CVE Vulnerability Database

Search and browse 381,181 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-67296HIGH8.7FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to valid...
CVE-2026-67295MEDIUM6.3FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to...
CVE-2026-67294CRITICAL9.3FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-si...
CVE-2026-67293CRITICAL9.3FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. ...
CVE-2026-67292CRITICAL9.3FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/cor...
CVE-2026-67291HIGH8.7FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments...
CVE-2026-67290HIGH8.7FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG...
CVE-2026-67289CRITICAL9.8FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controll...
CVE-2026-67288HIGH8.7FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept ...
CVE-2026-66402CRITICAL9.8FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in ...
CVE-2026-66401LOW2.4FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fail...
CVE-2026-2411MEDIUM6.5Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose...
CVE-2026-10773MEDIUM5.4The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const c...
CVE-2026-10772Rejected reason: ** DUPLICATE ** This CVE Record has been rejected by the Zephyr Project CNA. CVE-2026-10772 was assigne...
CVE-2025-71404MEDIUM5.1better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the ...
CVE-2025-71403HIGH7.1better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute ...
CVE-2025-71402LOW2better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-ou...
CVE-2026-18536HIGH7.5Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource:...
CVE-2026-6453MEDIUM6.5The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. Thi...
CVE-2026-18435MEDIUM6.4The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-18344MEDIUM6.1The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' par...
CVE-2026-18062MEDIUM6.4The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-18059MEDIUM5.3The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exp...
CVE-2026-17605MEDIUM6.6The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Incl...
CVE-2026-17580MEDIUM6.5The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elem...