Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.2 MEDIUM
CVE-2026-67293 — FreeRDP before 3.29.0 Improper Certificate Hostname Validation

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) trea…

freerdp | Remote | Cryptography
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.5 MEDIUM
CVE-2026-67292 — FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure

FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte respon…

freerdp | Remote | Information Disclosure
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-67291 — FreeRDP before 3.29.0 Heap Out-of-Bounds Read via GLYPH_FRAGMENT_ADD

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYP…

freerdp | