Foxit Software Incorporated

First CVE: Dec 19, 2025Active for: 1 year
63
CVEs Published
More CVEs Published than 63% of tracked CNAs
31.5
Avg CVEs / Year
More Avg CVEs / Year than 77% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Foxit Software Incorporated as a CNA, 100.0% affect products that Foxit Software Incorporated develops as a vendor.

100.0%
Self-reported: 63Third-party: 0

Of all the CVEs published that affect products developed by Foxit Software Incorporated, 17.6% are self-published by Foxit Software Incorporated as a CNA.

17.6%
82.4%
Self-published: 63Published by other CNAs: 295

Trends Over Time

The number and severity of CVEs published by Foxit Software Incorporated over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2025
7 months ago
Most Recent CVE
Jul 8, 2026
16 days ago

Top CVEs

All CVEs published by Foxit Software Incorporated as a CNA, regardless of affected vendor or product.

63 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT
Jul 8, 20267.837NONO
An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to
Apr 13, 20269.836NONO
When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old field pointers, resulting in invalid pointer references and cau
Jul 8, 20267.834NONO
After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused the application to crash.
Jul 8, 20267.834NONO
The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting
Jul 8, 20267.834NONO
When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form is reset. During this
Jul 8, 20267.833NONO
When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the
Jul 8, 20267.833NONO
Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document view, eventually leadin
Jul 8, 20267.833NONO
The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, the thumbnails s
Jul 8, 20267.833NONO
The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly resolved a portion of the abnormal object as a pointer and use
Jul 8, 20267.832NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA63 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local49 (77.8%)
Network14 (22.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low63 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (7.9%)
Unknown0 (0.0%)
Required58 (92.1%)
Privileges Required
Low12 (19.0%)
High0 (0.0%)
None51 (81.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (63 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Foxit Software Incorporated as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Foxit Software Incorporated as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs