CWE-356: CWE-356

17
Total CVEs
0
Critical
14
High
7.4
Avg CVSS

Yearly Trend

2026
2
2025
13
2024
1
2022
1

Top Affected Vendors

1 Pdfsam 3
2 Sodapdf 3
3 Pdfforge 3
4 Fedoraproject 1
5 Mozilla 1
6 Debian 1
7 Rarlab 1
8 Jetbrains 1
9 Ni 1
10 Libreoffice 1

All CWE-356 CVEs (17)

CVE-2025-2450
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems running NI Vision Builder AI by tricking users into opening malicious ...

Mar 18, 2025
CVE-2025-3909
8.1

This vulnerability in Thunderbird allows attackers to execute JavaScript in the file:/// context by crafting a malicious email attachment. When Thunde...

May 14, 2025
CVE-2025-3839
8.0

Epiphany browser's external URL handler feature can be abused to exploit vulnerabilities in external applications, making them appear remotely exploit...

Jan 23, 2026
CVE-2026-0777
7.8

This vulnerability allows remote attackers to execute arbitrary code on Xmind installations by tricking users into opening malicious attachments. The ...

Feb 20, 2026
CVE-2025-14412
7.8

This vulnerability in Soda PDF Desktop allows remote attackers to execute arbitrary code by tricking users into opening malicious XLS files. The softw...

Dec 23, 2025
CVE-2025-14414
7.8

This vulnerability in Soda PDF Desktop allows remote attackers to execute arbitrary code by tricking users into opening malicious Word files. The soft...

Dec 23, 2025
CVE-2025-14415
7.8

This vulnerability in Soda PDF Desktop allows remote attackers to execute arbitrary code by tricking users into opening malicious files or visiting ma...

Dec 23, 2025
CVE-2025-14417
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of pdfforge PDF Architect. Attackers can e...

Dec 23, 2025
CVE-2025-14403
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDFsam Enhanced. Attackers can exploit ...

Dec 23, 2025
CVE-2022-35873
7.8

This vulnerability allows remote attackers to execute arbitrary code on Inductive Automation Ignition installations by tricking users into opening mal...

Jul 25, 2022
CVE-2025-14416
7.0

This vulnerability in pdfforge PDF Architect allows remote attackers to execute arbitrary code by tricking users into opening malicious DOC files. The...

Dec 23, 2025
CVE-2025-14418
7.0

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of pdfforge PDF Architect. Attackers can e...

Dec 23, 2025
CVE-2025-14402
7.0

This vulnerability in PDFsam Enhanced allows remote attackers to execute arbitrary code by tricking users into opening malicious DOC files. The softwa...

Dec 23, 2025
CVE-2025-14404
7.0

PDFsam Enhanced has a remote code execution vulnerability in its XLS file processing. Attackers can execute arbitrary code by tricking users into open...

Dec 23, 2025
CVE-2025-31334
6.8

This vulnerability allows attackers to bypass Windows' 'Mark of the Web' security warnings by tricking users into opening malicious symbolic links in ...

Apr 3, 2025
CVE-2024-3044
6.5

This vulnerability in LibreOffice allows attackers to embed malicious scripts in documents that execute automatically when users click on graphics, by...

May 14, 2024
CVE-2025-58335
5.5

This vulnerability in JetBrains Junie allows attackers to access sensitive information through the search_project function. It affects users running v...

Aug 28, 2025

About CWE-356 (CWE-356)

Our database tracks 17 CVEs classified as CWE-356, with 0 rated critical and 14 rated high severity. The average CVSS score for CWE-356 vulnerabilities is 7.4.

External reference: View CWE-356 on MITRE CWE →

Monitor CWE-356 Vulnerabilities

Get alerted when new CWE-356 CVEs affect your infrastructure.

Start Monitoring Free