Adobe Animate vulnerabilities
108 known vulnerabilities affecting adobe/animate.
Total CVEs
108
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH81MEDIUM24LOW2
Vulnerabilities
Page 2 of 6
CVE-2021-42272P3HIGHCVSS 7.8≤ 21.0.9≥ unspecified, ≤ 21.0.92021-11-18
CVE-2021-42272 [HIGH] CWE-787 CVE-2021-42272: Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that
Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious GIF file.
nvd
CVE-2021-42524P3HIGHCVSS 7.8≤ 21.0.9≥ unspecified, ≤ 21.0.92021-11-18
CVE-2021-42524 [HIGH] CWE-787 CVE-2021-42524: Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that
Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious BMP file.
nvd
CVE-2021-42271P3HIGHCVSS 7.8≤ 21.0.9≥ unspecified, ≤ 21.0.92021-11-18
CVE-2021-42271 [HIGH] CWE-787 CVE-2021-42271: Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that
Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious BMP file.
nvd
CVE-2024-53953P3HIGHCVSS 7.8fixed in 23.0.9≥ 24.0.0, < 24.0.6+1 more2024-12-10
CVE-2024-53953 [HIGH] CWE-416 CVE-2024-53953: Animate versions 23.0.8, 24.0.5 and earlier are affected by a Use After Free vulnerability that coul
Animate versions 23.0.8, 24.0.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-48346P3HIGHCVSS 7.9≥ 23.0.0, < 23.0.16≥ 24.0.0, < 24.0.142026-07-14
CVE-2026-48346 [HIGH] CWE-426 CVE-2026-48346: Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code ex
Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
nvd
CVE-2024-49526P3HIGHCVSS 7.8fixed in 23.0.8≥ 24.0.0, < 24.0.5+1 more2024-11-12
CVE-2024-49526 [HIGH] CWE-416 CVE-2024-49526: Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that coul
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-47414P3HIGHCVSS 7.8≥ 23.0.0, < 23.0.8≥ 24.0.0, < 24.0.5+1 more2024-10-09
CVE-2024-47414 [HIGH] CWE-416 CVE-2024-47414: Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that coul
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-47418P3HIGHCVSS 7.8≥ 23.0.0, < 23.0.8≥ 24.0.0, < 24.0.5+1 more2024-10-09
CVE-2024-47418 [HIGH] CWE-416 CVE-2024-47418: Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that coul
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-47415P3HIGHCVSS 7.8≥ 23.0.0, < 23.0.8≥ 24.0.0, < 24.0.5+1 more2024-10-09
CVE-2024-47415 [HIGH] CWE-416 CVE-2024-47415: Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that coul
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-47412P3HIGHCVSS 7.8≥ 23.0.0, < 23.0.8≥ 24.0.0, < 24.0.5+1 more2024-10-09
CVE-2024-47412 [HIGH] CWE-416 CVE-2024-47412: Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that coul
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-47413P3HIGHCVSS 7.8≥ 23.0.0, < 23.0.8≥ 24.0.0, < 24.0.5+1 more2024-10-09
CVE-2024-47413 [HIGH] CWE-416 CVE-2024-47413: Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that coul
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-27200P3HIGHCVSS 7.8≥ 23.0.0, < 23.0.11≥ 24.0.0, < 24.0.8+1 more2025-04-08
CVE-2025-27200 [HIGH] CWE-416 CVE-2025-27200: Animate versions 24.0.7, 23.0.10 and earlier are affected by a Use After Free vulnerability that cou
Animate versions 24.0.7, 23.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-20761P3HIGHCVSS 7.8≥ 23.0.0, < 23.0.4v24.0.0+1 more2024-03-18
CVE-2024-20761 [HIGH] CWE-787 CVE-2024-20761: Animate versions 24.0, 23.0.3 and earlier are affected by an out-of-bounds write vulnerability that
Animate versions 24.0, 23.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-30282P3HIGHCVSS 7.8≥ 23.0.0, < 23.0.6≥ 24.0.0, < 24.0.3+1 more2024-05-16
CVE-2024-30282 [HIGH] CWE-787 CVE-2024-30282: Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability tha
Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-30296P3HIGHCVSS 7.8≥ 23.0.0, < 23.0.6≥ 24.0.0, < 24.0.3+1 more2024-05-16
CVE-2024-30296 [HIGH] CWE-787 CVE-2024-30296: Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability tha
Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-30297P3HIGHCVSS 7.8≥ 23.0.0, < 23.0.6≥ 24.0.0, < 24.0.3+1 more2024-05-16
CVE-2024-30297 [HIGH] CWE-787 CVE-2024-30297: Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability tha
Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-48347P3HIGHCVSS 7.7≥ 23.0.0, < 23.0.16≥ 24.0.0, < 24.0.142026-07-14
CVE-2026-48347 [HIGH] CWE-78 CVE-2026-48347: Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Com
Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
nvd
CVE-2025-49561P3HIGHCVSS 7.8≥ 23.0.0, < 23.0.13≥ 24.0.0, < 24.0.10+1 more2025-08-12
CVE-2025-49561 [HIGH] CWE-416 CVE-2025-49561: Animate versions 23.0.12, 24.0.9 and earlier are affected by a Use After Free vulnerability that cou
Animate versions 23.0.12, 24.0.9 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-48348P3HIGHCVSS 7.7≥ 23.0.0, < 23.0.16≥ 24.0.0, < 24.0.142026-07-14
CVE-2026-48348 [HIGH] CWE-863 CVE-2026-48348: Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
nvd
CVE-2020-9747P3HIGHCVSS 7.8≤ 20.5≥ unspecified, ≤ 20.52020-10-21
CVE-2020-9747 [HIGH] CWE-415 CVE-2020-9747: Adobe Animate version 20.5 (and earlier) is affected by a double free vulnerability when parsing a c
Adobe Animate version 20.5 (and earlier) is affected by a double free vulnerability when parsing a crafted .fla file, which could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.
nvd