VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25302 CVEsRSS

CVE-2026-91800High· 8.8
5d ago

A local privilege escalation vulnerability exists in the installer of Foxit PDF Editor for macOS due to insufficient validation of a user-modifiable configuration value during high-privilege upgrades

A local privilege escalation vulnerability exists in the installer of Foxit PDF Editor for macOS due to insufficient validation of a user-modifiable configuration value during high-privilege upgrades. A local attacker could exploit this …

▾ TwilightFoxit Software Inc. · Foxit PDF EditorEPSS 0.10%via NVD
CVE-2026-91799High· 7.8
5d ago

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects. A specially crafted PDF may cause the application to access a released object during array processing, potentially resulting in appl…

▾ TwilightFoxit Software Inc. · Foxit PDF EditorEPSS 0.13%via NVD
CVE-2026-91798High· 8.8
5d ago

A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure permission configuration that allows the configuration file to be modified by regular users, which may lead to arbitrary…

A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure permission configuration that allows the configuration file to be modified by regular users, which may lead to arbitrary…

▾ TwilightFoxit Software Inc. · Foxit PDF EditorEPSS 0.10%via NVD
CVE-2026-91797High· 7.8
5d ago

Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened.

Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened.

▾ TwilightFoxit Software Inc. · Foxit PDF EditorEPSS 0.21%via NVD
CVE-2026-91796Medium· 6.1
5d ago

The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the …

The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the …

▾ SunlitFoxit Software Inc. · Foxit PDF EditorEPSS 0.12%via NVD
CVE-2026-91795High· 7.8
5d ago

Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files

Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violat…

▾ TwilightFoxit Software Inc. · Foxit PDF EditorEPSS 0.08%via NVD
CVE-2026-91794High· 7.8
5d ago

An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient consistency and boundary validation when processing malformed color space data, which may cause the program to crash …

An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient consistency and boundary validation when processing malformed color space data, which may cause the program to crash …

▾ TwilightFoxit Software Inc. · Foxit PDF EditorEPSS 0.16%via NVD
CVE-2026-91793High· 7.8
5d ago

When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data

When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data. During subsequent annotation appearance reconstruction, it accesses an object afte…

▾ TwilightFoxit Software Inc. · Foxit PDF EditorEPSS 0.13%via NVD
CVE-2026-91792High· 7.8
5d ago

When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related JavaScript actions

When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related JavaScript actions. This can cause the application to access page objects after they h…

▾ TwilightFoxit Software Inc. · Foxit PDF EditorEPSS 0.13%via NVD
CVE-2026-91791High· 7.8
5d ago

When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition involving JavaScript triggered by page-visibility events

When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition involving JavaScript triggered by page-visibility events. This can cause the application to access a released page-view o…

▾ TwilightFoxit Software Inc. · Foxit PDF EditorEPSS 0.14%via NVD
CVE-2026-91790High· 7.8
5d ago

When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed

When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed. As a result, the program may access an already-freed internal data structure, triggering…

▾ TwilightFoxit Software Inc. · Foxit PDF EditorEPSS 0.13%via NVD
CVE-2026-91789High· 7.8
5d ago

Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and related size information

Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and related size information. Under certain conditions, this could lead to an incorrectly sized memory allocation and a subsequ…

▾ TwilightFoxit Software Inc. · Foxit PDF EditorEPSS 0.16%via NVD
CVE-2026-91788Medium· 4.7
5d ago

When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks required by the specification

When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks required by the specification. As a result, a trusted malicious PDF could potentially access sensitive content from ot…

▾ SunlitFoxit Software Inc. · Foxit PDF EditorEPSS 0.10%via NVD
CVE-2026-50228Medium· 6.1
5d ago

An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and including 5.2.63) on localhost TCP port 9993

An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and including 5.2.63) on localhost TCP port 9993. Because Chromium remote debugging is enabled in the pro…

▾ SunlitAcer · NitroSense V5EPSS 0.13%via NVD
CVE-2026-50227Medium· 6.1
5d ago

An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSense software (versions up to and including 5.2.62)

An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSense software (versions up to and including 5.2.62). This allows the attacker to invoke exposed ddsc RPC functions, incl…

▾ SunlitAcer · NitroSense V5EPSS 0.35%via NVD
CVE-2026-82331Critical· 9.8
5d ago

Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of th…

Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of th…

▾ MidnightApache Software Foundation · buildstreamEPSS 0.42%via NVD
CVE-2026-6831Medium· 6.5
5d ago

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 2.0.9

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 2.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…

▾ Sunlitvsourz1td · Advanced Contact form 7 DBEPSS 0.26%via NVD
CVE-2026-5924Medium· 6.4
5d ago

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps block's 'customStyle' attribute in all versions up to, and including, 2.1.3

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps block's 'customStyle' attribute in all versions up to, and including, 2.1.3. This is due to the use of eval() on user-con…

▾ Sunlitjetmonsters · Getwid – Gutenberg BlocksEPSS 0.26%via NVD
CVE-2026-93528Low· 3.7PoC
5d ago

The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.

The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.

▾ TwilightEPSS 0.22%via NVD
CVE-2026-93511Medium· 5.3
5d ago

The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowing unauthenticated attackers to forge payment confirmations and subscription-c…

The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowing unauthenticated attackers to forge payment confirmations and subscription-c…

▾ SunlitEPSS 0.20%via NVD
CVE-2026-93510Medium· 4.3
5d ago

The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel claim handler, allowing authenticated users, Subscriber and above, to credit their o…

The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel claim handler, allowing authenticated users, Subscriber and above, to credit their o…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-93508High· 8.1
5d ago

The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post m…

The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post m…

▾ TwilightEPSS 0.21%via NVD
CVE-2026-93507Low· 3.3
5d ago

The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, inclu…

The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, inclu…

▾ SunlitEPSS 0.13%via NVD
CVE-2026-91077Low· 2.7
5d ago

The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other au…

The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other au…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-91073Medium· 6.8
5d ago

The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to perform Stored Cross-Site Scripting a…

The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to perform Stored Cross-Site Scripting a…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-91025Medium· 4.3
5d ago

The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated…

The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-91024Medium· 6.8
5d ago

The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to per…

The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to per…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-90985Medium· 5.3
5d ago

The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing unauthenticated users to read the description…

The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing unauthenticated users to read the description…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-90951Low· 3.7
5d ago

The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that mem…

The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that mem…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-89331Medium· 5.3
5d ago

The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose the email addresses of a shared board's members, ty…

The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose the email addresses of a shared board's members, ty…

▾ SunlitEPSS 0.21%via NVD
CVEs tagged “nvd” — page 73 · VulnSea