Vulnerabilities
Summary — last 7 days
New vulnerabilities2,722▼ 518 vs. last week
Critical / high1,296▼ 206 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)226▼ 276 vs. last week
20 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.2) | 0.27% | — | 3dflipbook PDF Viewer AND EmbedderAI | 7/27/2026 | 7/27/2026 | Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | |
| Deferred | High (8.4) | 0.21% | — | Docudepot PDF Reader PDF Viewer APPAI | 4/1/2026 | 6/17/2026 | An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Deferred | Medium (4.9) | 0.19% | — | Andy Fragen Embed PDF ViewerAI | 3/13/2026 | 6/17/2026 | Server-Side Request Forgery (SSRF) vulnerability in Andy Fragen Embed PDF Viewer embed-pdf-viewer allows Server Side Request Forgery.This issue affects Embed PDF Viewer: from n/a through <= 2.4.7. | |
| Deferred | Medium (6.5) | 0.29% | — | Simplebooklet PDF Viewer AND EmbedderAI | 3/27/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in simplebooklet Simplebooklet PDF Viewer and Embedder simplebooklet allows Stored XSS.This issue affects Simplebooklet PDF Viewer and Embedder: from n/a through <= 1.1.1. | |
| Deferred | Medium (5.9) | 0.25% | — | Andy Fragen Embed PDF ViewerAI | 12/31/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andy Fragen Embed PDF Viewer embed-pdf-viewer.This issue affects Embed PDF Viewer: from n/a through <= 2.3.1. | |
| Analyzed | Critical (9) | 0.43% | — | Xwiki PDF Viewer Macro | 11/13/2024 | 6/17/2026 | macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't properly escaped, allowing XSS for any user who can edit a page. XSS can impact the confidentiality, integrity and availability of the whole XWiki installation when an admin visits the page with the… | |
| Analyzed | High (7.5) | 0.52% | — | Xwiki PDF Viewer Macro | 11/13/2024 | 6/17/2026 | macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService can access any attachment stored in the wiki as the "key" that is passed to prevent this is computed incorrectly, calling skip on the digest stream doesn't update the digest. This is fixed in 2.5.6. | |
| Analyzed | High (7.5) | 0.67% | — | Xwiki PDF Viewer Macro | 11/13/2024 | 6/17/2026 | macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The PDF Viewer macro allows an attacker to view any attachment using the "Delegate my view right" feature as long as the attacker can view a page whose last author has access to the attachment. For this, the attacker only needs to provide the… | |
| Deferred | Medium (6.4) | 0.37% | — | Embed PDF ViewerAI | 10/9/2024 | 6/17/2026 | The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Deferred | Medium (5.9) | 0.27% | — | Themencode TNC PDF ViewerAI | 10/5/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeNcode LLC TNC PDF viewer allows Stored XSS.This issue affects TNC PDF viewer: from n/a through 3.1.0. | |
| Modified | Medium (5.4) | 0.33% | — | Redlettuce PDF Viewer FOR Elementor | 6/18/2024 | 6/17/2026 | The PDF Viewer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the render function in all versions up to, and including, 2.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Deferred | High (7.1) | 0.37% | — | Creativeinteractivemedia 3D Flipbook PDF Viewer PDF Embedder Real 3D FlipbookAI | 4/22/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative interactive media 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin allows Reflected XSS.This issue affects 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin:… | |
| Modified | Medium (5.4) | 0.34% | — | Redlettuce PDF Viewer FOR Elementor | 3/31/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RedLettuce Plugins PDF Viewer for Elementor allows Stored XSS.This issue affects PDF Viewer for Elementor: from n/a through 2.9.3. | |
| Modified | Medium (5.4) | 0.42% | — | Themencode TNC PDF Viewer | 3/13/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNcode LLC TNC PDF viewer allows Stored XSS.This issue affects TNC PDF viewer: from n/a through 2.8.0. | |
| Modified | Medium (5.4) | 0.36% | — | Simple PDF Viewer Project Simple PDF Viewer | 4/23/2023 | 6/17/2026 | Auth. (contrinbutor+) Cross-Site Scripting (XSS) vulnerability in WebArea | Vera Nedvyzhenko Simple PDF Viewer plugin <= 1.9 versions. | |
| Modified | Medium (5.4) | 0.47% | — | PDF Viewer Project PDF Viewer | 1/30/2023 | 6/17/2026 | The PDF Viewer WordPress plugin before 1.0.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | |
| Modified | Medium (5.4) | 0.65% | — | PDF Viewer Block FOR Gutenberg Project PDF Viewer Block FOR Gutenberg | 10/18/2021 | 6/17/2026 | The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks. | |
| Modified | High (9.3) | 4.5% | 💥 Exploit | Edraw PDF Viewer Component | 6/22/2009 | 6/16/2026 | Insecure method vulnerability in the PDFVIEWER.PDFViewerCtrl.1 ActiveX control (pdfviewer.ocx) in Edraw PDF Viewer Component before 3.2.0.126 allows remote attackers to create and overwrite arbitrary files via a URL argument to the FtpConnect argument and a target filename argument to the FtpDownloadFile method. NOTE:… | |
| Modified | High (9.3) | 35% | 💥 Exploit | Verypdf Verydoc PDF Viewer | 12/12/2008 | 6/16/2026 | Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX Control allows remote attackers to execute arbitrary code via a long first argument to the OpenPDF method. NOTE: some of these details are obtained from third party information. | |
| Modified | High (8.8) | 2.8% | 💥 Exploit | Visagesoft Expert PDF Viewer Activex | 11/4/2008 | 6/16/2026 | Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remote attackers to overwrite arbitrary files via a full pathname to the savePageAsBitmap method. |