Products: 4
    Vulnerabilities: 20
    Known Exploited: 0
    1
    Critical Level Threats
    5
    High Level Threats
    13
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-63729

    TeX Live SyncTeX Parser Heap Use-After-Free via Malformed SyncTeX File

    Last Modified: Jul 30, 2026
    Published: Jul 21, 2026

    CVE-2023-46048

    Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c. NOTE: this is disputed because it should be categorized as a usability problem.

    Last Modified: Apr 15, 2026
    Published: Mar 27, 2024

    CVE-2024-25262

    texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted TTF file.

    Last Modified: Apr 15, 2026
    Published: Feb 20, 2024

    CVE-2023-32700

    texlive: arbitrary code execution allows document complied with older version

    Last Modified: Jan 31, 2025
    Published: May 20, 2023

    CVE-2023-32668

    LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted by default, as stated in the documentation. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

    Last Modified: Nov 03, 2025
    Published: May 11, 2023
    Items Per Page
    Tug Vulnerabilities & Security CVEs | CVE-DB