2026 CVE Vulnerabilities

45,449 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-57256HIGH7.8When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and thi...
CVE-2026-57254HIGH7.8There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF,...
CVE-2026-57252HIGH7.8When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotatio...
CVE-2026-57251HIGH7.8The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper ...
CVE-2026-57250HIGH7.8When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlyi...
CVE-2026-57249HIGH7.8After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form e...
CVE-2026-57248HIGH7.8When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object ...
CVE-2026-57247HIGH7.8The application re-enters the document structure via field processing and deletes the current page, and then continues u...
CVE-2026-57246HIGH7.8When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature ...
CVE-2026-57245HIGH7.8When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to valida...
CVE-2026-57244HIGH7.8After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verifica...
CVE-2026-57242HIGH7.8The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete ...
CVE-2026-57240HIGH7.8When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old fie...
CVE-2026-57239HIGH7.8The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege use...
CVE-2026-57238HIGH7.8After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the...
CVE-2026-57237HIGH7.8When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the under...
CVE-2026-56001HIGH8.8A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by...
CVE-2026-56000HIGH7.8Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland b...
CVE-2026-55999HIGH7.8Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland b...
CVE-2026-13129HIGH7.8When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in t...
CVE-2026-13128HIGH7.8Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the...
CVE-2026-13127HIGH7.8The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the...
CVE-2026-13126HIGH7.8The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a ...
CVE-2026-12378HIGH8.1The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data be...
CVE-2026-9700HIGH7.5The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now