Foxit records
359 published records for vendor foxit.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.3%
- Pre-auth RCE
- 40
- With a fix record
- 0.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-416 Use After Free200
- CWE-125 Out-of-bounds Read71
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-787 Out-of-bounds Write10
- CWE-476 NULL Pointer Dereference8
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')7
The weakness classes this vendor ships most often: where to look.
CWEAll records
359 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
63This week | CVE-2009-0837Weaponized | Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary codfoxit · reader3.0 · CWE-119 | Critical10.0 | — | 75.8% | Mar 10, 2009 |
60This week | CVE-2021-34833No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.foxit · pdf reader · CWE-416 | High7.8 | — | 95.7% | Aug 4, 2021 |
49Plan | CVE-2021-34847No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.foxit · pdf reader · CWE-416 | High7.8 | — | 61.6% | Aug 4, 2021 |
45Plan | CVE-2023-27363Proof of concept | Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerabilityfoxit · pdf editor · CWE-749 | High7.8 | — | 47.0% | May 2, 2024 |
43Plan | CVE-2022-24954No exploit | Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpafoxit · pdf reader · CWE-787 | Critical9.8 | — | 11.9% | Feb 10, 2022 |
42Plan | CVE-2021-34850No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.foxit · pdf reader · CWE-416 | High7.8 | — | 38.3% | Aug 4, 2021 |
40Plan | CVE-2024-25575No exploit | A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object.foxit · pdf editor · CWE-843 | High8.8 | — | 17.7% | Apr 30, 2024 |
40Plan | CVE-2024-25648No exploit | A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a ComboBox widget.foxit · pdf editor · CWE-416 | High8.8 | — | 15.6% | Apr 30, 2024 |
40Plan | CVE-2024-25938No exploit | A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Barcode widget.foxit · pdf editor · CWE-416 | High8.8 | — | 15.6% | Apr 30, 2024 |
40Plan | CVE-2022-28104No exploit | Foxit PDF Editor v11.3.1 was discovered to contain an arbitrary file upload vulnerability.foxit · pdf editor · CWE-434 | Critical9.8 | — | 1.9% | May 20, 2022 |
39Monitor | CVE-2021-38563No exploit | An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1.foxit · pdf reader · CWE-129 | Critical9.8 | — | 1.1% | Aug 11, 2021 |
39Monitor | CVE-2022-24955No exploit | Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.foxit · pdf reader · CWE-427 | Critical9.8 | — | 1.1% | Feb 10, 2022 |
39Monitor | CVE-2026-5936No exploit | Server-Side Request Forgery (SSRF) via URL Parameter in Foxit PDF Services APIfoxit · pdf services api · CWE-918 | Critical9.8 | — | 0.3% | Apr 13, 2026 |
37Monitor | CVE-2021-21831No exploit | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.3.37598.foxit · pdf reader · CWE-416 | High8.8 | — | 6.2% | Aug 5, 2021 |
36Monitor | CVE-2021-40420No exploit | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543.foxit · pdf reader · CWE-416 | High8.8 | — | 4.7% | Feb 4, 2022 |
36Monitor | CVE-2017-14458No exploit | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 8.3.2.25013.foxit · pdf reader · CWE-416 | High8.8 | — | 3.4% | Apr 23, 2018 |
36Monitor | CVE-2018-3850No exploit | An exploitable use-after-free vulnerability exists in the JavaScript engine Foxit Software Foxit PDF Reader version 9.0.1.1049.foxit · pdf reader · CWE-416 | High8.8 | — | 2.8% | Apr 23, 2018 |
36Monitor | CVE-2022-24971No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543.foxit · pdf editor · CWE-125 | High8.8 | — | 2.7% | Feb 18, 2022 |
36Monitor | CVE-2022-24364No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543.foxit · pdf editor · CWE-416 | High8.8 | — | 2.5% | Feb 18, 2022 |
36Monitor | CVE-2022-24365No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543.foxit · pdf editor · CWE-416 | High8.8 | — | 2.5% | Feb 18, 2022 |
36Monitor | CVE-2022-24363No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543.foxit · pdf editor · CWE-416 | High8.8 | — | 2.5% | Feb 18, 2022 |
36Monitor | CVE-2022-24366No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543.foxit · pdf editor · CWE-416 | High8.8 | — | 2.5% | Feb 18, 2022 |
36Monitor | CVE-2022-24369No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543.foxit · pdf editor · CWE-787 | High8.8 | — | 2.5% | Feb 18, 2022 |
36Monitor | CVE-2022-24359No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543.foxit · pdf editor · CWE-416 | High8.8 | — | 2.5% | Feb 18, 2022 |
36Monitor | CVE-2022-24360No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543.foxit · pdf editor · CWE-416 | High8.8 | — | 2.5% | Feb 18, 2022 |
- CVE-2009-083763This week
Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary cod
CriticalCVSS 10.0WeaponizedEPSS 76%foxit · reader3.0Mar 10, 2009
- CVE-2021-3483360This week
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.
