2026 CVE Vulnerabilities
45,449 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57256 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and thi... |
| CVE-2026-57254 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF,... |
| CVE-2026-57252 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotatio... |
| CVE-2026-57251 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper ... |
| CVE-2026-57250 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlyi... |
| CVE-2026-57249 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form e... |
| CVE-2026-57248 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object ... |
| CVE-2026-57247 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The application re-enters the document structure via field processing and deletes the current page, and then continues u... |
| CVE-2026-57246 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature ... |
| CVE-2026-57245 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to valida... |
| CVE-2026-57244 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verifica... |
| CVE-2026-57242 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete ... |
| CVE-2026-57240 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old fie... |
| CVE-2026-57239 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege use... |
| CVE-2026-57238 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the... |
| CVE-2026-57237 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the under... |
| CVE-2026-56001 | HIGH | 8.8 | 0.4% | Jul 8, 2026 | A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by... |
| CVE-2026-56000 | HIGH | 7.8 | 0.2% | Jul 8, 2026 | Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland b... |
| CVE-2026-55999 | HIGH | 7.8 | 0.3% | Jul 8, 2026 | Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland b... |
| CVE-2026-13129 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in t... |
| CVE-2026-13128 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the... |
| CVE-2026-13127 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the... |
| CVE-2026-13126 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a ... |
| CVE-2026-12378 | HIGH | 8.1 | 0.2% | Jul 8, 2026 | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data be... |
| CVE-2026-9700 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now