|
841
|
5.5 |
MEDIUM
Local
|
foxit
|
pdf_editor pdf_reader
|
Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service.
|
CWE-691
Insufficient Control Flow Management
|
CVE-2026-5938
|
2026-04-30 02:29 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
842
|
5.5 |
MEDIUM
Local
|
foxit
|
pdf_editor pdf_reader
|
A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.
|
CWE-416
Use After Free
|
CVE-2026-5939
|
2026-04-30 02:28 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
843
|
5.5 |
MEDIUM
Local
|
foxit
|
pdf_editor pdf_reader
|
Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes.
|
CWE-416
Use After Free
|
CVE-2026-5940
|
2026-04-30 02:26 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
844
|
7.1 |
HIGH
Local
|
foxit
|
pdf_editor pdf_reader
|
Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to invalid memory writes and program crashes during inte…
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-5941
|
2026-04-30 02:24 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
845
|
5.5 |
MEDIUM
Local
|
foxit
|
pdf_editor pdf_reader
|
Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program.
|
CWE-416
Use After Free
|
CVE-2026-5942
|
2026-04-30 02:18 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
846
|
7.8 |
HIGH
Local
|
foxit
|
pdf_editor pdf_reader
|
Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not pro…
|
CWE-416
Use After Free
|
CVE-2026-5943
|
2026-04-30 02:18 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
847
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performin…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-7393
|
2026-04-30 02:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
848
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function delete_supplier of the file /ajax.php?action=delete_supplier. Such manipulation of …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7392
|
2026-04-30 02:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
849
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function save_supplier of the file /ajax.php?action=save_supplier. This manipulation of the argument …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7391
|
2026-04-30 02:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
850
|
6.1 |
MEDIUM
Local
|
artifex
|
mupdf
|
A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulatio…
|
CWE-119 CWE-125
Incorrect Access of Indexable Resource ('Range Error') Out-of-bounds Read
|
CVE-2026-7233
|
2026-04-30 02:15 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|