Vulnerabilities

Summary — last 7 days

New vulnerabilities2,722▼ 518 vs. last week
Critical / high1,296▼ 206 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)226▼ 276 vs. last week
–

20 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.2)0.27%—3dflipbook PDF Viewer AND EmbedderAI7/27/20267/27/2026
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.
DeferredHigh (8.4)0.21%—Docudepot PDF Reader PDF Viewer APPAI4/1/20266/17/2026
An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
DeferredMedium (4.9)0.19%—Andy Fragen Embed PDF ViewerAI3/13/20266/17/2026
Server-Side Request Forgery (SSRF) vulnerability in Andy Fragen Embed PDF Viewer embed-pdf-viewer allows Server Side Request Forgery.This issue affects Embed PDF Viewer: from n/a through <= 2.4.7.
DeferredMedium (6.5)0.29%—Simplebooklet PDF Viewer AND EmbedderAI3/27/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in simplebooklet Simplebooklet PDF Viewer and Embedder simplebooklet allows Stored XSS.This issue affects Simplebooklet PDF Viewer and Embedder: from n/a through <= 1.1.1.
DeferredMedium (5.9)0.25%—Andy Fragen Embed PDF ViewerAI12/31/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andy Fragen Embed PDF Viewer embed-pdf-viewer.This issue affects Embed PDF Viewer: from n/a through <= 2.3.1.
AnalyzedCritical (9)0.43%—Xwiki PDF Viewer Macro11/13/20246/17/2026
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't properly escaped, allowing XSS for any user who can edit a page. XSS can impact the confidentiality, integrity and availability of the whole XWiki installation when an admin visits the page with the…
AnalyzedHigh (7.5)0.52%—Xwiki PDF Viewer Macro11/13/20246/17/2026
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService can access any attachment stored in the wiki as the "key" that is passed to prevent this is computed incorrectly, calling skip on the digest stream doesn't update the digest. This is fixed in 2.5.6.
AnalyzedHigh (7.5)0.67%—Xwiki PDF Viewer Macro11/13/20246/17/2026
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The PDF Viewer macro allows an attacker to view any attachment using the "Delegate my view right" feature as long as the attacker can view a page whose last author has access to the attachment. For this, the attacker only needs to provide the…
DeferredMedium (6.4)0.37%—Embed PDF ViewerAI10/9/20246/17/2026
The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and…
DeferredMedium (5.9)0.27%—Themencode TNC PDF ViewerAI10/5/20246/17/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeNcode LLC TNC PDF viewer allows Stored XSS.This issue affects TNC PDF viewer: from n/a through 3.1.0.
ModifiedMedium (5.4)0.33%—Redlettuce PDF Viewer FOR Elementor6/18/20246/17/2026
The PDF Viewer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the render function in all versions up to, and including, 2.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…
DeferredHigh (7.1)0.37%—Creativeinteractivemedia 3D Flipbook PDF Viewer PDF Embedder Real 3D FlipbookAI4/22/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative interactive media 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin allows Reflected XSS.This issue affects 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin:…
ModifiedMedium (5.4)0.34%—Redlettuce PDF Viewer FOR Elementor3/31/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RedLettuce Plugins PDF Viewer for Elementor allows Stored XSS.This issue affects PDF Viewer for Elementor: from n/a through 2.9.3.
ModifiedMedium (5.4)0.42%—Themencode TNC PDF Viewer3/13/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNcode LLC TNC PDF viewer allows Stored XSS.This issue affects TNC PDF viewer: from n/a through 2.8.0.
ModifiedMedium (5.4)0.36%—Simple PDF Viewer Project Simple PDF Viewer4/23/20236/17/2026
Auth. (contrinbutor+) Cross-Site Scripting (XSS) vulnerability in WebArea | Vera Nedvyzhenko Simple PDF Viewer plugin <= 1.9 versions.
ModifiedMedium (5.4)0.47%—PDF Viewer Project PDF Viewer1/30/20236/17/2026
The PDF Viewer WordPress plugin before 1.0.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
ModifiedMedium (5.4)0.65%—PDF Viewer Block FOR Gutenberg Project PDF Viewer Block FOR Gutenberg10/18/20216/17/2026
The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
ModifiedHigh (9.3)4.5%💥 ExploitEdraw PDF Viewer Component6/22/20096/16/2026
Insecure method vulnerability in the PDFVIEWER.PDFViewerCtrl.1 ActiveX control (pdfviewer.ocx) in Edraw PDF Viewer Component before 3.2.0.126 allows remote attackers to create and overwrite arbitrary files via a URL argument to the FtpConnect argument and a target filename argument to the FtpDownloadFile method. NOTE:…
ModifiedHigh (9.3)35%💥 ExploitVerypdf Verydoc PDF Viewer12/12/20086/16/2026
Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX Control allows remote attackers to execute arbitrary code via a long first argument to the OpenPDF method. NOTE: some of these details are obtained from third party information.
ModifiedHigh (8.8)2.8%💥 ExploitVisagesoft Expert PDF Viewer Activex11/4/20086/16/2026
Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remote attackers to overwrite arbitrary files via a full pathname to the savePageAsBitmap method.
Orbitaley — Vulnerabilities