Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
399 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 3.8% | — | Foxit PDF ReaderFoxitsoftware PDF Editor | 4/8/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation… | |
| Modificada | Alta (7.8) | 3.1% | — | Foxit PDF ReaderFoxitsoftware PDF Editor | 4/8/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation… | |
| Modificada | Alta (7.8) | 3.1% | — | Foxit PDF ReaderFoxitsoftware PDF Editor | 4/8/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation… | |
| Modificada | Alta (7.8) | 96% | — | Foxit PDF ReaderFoxitsoftware PDF Editor | 4/8/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation… | |
| Modificada | Alta (7.8) | 4.0% | — | Foxit PDF ReaderFoxitsoftware PDF Editor | 4/8/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the delay… | |
| Modificada | Alta (7.8) | 3.5% | — | Foxit PDF ReaderFoxitsoftware PDF Editor | 4/8/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.4.37651. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Document… | |
| Modificada | Alta (7.2) | 0.72% | — | Unidocs Ezpdf EditorUnidocs Ezpdf Reader | 29/6/2021 | 17/6/2026 | A memory corruption vulnerability exists when ezPDF improperly handles the parameter. This vulnerability exists due to insufficient validation of the parameter. | |
| Modificada | Media (5.3) | 3.6% | — | Avanquest Expert PDF UltimateAvanquest PDF Experte UltimateFoxitsoftware Foxit ReaderGonitro Nitro PRO+13 | 7/1/2021 | 17/6/2026 | The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the… | |
| Modificada | Media (5.3) | 1.1% | — | Code-industry Master PDF EditorFoxitsoftware Foxit ReaderFoxitsoftware PhantompdfGonitro Nitro PRO+9 | 7/1/2021 | 17/6/2026 | The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates… | |
| Modificada | Media (5.5) | 1.0% | — | Gonitro Nitro Free PDF Reader | 10/1/2020 | 17/6/2026 | The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a Out-of-Bounds Read via crafted Unicode content. | |
| Modificada | Media (5.5) | 1.2% | — | Gonitro Nitro Free PDF Reader | 16/12/2019 | 17/6/2026 | The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0xa08a Out-of-Bounds Read via crafted Unicode content. | |
| Modificada | Alta (8.8) | 2.8% | — | Foxit PDF Reader | 23/4/2018 | 17/6/2026 | An exploitable use-after-free vulnerability exists in the JavaScript engine Foxit Software Foxit PDF Reader version 9.0.1.1049. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious… | |
| Modificada | Alta (8.8) | 3.3% | — | Foxit PDF Reader | 23/4/2018 | 17/6/2026 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 8.3.2.25013. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the… | |
| Modificada | Media (5.4) | 0.27% | — | Foxitsoftware Foxit Mobilepdf - PDF Reader | 1/10/2014 | 17/6/2026 | The Foxit MobilePDF - PDF Reader (aka com.foxit.mobile.pdf.lite) application 2.2.0.0616 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (9.3) | 5.2% | — | Nuance PDF Reader | 27/3/2014 | 16/6/2026 | Heap-based buffer overflow in PDFCore8.dll in Nuance PDF Reader before 8.1 allows remote attackers to execute arbitrary code via crafted font table directory values in a TTF file, related to naming table entries. | |
| Modificada | Alta (9.3) | 3.2% | — | Nuance PDF ReaderNuance PDF Reader Plus | 24/2/2013 | 16/6/2026 | Nuance PDF Reader 7.0 and PDF Viewer Plus 7.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document. | |
| Modificada | Media (6.9) | 0.35% | — | Nuance PDF Reader | 6/9/2012 | 16/6/2026 | Multiple untrusted search path vulnerabilities in Nuance PDF Reader 6.0 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) exceptiondumpdll.dll file in the current working directory, as demonstrated by a directory that contains a .pdf file. NOTE: some of these details are obtained from third… | |
| Modificada | Alta (9.3) | 7.4% | 💥 Exploit | Investintech Slimpdf Reader | 1/11/2011 | 16/6/2026 | Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. | |
| Modificada | Alta (9.3) | 3.1% | — | Investintech Slimpdf Reader | 1/11/2011 | 16/6/2026 | Investintech.com SlimPDF Reader does not prevent faulting-address data from affecting branch selection, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. | |
| Modificada | Alta (9.3) | 3.1% | — | Investintech Slimpdf Reader | 1/11/2011 | 16/6/2026 | Investintech.com SlimPDF Reader does not prevent faulting-instruction data from affecting write operations, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. | |
| Modificada | Alta (9.3) | 3.1% | — | Investintech Slimpdf Reader | 1/11/2011 | 16/6/2026 | Investintech.com SlimPDF Reader does not properly restrict read operations during block data moves, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. | |
| Modificada | Alta (9.3) | 3.1% | — | Investintech Slimpdf Reader | 1/11/2011 | 16/6/2026 | Investintech.com SlimPDF Reader does not properly restrict write operations, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. | |
| Modificada | Media (5) | 6.0% | 💥 Exploit | Impactfinancials Impact PDF Reader | 18/6/2010 | 16/6/2026 | Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers to cause a denial of service (server crash) via a "..." body in a POST request. | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | Foxit PDF Reader | 24/4/2007 | 16/6/2026 | Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document. |