PDF-XChange is a document-handling software vendor with a narrow product portfolio centered on PDF editing and manipulation tools, yet appears with marked prominence in vulnerability disclosures relative to the software category. The vendor's vulnerability footprint concentrates in flagship products such as PDF-XChange Editor, PDF Tools, and PDF-XChange Pro, which serve both individual and enterprise users for document creation, editing, and processing workflows. While the disclosure volume is substantial, the recurring weakness classes remain diffuse across the products, suggesting a varied attack surface rather than a single dominant flaw pattern. Defenders should monitor this vendor's advisories as part of document-processing risk management, particularly in environments where these tools handle untrusted or user-supplied files; current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pdf Xchange over time
Signals from CVEs in this vendor scope (288 CVEs).
288 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-0907HIGH PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affecte | Feb 11, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-0903HIGH PDF-XChange Editor RTF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected | Feb 11, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-0899HIGH PDF-XChange Editor AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PD | Feb 11, 2025 | 8.8 | 25 | NO | NO |
CVE-2022-37354HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in | Mar 29, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-42423HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in | Jan 26, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-42421HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in | Jan 26, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-42420HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in | Jan 26, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-42419HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in | Jan 26, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-42418HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in | Jan 26, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-42416HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in | Jan 26, 2023 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (288 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pdf Xchange.
Media articles that mention a CVE ID that affects a product developed by Pdf Xchange — matched by CVE ID, not by vendor name.