VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 404 of 1286 · EPSS data 2026.07.20
ReviewHigh
CVE-2026-56002

X.Org libXfont2, libxfont

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within the X server.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57256

Foxit Software Inc. Foxit PDF Editor, Foxit PDF Reader, pdf editor

When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form is reset. During this process, the application failed to adequately verify the validity of the form objects and their internal dictionary pointers, resulting in accessing internal members of invalid or improperly initialized fields. This led to an illegal pointer read, ultimately causing the application to crash.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57248

Foxit Software Inc. Foxit PDF Editor, Foxit PDF Reader, pdf editor

When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks. As a result, due to the damage to the internal structure of the annotations, it causes the application to crash during subsequent release.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57245

Foxit Software Inc. Foxit PDF Editor, Foxit PDF Reader, pdf editor

When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to validate the abnormal annotation relationships and field combinations. This results in the internal objects entering an invalid state. Eventually, during the destruction phase, an invalid pointer write occurred, causing the application to crash.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57244

Foxit Software Inc. Foxit PDF Editor, Foxit PDF Reader, pdf editor

After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verification, resulting in the failure of the control pointer during the traversal process. After the pointer fails, it still continues to dereference, causing the application to crash.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57242

Foxit Software Inc. Foxit PDF Editor, Foxit PDF Reader, pdf editor

The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete lifecycle management and null value validation; when the page state changes, the application continuously dereferences invalid objects, eventually leading to a crash.

The CVSS severity warrants an early asset and exposure review.