CVE Vulnerability Database
Search and browse 381,181 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67296 | HIGH | 8.7 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to valid... |
| CVE-2026-67295 | MEDIUM | 6.3 | 0.2% | Aug 1, 2026 | FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to... |
| CVE-2026-67294 | CRITICAL | 9.3 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-si... |
| CVE-2026-67293 | CRITICAL | 9.3 | 0.2% | Aug 1, 2026 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. ... |
| CVE-2026-67292 | CRITICAL | 9.3 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/cor... |
| CVE-2026-67291 | HIGH | 8.7 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments... |
| CVE-2026-67290 | HIGH | 8.7 | 0.4% | Aug 1, 2026 | FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG... |
| CVE-2026-67289 | CRITICAL | 9.8 | 0.4% | Aug 1, 2026 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controll... |
| CVE-2026-67288 | HIGH | 8.7 | 0.4% | Aug 1, 2026 | FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept ... |
| CVE-2026-66402 | CRITICAL | 9.8 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in ... |
| CVE-2026-66401 | LOW | 2.4 | 0.2% | Aug 1, 2026 | FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fail... |
| CVE-2026-2411 | MEDIUM | 6.5 | 0.1% | Aug 1, 2026 | Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose... |
| CVE-2026-10773 | MEDIUM | 5.4 | 0.2% | Aug 1, 2026 | The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const c... |
| CVE-2026-10772 | — | — | — | Aug 1, 2026 | Rejected reason: ** DUPLICATE ** This CVE Record has been rejected by the Zephyr Project CNA. CVE-2026-10772 was assigne... |
| CVE-2025-71404 | MEDIUM | 5.1 | 0.4% | Aug 1, 2026 | better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the ... |
| CVE-2025-71403 | HIGH | 7.1 | 0.2% | Aug 1, 2026 | better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute ... |
| CVE-2025-71402 | LOW | 2 | 0.2% | Aug 1, 2026 | better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-ou... |
| CVE-2026-18536 | HIGH | 7.5 | 0.2% | Aug 1, 2026 | Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource:... |
| CVE-2026-6453 | MEDIUM | 6.5 | 0.3% | Aug 1, 2026 | The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. Thi... |
| CVE-2026-18435 | MEDIUM | 6.4 | 0.2% | Aug 1, 2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2026-18344 | MEDIUM | 6.1 | 0.2% | Aug 1, 2026 | The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' par... |
| CVE-2026-18062 | MEDIUM | 6.4 | 0.2% | Aug 1, 2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2026-18059 | MEDIUM | 5.3 | 0.3% | Aug 1, 2026 | The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exp... |
| CVE-2026-17605 | MEDIUM | 6.6 | 0.7% | Aug 1, 2026 | The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Incl... |
| CVE-2026-17580 | MEDIUM | 6.5 | 0.3% | Aug 1, 2026 | The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elem... |
