Threats Tagged 'cwe-356'
View all threats tagged with 'cwe-356'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-356'
Click on any threat for detailed analysis and mitigation recommendations
0 Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, when asking for allowance. Further it does not show after the tool was being invoked, which parameters were used. Thus, maybe unwanted or even malicious values could be used without the user having a chance to notice it. Patched in Zed Editor 0.219.4 which includes expandable tool call details. Join the discussion | CVE Database V5 | 02/10/2026, 17:27:49 UTC Added: 02/10/2026, 17:46:41 UTC |
0 Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Soda PDF Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Word files. The issue results from allowing the execution of dangerous script without user warning. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27496. Join the discussion | CVE Database V5 | 12/23/2025, 21:24:58 UTC Added: 12/23/2025, 21:45:57 UTC |
0 Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Soda PDF Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the implementation of the Launch action. The issue results from allowing the execution of dangerous script without user warning. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27494. Join the discussion | CVE Database V5 | 12/23/2025, 21:24:19 UTC Added: 12/23/2025, 21:31:00 UTC |
0 CVE-2025-14412 is a high-severity vulnerability in Soda PDF Desktop version 14.0.509.23030 that allows remote code execution via malicious XLS files. The flaw arises because the product UI fails to warn users about unsafe actions when handling XLS files containing dangerous scripts. Exploitation requires user interaction, such as opening a crafted XLS file or visiting a malicious page. Successful exploitation enables attackers to execute arbitrary code with the privileges of the current user, potentially compromising confidentiality, integrity, and availability. No known exploits are currently reported in the wild. Organizations using this specific Soda PDF Desktop version should be vigilant and apply mitigations promptly to prevent compromise. Join the discussion | CVE Database V5 | 12/23/2025, 21:24:04 UTC Added: 12/23/2025, 21:31:00 UTC |
0 pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XLS files. The issue results from allowing the execution of dangerous script without user warning. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27502. Join the discussion | CVE Database V5 | 12/23/2025, 21:22:46 UTC Added: 12/23/2025, 21:31:00 UTC |
0 pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the implementation of the Launch action. The issue results from allowing the execution of dangerous script without user warning. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27501. Join the discussion | CVE Database V5 | 12/23/2025, 21:22:39 UTC Added: 12/23/2025, 21:31:00 UTC |
0 pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of DOC files. The issue results from allowing the execution of dangerous script without user warning. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27503. Join the discussion | CVE Database V5 | 12/23/2025, 21:22:31 UTC Added: 12/23/2025, 21:31:00 UTC |
0 PDFsam Enhanced XLS File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDFsam Enhanced. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XLS files. The issue results from allowing the execution of dangerous script without user warning. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27498. Join the discussion | CVE Database V5 | 12/23/2025, 21:21:19 UTC Added: 12/23/2025, 21:30:58 UTC |
0 PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDFsam Enhanced. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the implementation of the Launch action. The issue results from allowing the execution of dangerous script without user warning. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27500. Join the discussion | CVE Database V5 | 12/23/2025, 21:21:15 UTC Added: 12/23/2025, 21:30:58 UTC |
0 PDFsam Enhanced DOC File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDFsam Enhanced. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of DOC files. The issue results from allowing the execution of dangerous script without user warning. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27499. Join the discussion | CVE Database V5 | 12/23/2025, 21:21:10 UTC Added: 12/23/2025, 21:30:58 UTC |
Showing 1 to 10 of 11 results