Exposição de Adobe Experience Manager

CMS
219
score de exposição
18.203
sites usam
1
em exploração
4
críticos
Análise Vexday

Com 1.022 CVEs catalogadas, o Adobe Experience Manager acumula um histórico de vulnerabilidades considerável, ainda que sua taxa de exploração ativa esteja abaixo da média geral do catálogo CISA KEV. A falha mais comum é CWE-79 (Cross-Site Scripting), o que indica exposição persistente a vetores de injeção de script no lado do cliente — um padrão relevante em plataformas de gerenciamento de conteúdo com amplas superfícies de entrada. Atenção especial deve ser dada ao CVE-2025-54253, atualmente a vulnerabilidade mais crítica em exploração ativa, com índice EPSS de aproximadamente 0,90, sinalizando altíssima probabilidade de exploração real e exigindo priorização imediata de mitigação. O volume de 61 CVEs surgidas nos últimos 90 dias reforça que a superfície de ataque da plataforma segue em expansão ativa, demandando monitoramento contínuo e ciclos de patching ágeis.

CVEs

1.022 resultados
CVE-2024-52862MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.4%CVE-2024-36180MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.4%CVE-2024-36185MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.4%CVE-2024-36186MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.4%CVE-2024-36187MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.4%CVE-2024-36188MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.4%CVE-2024-36200MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.4%CVE-2024-36202MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.4%CVE-2024-36203MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.4%CVE-2024-36204MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.4%CVE-2024-36205MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.4%CVE-2024-36206MEDIUMAdobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79)EPSS 0.4%CVE-2024-36207MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.4%CVE-2024-36208MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.4%CVE-2024-36211MEDIUMAdobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79)EPSS 0.4%CVE-2024-36212MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.4%CVE-2024-36213MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.4%CVE-2024-41849MEDIUMAdobe Experience Manager | Improper Input Validation (CWE-20)EPSS 0.4%CVE-2025-54246MEDIUMAdobe Experience Manager | Incorrect Authorization (CWE-863)EPSS 0.4%CVE-2023-51460MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.4%

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →