2026 CVE Vulnerabilities
57,068 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57251 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper ... |
| CVE-2026-57250 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlyi... |
| CVE-2026-57249 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form e... |
| CVE-2026-57248 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object ... |
| CVE-2026-57247 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The application re-enters the document structure via field processing and deletes the current page, and then continues u... |
| CVE-2026-57246 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature ... |
| CVE-2026-57245 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to valida... |
| CVE-2026-57244 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verifica... |
| CVE-2026-57243 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document stat... |
| CVE-2026-57242 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete ... |
| CVE-2026-57241 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related... |
| CVE-2026-57240 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old fie... |
| CVE-2026-57239 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege use... |
| CVE-2026-57238 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the... |
| CVE-2026-57237 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the under... |
| CVE-2026-56001 | HIGH | 8.8 | 0.4% | Jul 8, 2026 | A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by... |
| CVE-2026-56000 | HIGH | 7.8 | 0.2% | Jul 8, 2026 | Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland b... |
| CVE-2026-55999 | HIGH | 7.8 | 0.3% | Jul 8, 2026 | Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland b... |
| CVE-2026-13129 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in t... |
| CVE-2026-13128 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the... |
| CVE-2026-13127 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the... |
| CVE-2026-13126 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a ... |
| CVE-2026-9695 | CRITICAL | 9.8 | 0.3% | Jul 8, 2026 | An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an a... |
| CVE-2026-12378 | HIGH | 8.1 | 0.2% | Jul 8, 2026 | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data be... |
| CVE-2026-9731 | MEDIUM | 4.3 | 0.1% | Jul 8, 2026 | The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now