NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-91797 Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to ... 2026-09-23 7.8 LOCAL HIGH NVD
CVE-2026-91796 The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger ext... 2026-09-23 6.1 LOCAL MEDIUM NVD
CVE-2026-91795 Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an ... 2026-09-23 7.8 LOCAL HIGH NVD
CVE-2026-91794 An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient consistency and boundary valid... 2026-09-23 7.8 LOCAL HIGH NVD
CVE-2026-91793 When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font d... 2026-09-23 7.8 LOCAL HIGH NVD
CVE-2026-91792 When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related... 2026-09-23 7.8 LOCAL HIGH NVD
CVE-2026-91791 When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition involving JavaScript triggered by ... 2026-09-23 7.8 LOCAL HIGH NVD
CVE-2026-91790 When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed. A... 2026-09-23 7.8 LOCAL HIGH NVD
CVE-2026-91789 Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and related size information. Under cert... 2026-09-23 7.8 LOCAL HIGH NVD
CVE-2026-91788 When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks required by the specification. ... 2026-09-23 4.7 LOCAL MEDIUM NVD
CVE-2026-82331 Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12... 2026-09-23 9.8 NETWORK CRITICAL NVD
CVE-2026-96273 Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB.createUnregisteredOption(), causing an ArrayIndexOutOfBoundsException that leave... 2026-09-23 5.5 LOCAL MEDIUM NVD
CVE-2026-61685 ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build TypeORM `QueryBuilder` conditions ... 2026-09-22 7.5 NETWORK HIGH NVD
CVE-2026-57576 plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based cont... 2026-09-22 6.5 NETWORK MEDIUM NVD
CVE-2026-18176 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmissi... 2026-09-22 7.4 ADJACENT_NETWORK HIGH NVD