Vulnerabilidades en parallax
12 resultadosAnálisis Vexday
Parallax apresenta um perfil de risco baixo com 12 CVEs catalogadas, das quais apenas 2 são críticas e nenhuma está sob ataque ativo no momento. A ausência de divulgações nos últimos 90 dias e a fraqueza dominante em codificação/validação de saída (CWE-116) sugerem um cenário estável, sem pressão imediata de exploração.
CVE-2025-68428CRITICALjsPDF has Local File Inclusion/Path Traversal vulnerabilityEPSS 2.1%CVE-2026-25755HIGHjsPDF has PDF Object Injection via Unsanitized Input in addJS MethodEPSS 0.8%CVE-2026-25535HIGHjsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF DimensionsEPSS 0.7%CVE-2025-57810HIGHjsPDF Parsing of Corrupt PNGs Leads to Potential Denial of Service (DoS)EPSS 0.7%CVE-2025-29907HIGHjsPDF Bypass Regular Expression Denial of Service (ReDoS)EPSS 0.6%CVE-2026-24133HIGHjsPDF Affected by Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoderEPSS 0.6%CVE-2026-24737HIGHjsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript ExecutionEPSS 0.5%CVE-2026-25940HIGHjsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property)EPSS 0.4%CVE-2026-31898HIGHjsPDF has a PDF Object Injection via FreeText colorEPSS 0.4%CVE-2026-31938CRITICALjsPDF has HTML Injection in New Window pathsEPSS 0.3%CVE-2026-24043MEDIUMjsPDF Affected by Stored XMP Metadata Injection (Spoofing & Integrity Violation)EPSS 0.3%CVE-2026-24040MEDIUMjsPDF has a Shared State Race Condition in addJS PluginEPSS 0.3%