Tungstenautomation's vulnerability footprint centers on a tightly scoped portfolio of document-processing and capture software, including Power PDF and Kofax Capture, that occupy a significant role in enterprise content management workflows despite a narrow product range. The recurring weakness classes—out-of-bounds writes, out-of-bounds reads, heap-based buffer overflows, use-after-free conditions, and improper memory-buffer restrictions—reflect the memory-safety demands of PDF parsing and document-handling libraries that process untrusted input at scale. This pattern is durable across the vendor's disclosures and typical of native-code libraries handling complex binary formats, where parsing logic is inherently prone to boundary violations. Defenders should treat updates for these products as relevant to document-processing infrastructure and supply chains, and should prioritize patching in environments where these tools handle externally sourced files; current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tungstenautomation over time
Signals from CVEs in this vendor scope (138 CVEs).
138 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-12547HIGH Tungsten Automation Power PDF JPF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affe | Feb 11, 2025 | 8.8 | 25 | NO | NO |
CVE-2023-44436HIGH Kofax Power PDF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of K | May 3, 2024 | 7.8 | 24 | NO | NO |
CVE-2023-44435HIGH Kofax Power PDF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of K | May 3, 2024 | 7.8 | 24 | NO | NO |
CVE-2023-44432HIGH Kofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installat | May 3, 2024 | 7.8 | 24 | NO | NO |
CVE-2024-12551HIGH Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affec | Feb 11, 2025 | 7.8 | 23 | NO | NO |
CVE-2023-38090HIGH Kofax Power PDF popUpMenu Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installat | May 3, 2024 | 7.8 | 23 | NO | NO |
CVE-2023-38088HIGH Kofax Power PDF printf Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of | May 3, 2024 | 7.8 | 23 | NO | NO |
CVE-2023-38087HIGH Kofax Power PDF clearTimeOut Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | May 3, 2024 | 7.8 | 23 | NO | NO |
CVE-2023-37340HIGH Kofax Power PDF PNG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installat | May 3, 2024 | 7.8 | 23 | NO | NO |
CVE-2023-37337HIGH Kofax Power PDF JP2 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installat | May 3, 2024 | 7.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (138 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tungstenautomation.
Media articles that mention a CVE ID that affects a product developed by Tungstenautomation — matched by CVE ID, not by vendor name.