HighCVSS 7.8No exploitEPSS 96%foxit · pdf readerAug 4, 2021
- CVE-2021-3484749Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.
HighCVSS 7.8No exploitEPSS 62%foxit · pdf readerAug 4, 2021
- CVE-2023-2736345Plan
Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability
HighCVSS 7.8Proof of conceptEPSS 47%foxit · pdf editorMay 2, 2024
- CVE-2022-2495443Plan
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpa
CriticalCVSS 9.8No exploitEPSS 12%foxit · pdf readerFeb 10, 2022
- CVE-2021-3485042Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.
HighCVSS 7.8No exploitEPSS 38%foxit · pdf readerAug 4, 2021
- CVE-2024-2557540Plan
A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object.
HighCVSS 8.8No exploitEPSS 18%foxit · pdf editorApr 30, 2024
- CVE-2024-2564840Plan
A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a ComboBox widget.
HighCVSS 8.8No exploitEPSS 16%foxit · pdf editorApr 30, 2024
- CVE-2024-2593840Plan
A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Barcode widget.
HighCVSS 8.8No exploitEPSS 16%foxit · pdf editorApr 30, 2024
- CVE-2022-2810440Plan
Foxit PDF Editor v11.3.1 was discovered to contain an arbitrary file upload vulnerability.
CriticalCVSS 9.8No exploitEPSS 2%foxit · pdf editorMay 20, 2022
- CVE-2021-3856339Monitor
An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1.
CriticalCVSS 9.8No exploitEPSS 1%foxit · pdf readerAug 11, 2021
- CVE-2022-2495539Monitor
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.
CriticalCVSS 9.8No exploitEPSS 1%foxit · pdf readerFeb 10, 2022
- CVE-2026-593639Monitor
Server-Side Request Forgery (SSRF) via URL Parameter in Foxit PDF Services API
CriticalCVSS 9.8No exploitEPSS 0%foxit · pdf services apiApr 13, 2026
- CVE-2021-2183137Monitor
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.3.37598.
HighCVSS 8.8No exploitEPSS 6%foxit · pdf readerAug 5, 2021
- CVE-2021-4042036Monitor
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543.
HighCVSS 8.8No exploitEPSS 5%foxit · pdf readerFeb 4, 2022
- CVE-2017-1445836Monitor
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 8.3.2.25013.
HighCVSS 8.8No exploitEPSS 3%foxit · pdf readerApr 23, 2018
- CVE-2018-385036Monitor
An exploitable use-after-free vulnerability exists in the JavaScript engine Foxit Software Foxit PDF Reader version 9.0.1.1049.
HighCVSS 8.8No exploitEPSS 3%foxit · pdf readerApr 23, 2018
- CVE-2022-2497136Monitor
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543.
HighCVSS 8.8No exploitEPSS 3%foxit · pdf editorFeb 18, 2022
- CVE-2022-2436436Monitor
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543.
HighCVSS 8.8No exploitEPSS 3%foxit · pdf editorFeb 18, 2022
- CVE-2022-2436536Monitor
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543.
HighCVSS 8.8No exploitEPSS 3%foxit · pdf editorFeb 18, 2022
- CVE-2022-2436336Monitor
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543.
HighCVSS 8.8No exploitEPSS 3%foxit · pdf editorFeb 18, 2022
- CVE-2022-2436636Monitor
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543.
HighCVSS 8.8No exploitEPSS 3%foxit · pdf editorFeb 18, 2022
- CVE-2022-2436936Monitor
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543.
HighCVSS 8.8No exploitEPSS 3%foxit · pdf editorFeb 18, 2022
- CVE-2022-2435936Monitor
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543.
HighCVSS 8.8No exploitEPSS 3%foxit · pdf editorFeb 18, 2022
- CVE-2022-2436036Monitor
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543.
HighCVSS 8.8No exploitEPSS 3%foxit · pdf editorFeb 18, 2022