Vulnerabilities

Summary — last 7 days

New vulnerabilities2,726▼ 82 vs. last week
Critical / high1,416▲ 189 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)100▼ 400 vs. last week
–

4 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (5.3)3.7%—Avanquest Expert PDF UltimateAvanquest PDF Experte UltimateFoxitsoftware Foxit ReaderGonitro Nitro PRO+131/7/20216/17/2026
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the…
ModifiedMedium (5.3)1.1%—Code-industry Master PDF EditorFoxitsoftware Foxit ReaderFoxitsoftware PhantompdfGonitro Nitro PRO+91/7/20216/17/2026
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates…
ModifiedHigh (7.8)2.4%—Nitropdf Nitro PRONitropdf Nitro Reader2/8/20186/16/2026
Nitro Pro 7.5.0.22 and earlier and Nitro Reader 2.5.0.36 and earlier allow remote attackers to execute arbitrary code via a crafted PDF file.
ModifiedHigh (7.8)2.8%—Nitropdf Nitro PRONitropdf Nitro Reader2/8/20186/16/2026
Nitro Pro 7.5.0.29 and earlier and Nitro Reader 2.5.0.45 and earlier allow remote attackers to execute arbitrary code via a crafted PDF file.