Pdf Reader
Vendor:
First CVE: Apr 24, 2007 · Active for 19 years
346
Total CVEs
More Total CVEs than 100% of tracked products
43.3
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pdf Reader over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 24, 2007
19 years ago
Most Recent CVE
Jul 8, 2026
16 days ago
CVE Severity & Scoring
Pdf Reader346 CVEs
9%
14%
77%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local290 (83.8%)
Network55 (15.9%)
Unknown1 (0.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low342 (98.8%)
High3 (0.9%)
Unknown1 (0.3%)
User Interaction
None19 (5.5%)
Unknown1 (0.3%)
Required324 (93.6%)
Privileges Required
Low11 (3.2%)
High0 (0.0%)
None334 (96.5%)
Unknown1 (0.3%)
Top CVEs
Signals from CVEs in this product scope (346 CVEs).
346 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34833HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulner | Aug 4, 2021 | 7.8 | 76 | NO | NO |
CVE-2021-34847HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulner | Aug 4, 2021 | 7.8 | 58 | NO | NO |
CVE-2023-27363HIGH Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal | May 3, 2024 | 7.8 | 50 | NO | NO |
CVE-2021-34850HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulner | Aug 4, 2021 | 7.8 | 44 | NO | NO |
CVE-2010-20010HIGH Foxit PDF Reader before 4.2.0.0928 does not properly bound-check the /Title entry in the PDF Info dictionary. A specially crafted PDF with an overlong Title string can overflow a f | Aug 20, 2025 | 8.4 | 42 | NO | YES |
CVE-2026-57239HIGH The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT | Jul 8, 2026 | 7.8 | 37 | NO | NO |
CVE-2011-10030HIGH Foxit PDF Reader < 4.3.1.0218 exposes a JavaScript API function, createDataObject(), that allows untrusted PDF content to write arbitrary files anywhere on disk. By embedding a ma | Aug 20, 2025 | 8.4 | 36 | NO | YES |
CVE-2022-24954CRITICAL Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substring | Feb 11, 2022 | 9.8 | 36 | NO | NO |
CVE-2026-57240HIGH When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old field pointers, resulting in invalid pointer references and cau | Jul 8, 2026 | 7.8 | 34 | NO | NO |
CVE-2026-57238HIGH After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused the application to crash. | Jul 8, 2026 | 7.8 | 34 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (346 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
0.6% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.3% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (346 CVEs).
Media Mentions
Signals from CVEs in this product scope (346 CVEs).
Top CNAs Publishing CVEs For Pdf Reader
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.1.1049 | 1 | 8.8 | 2.9% | 0 | 0 |
| 8.3.2.25013 | 1 | 8.8 | 3.4% | 0 | 0 |
| 2025.1.0.27937 | 1 | 8.8 | 0.6% | 0 | 0 |
| 2024.1.0.63682 | 1 | 8.8 | 15.6% | 0 | 0 |
| 2024.1.0.23997 | 4 | 8.8 | 12.7% | 0 | 0 |
| 2.0 | 1 | 5.0 | 7.6% | 0 | 1 |
| 12.1.2.15332 | 4 | 8.6 | 1.0% | 0 | 0 |
| 12.1.1.15289 | 1 | 8.8 | 0.9% | 0 | 0 |
| 12.0.1.12430 | 4 | 7.8 | 1.0% | 0 | 0 |
| 11.1.0.52543 | 2 | 8.8 | 3.2% | 0 | 0 |
| 11.0.0.49893 | 1 | 8.8 | 1.9% | 0 | 0 |
| 10.1.4.37651 | 1 | 8.8 | 1.9% | 0 | 0 |
| 10.1.3.37598 | 1 | 8.8 | 4.5% | 0 | 0 |