2026 CVE Vulnerabilities

57,068 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-57251HIGH7.8The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper ...
CVE-2026-57250HIGH7.8When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlyi...
CVE-2026-57249HIGH7.8After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form e...
CVE-2026-57248HIGH7.8When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object ...
CVE-2026-57247HIGH7.8The application re-enters the document structure via field processing and deletes the current page, and then continues u...
CVE-2026-57246HIGH7.8When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature ...
CVE-2026-57245HIGH7.8When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to valida...
CVE-2026-57244HIGH7.8After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verifica...
CVE-2026-57243MEDIUM6.1During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document stat...
CVE-2026-57242HIGH7.8The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete ...
CVE-2026-57241MEDIUM6.1The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related...
CVE-2026-57240HIGH7.8When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old fie...
CVE-2026-57239HIGH7.8The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege use...
CVE-2026-57238HIGH7.8After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the...
CVE-2026-57237HIGH7.8When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the under...
CVE-2026-56001HIGH8.8A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by...
CVE-2026-56000HIGH7.8Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland b...
CVE-2026-55999HIGH7.8Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland b...
CVE-2026-13129HIGH7.8When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in t...
CVE-2026-13128HIGH7.8Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the...
CVE-2026-13127HIGH7.8The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the...
CVE-2026-13126HIGH7.8The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a ...
CVE-2026-9695CRITICAL9.8An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an a...
CVE-2026-12378HIGH8.1The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data be...
CVE-2026-9731MEDIUM4.3The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now