boxscore/security
PRODUCT · referenceProducts · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

ColdFusion

Product reference — ColdFusion by Adobe · sector: Enterprise Applications. Cumulative disclosure record for this product across the archive.

Follow ColdFusion — Atom feed

Product totals

Disclosures & known-exploited
All-timeYTD
CVEs3520
KEV entries151
Rate & severity
KEV/100Med CVSSMed EPSSCHML
42.98.8.025591020

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over this product's disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▂▁▁▁▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▃▁

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-090
2025-100
2025-110
2025-121
2026-010
2026-020
2026-030
2026-040
2026-050
2026-0616
2026-074
2026-080

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2023-29300100.0YES2024-01-08
CVE-2018-15961100.0YES2021-11-03
CVE-2023-29298100.0YES2023-07-20
CVE-2023-38205100.0YES2023-07-20
CVE-2026-4828210.099.9CRITICALYES2026-07-07
CVE-2024-2076799.9YES2024-12-16
CVE-2023-2636099.9YES2023-03-15
CVE-2023-3820399.9YES2024-01-08
CVE-2013-062599.8YES2022-03-07
CVE-2013-063299.8YES2022-03-03
CVE-2017-306699.8YES2025-02-24
CVE-2013-062999.2YES2022-03-07
CVE-2013-063199.2YES2022-03-07
CVE-2018-493999.1YES2021-11-03
CVE-2023-2635996.9YES2023-08-21

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-483648.25.5HIGH2026-07-13
CVE-2026-483638.25.5HIGH2026-07-13
CVE-2026-4828210.099.9CRITICALYES2026-07-07
CVE-2026-4831610.073.8CRITICAL2026-07-06
CVE-2026-483159.371.3CRITICAL2026-06-30
CVE-2026-483146.550.8MEDIUM2026-06-30
CVE-2026-483139.390.1CRITICAL2026-06-30
CVE-2026-483078.853.7HIGH2026-06-30
CVE-2026-482858.658.1HIGH2026-06-30
CVE-2026-4828310.073.1CRITICAL2026-06-30
CVE-2026-4828110.077.0CRITICAL2026-06-30
CVE-2026-4827710.077.0CRITICAL2026-06-30
CVE-2026-4827610.091.6CRITICAL2026-06-30
CVE-2026-479607.438.0HIGH2026-06-09
CVE-2026-479334.810.8MEDIUM2026-06-09

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2026-482822026-07-0710.099.9CRITICAL
CVE-2017-30662025-02-2499.8
CVE-2024-207672024-12-1699.9
CVE-2023-382032024-01-0899.9
CVE-2023-293002024-01-08100.0
CVE-2023-263592023-08-2196.9
CVE-2023-382052023-07-20100.0
CVE-2023-292982023-07-20100.0
CVE-2023-263602023-03-1599.9
CVE-2013-06252022-03-0799.8
CVE-2013-06292022-03-0799.2
CVE-2013-06312022-03-0799.2
CVE-2013-06322022-03-0399.8
CVE-2018-159612021-11-03100.0
CVE-2018-49392021-11-0399.1

Related

Vendor: Adobe — all products and the full vendor record.

Methodology

A product is a (vendor, product) pair as named in the affected-product data. Rate statistics are arithmetic over published figures. Counts key to first-seen day. Raw counts are not comparable across products; this is a reference page assembled from the public record, not a ranking by our judgment.

Sources. CVE Program (cvelistV5), NVD (NIST), CISA KEV, FIRST EPSS.