Vulnerabilities in Foxit Software Inc.
64 resultsVexday analysis
Foxit Software apresenta volume preocupante com 36 vulnerabilidades publicadas nos últimos 90 dias em um portfólio de 63 CVEs, indicando atividade de descoberta ou divulgação intensificada. A fraqueza dominante (CWE-416 - use-after-free) é típica de aplicações complexas e pode resultar em execução de código, mas nenhuma está registrada em exploração ativa (KEV) e nenhuma atinge criticidade máxima. O padrão recente sugere maior exposição a risco durante processo de patching.
CVE-2026-3779HIGHFoxit PDF Editor/Reader List Box Calculate Array Use-After-Free VulnerabilityEPSS 0.3%CVE-2025-66495HIGHFoxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-66494HIGHFoxit PDF Reader PDF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-66493HIGHFoxit PDF Reader AcroForm Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-66499HIGHFoxit PDF Reader PDF Parsing Heap-Based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-3775HIGHFoxit PDF Editor/Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-57259MEDIUMFoxit PDF Editor/Reader XDP XFA XXE arbitrary local file readEPSS 0.2%CVE-2026-1592MEDIUMStored XSS via Create New Layer Field found in Foxit PDF Editor CloudEPSS 0.2%CVE-2026-1591MEDIUMStored XSS via Attachments Feature in https://pdfonline.foxit.com/EPSS 0.2%CVE-2026-5936HIGHServer-Side Request Forgery (SSRF) via URL Parameter in Foxit PDF Services APIEPSS 0.2%CVE-2025-66497MEDIUMFoxit PDF Reader 3D Annotation Out-of-Bounds Memory Access VulnerabilityEPSS 0.2%CVE-2025-66498MEDIUMFoxit PDF Reader 3D Annotation Out-of-Bounds Memory Access VulnerabilityEPSS 0.2%CVE-2025-66496MEDIUMFoxit PDF Reader 3D Annotation Out-of-Bounds Memory Access VulnerabilityEPSS 0.2%CVE-2026-5942MEDIUMFoxit PDF Editor/Reader AcroForm Signature Use-After-Free VulnerabilityEPSS 0.2%CVE-2026-5943HIGHFoxit PDF Editor/Reader AcroForm Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-66500MEDIUMFoxit webplugins.foxit.com Stored Cross-Site Scripting via postMessage VulnerabilityEPSS 0.2%CVE-2026-4947HIGHInsecure Direct Object Reference (IDOR) Leading to Signature Forgery in Foxit eSignEPSS 0.2%CVE-2026-57260HIGHSecurity vulnerability in Foxit PDF Editor/Reader — U3D Adobe Mesh Decompression (Type Confusion / Invalid Pointer Dereference)EPSS 0.2%CVE-2025-13941HIGHFoxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-57239HIGHFoxit PDF Editor/Reader Local Privilege EscalationEPSS 0.2%