56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.580 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2026-57247 | HIGH 7.8 | foxit pdf_editor The application re-enters the document structure via field processing and deletes the current page, and then continues using the field objects obtained before deletion, triggering an illegal read and crashing. | 0.1% | — |
| CVE-2026-57246 | HIGH 7.8 | foxit pdf_editor When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature verification, but the signature plugin does not perform validation when copying the abnormal string, causing the application to crash. | 0.1% | — |
| CVE-2026-57245 | HIGH 7.8 | foxit pdf_editor When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to validate the abnormal annotation relationships and field combinations. This results in the internal objects entering an invalid state. Eventually, | 0.1% | — |
| CVE-2026-57244 | HIGH 7.8 | foxit pdf_editor After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verification, resulting in the failure of the control pointer during the traversal process. After the pointer fails, it still continues to dereferen | 0.1% | — |
| CVE-2026-57243 | MED 6.1 | foxit pdf_editor During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document status. Subsequently, with outdated page information, the application attempts to access invalid addresses, causing the application to crash. | 0.1% | — |
| CVE-2026-57242 | HIGH 7.8 | foxit pdf_editor The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete lifecycle management and null value validation; when the page state changes, the application continuously dereferences invalid objects, even | 0.1% | — |
| CVE-2026-57241 | MED 6.1 | foxit pdf_editor The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; however, the renderer still trusts the outdated page count, and eventually the appl | 0.1% | — |
| CVE-2026-57240 | HIGH 7.8 | foxit pdf_editor When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old field pointers, resulting in invalid pointer references and causing the application to crash. | 0.1% | — |
| CVE-2026-57239 | HIGH 8.2 | foxit pdf_editor The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM. | 0.2% | — |
| CVE-2026-57238 | HIGH 7.8 | foxit pdf_editor After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused the application to crash. | 0.1% | — |
| CVE-2026-57237 | HIGH 7.8 | foxit pdf_editor When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by the program to become invalid. Eventually, it reads an illegal memory address, which leads to the crash of the a | 0.1% | — |
| CVE-2026-57211 | MED 6.5 | broadcom rabbitmq_server RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple | 0.4% | — |
| CVE-2026-57111 | HIGH 7.5 | apache helix Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an authorized user to read r | 0.3% | — |
| CVE-2026-57108 | HIGH 7.5 | microsoft .net Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-57107 | HIGH 7.8 | microsoft windows_admin_center Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-57106 | CRIT 10.0 | microsoft purview_data_governance Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-57105 | HIGH 8.0 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-57104 | HIGH 8.8 | microsoft azure_storage_explorer Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-57102 | HIGH 8.8 | microsoft visual_studio_code Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0.8% | — |
| CVE-2026-57101 | HIGH 7.1 | microsoft visual_studio_code Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-57100 | CRIT 9.9 | microsoft entra_provisioning_service Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-57097 | MED 6.4 | microsoft windows_10_1607 Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack. | 0.3% | — |
| CVE-2026-57096 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-57095 | MED 6.2 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-57094 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | 0.8% | — |