CVSS v3
7.8
HIGH
EPSS Score
19.5%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can execute local files and bypass the security dialog.
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can execute local files and bypass the security dialog.
Active exploitation of CVE-2020-14425 has not been confirmed. The EPSS score is 19.5%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2020-14425 has a CVSS v3 base score of 7.8 (HIGH severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).