Pdfsam is a PDF manipulation utility whose vulnerabilities cluster in its Enhanced edition and center on unsafe user-action warnings, out-of-bounds reads, and uncontrolled search path elements that reflect the complexities of file processing and path handling in desktop applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pdfsam over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14403HIGH PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations o | Dec 23, 2025 | 7.8 | 24 | NO | NO |
CVE-2025-14401HIGH PDFsam Enhanced App Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDFsam | Dec 23, 2025 | 7.8 | 24 | NO | NO |
CVE-2025-14404HIGH PDFsam Enhanced XLS File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Dec 23, 2025 | 7.0 | 23 | NO | NO |
CVE-2025-14402HIGH PDFsam Enhanced DOC File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Dec 23, 2025 | 7.0 | 23 | NO | NO |
CVE-2025-14405MEDIUM PDFsam Enhanced Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows phyiscally-present attackers to escalate privileges on affected | Dec 23, 2025 | 6.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pdfsam.
Media articles that mention a CVE ID that affects a product developed by Pdfsam — matched by CVE ID, not by vendor name.