
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
Published 2023-07-12 · Analyzed
9.8KEVEPSS 1.000
CVE-2023-26360
Adobe ColdFusion Improper Access Control Arbitrary code execution
Published 2023-03-23 · Analyzed
9.8KEVEPSS 0.973
CVE-2023-38203
Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE
Published 2023-07-20 · Analyzed
9.8KEVEPSS 0.971
CVE-2022-38418
Adobe ColdFusion Application Server Directory Traversal Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
9.8EPSS 0.800
CVE-2022-35711
Adobe ColdFusion ODBC Server Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
9.8EPSS 0.735
CVE-2022-35690
Adobe ColdFusion ODBC Agent Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
9.8EPSS 0.722
CVE-2023-38204
Bypass APSB23-41 (CVE-2023-38203) - Pre-Auth RCE ColdFusion 2021 Update 8
Published 2023-09-14 · Modified
9.8EPSS 0.662
CVE-2022-35710
Adobe ColdFusion ODBC Server Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
9.8EPSS 0.426
CVE-2022-35712
Adobe ColdFusion ODBC Agent Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
9.8EPSS 0.368
CVE-2023-26359
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
Published 2023-03-23 · Analyzed
9.8KEVEPSS 0.170
CVE-2019-8256
ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitation could lead to privilege escalation.
Published 2019-12-19 · Modified
9.8EPSS 0.040
CVE-2020-9672
Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.
Published 2020-07-17 · Modified
7.8EPSS 0.010
CVE-2020-9673
Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.
Published 2020-07-17 · Modified
7.8EPSS 0.010
CVE-2020-3768
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.
Published 2020-06-26 · Modified
7.8EPSS 0.009
CVE-2020-10145
The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability.
Published 2021-05-27 · Modified
7.8EPSS 0.005
CVE-2023-29298
Adobe ColdFusion Improper Access Control Security feature bypass
Published 2023-07-12 · Analyzed
7.5KEVEPSS 0.998
CVE-2023-38205
ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298
Published 2023-09-14 · Analyzed
7.5KEVEPSS 0.997
CVE-2022-38419
Adobe ColdFusion Solr Service XML External Entity Processing Arbitrary file system read
Published 2022-10-14 · Modified
7.5EPSS 0.530
CVE-2022-38422
Adobe ColdFusion Application Server Directory Traversal Information Disclosure Vulnerability
Published 2022-10-14 · Modified
7.5EPSS 0.443
CVE-2022-38420
Adobe ColdFusion Use of Hard-coded Credentials Application denial-of-service
Published 2022-10-14 · Modified
7.5EPSS 0.440
CVE-2022-42341
Adobe ColdFusion Improper Restriction of XML External Entity Reference Arbitrary file system read
Published 2022-10-14 · Modified
7.5EPSS 0.355
CVE-2023-29301
Adobe ColdFusion Improper Restriction of Excessive Authentication Attempts Security feature bypass
Published 2023-07-12 · Modified
7.5EPSS 0.347
CVE-2022-42340
Adobe ColdFusion Improper Input Validation Arbitrary file system read
Published 2022-10-14 · Modified
7.5EPSS 0.338
CVE-2018-15964
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known vulnerability vulnerability. Successful exploitation could lead to information disclosure.
Published 2018-09-25 · Modified
7.5EPSS 0.079
CVE-2019-8072
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Security bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
Published 2019-09-27 · Modified
7.5EPSS 0.074
CVE-2018-15960
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known vulnerability vulnerability. Successful exploitation could lead to arbitrary file overwrite.
Published 2018-09-25 · Modified
7.5EPSS 0.055
CVE-2020-3761
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a remote file read vulnerability. Successful exploitation could lead to arbitrary file read from the coldfusion install directory.
Published 2020-03-25 · Modified
7.5EPSS 0.042
1 / 2Next →