Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
399 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.15% | — | Foxit PDF EditorFoxit PDF Reader | 8/7/2026 | 9/7/2026 | The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; however, the renderer still trusts the outdated page count, and eventually the application crashes due to out-of-bounds access. | |
| Analizada | Alta (7.8) | 0.19% | — | Foxit PDF EditorFoxit PDF Reader | 8/7/2026 | 9/7/2026 | When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old field pointers, resulting in invalid pointer references and causing the application to crash. | |
| Analizada | Alta (7.8) | 0.17% | — | Foxit PDF EditorFoxit PDF Reader | 8/7/2026 | 9/7/2026 | The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM. | |
| Analizada | Alta (7.8) | 0.17% | — | Foxit PDF EditorFoxit PDF Reader | 8/7/2026 | 9/7/2026 | After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused the application to crash. | |
| Analizada | Alta (7.8) | 0.17% | — | Foxit PDF EditorFoxit PDF Reader | 8/7/2026 | 9/7/2026 | When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by the program to become invalid. Eventually, it reads an illegal memory address, which leads to the crash of the application. | |
| Analizada | Alta (7.8) | 0.17% | — | Foxit PDF EditorFoxit PDF Reader | 8/7/2026 | 9/7/2026 | When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. Eventually, the application crashes due to reading an invalid pointer. | |
| Analizada | Alta (7.8) | 0.17% | — | Foxit PDF EditorFoxit PDF Reader | 8/7/2026 | 9/7/2026 | Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document view, eventually leading to the crash of the application. | |
| Analizada | Alta (7.8) | 0.17% | — | Foxit PDF EditorFoxit PDF Reader | 8/7/2026 | 9/7/2026 | The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, the thumbnails still use the invalid page objects, ultimately causing the application to crash. | |
| Analizada | Alta (7.8) | 0.17% | — | Foxit PDF EditorFoxit PDF Reader | 8/7/2026 | 9/7/2026 | The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing. | |
| Aplazada | Baja (2.1) | 0.43% | — | Investintech SlimpdfereaderAI | 17/5/2026 | 17/6/2026 | A vulnerability was found in Investintech SlimPDFReader up to 2.0.13. Affected by this vulnerability is the function sub_3B4610 of the file SlimPDFReader.exe. The manipulation results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. The… | |
| Analizada | Alta (7.8) | 0.17% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not properly maintained, leading to a crash when accessing an invalid pointer during page information queries. | |
| Analizada | Media (5.5) | 0.15% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program. | |
| Analizada | Alta (7.1) | 0.16% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to invalid memory writes and program crashes during internal data structure construction. | |
| Analizada | Media (5.5) | 0.16% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes. | |
| Analizada | Media (5.5) | 0.16% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution. | |
| Analizada | Media (5.5) | 0.15% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service. | |
| Analizada | Media (5.5) | 0.15% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate. | |
| Aplazada | Alta (8.4) | 0.21% | — | Docudepot PDF Reader PDF Viewer APPAI | 1/4/2026 | 17/6/2026 | An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Aplazada | Alta (8.4) | 0.21% | — | ORA Tools PDF Reader Reader Editor APPAI | 1/4/2026 | 17/6/2026 | An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Analizada | Alta (7.8) | 0.17% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files,… | |
| Analizada | Alta (7.8) | 0.22% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution. | |
| Analizada | Media (5.5) | 0.15% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep traversal can cause uncontrolled recursion, stack exhaustion, and… | |
| Analizada | Alta (7.8) | 0.17% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object may be destroyed while stale pointers are still kept and… | |
| Analizada | Media (5.5) | 0.15% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior null or validity check, which allows a crafted document to… | |
| Analizada | Alta (7.8) | 0.19% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by low‑privileged users and is not strictly restricted to trusted system locations. Because these libraries may be resolved and loaded from user‑writable locations, a local… |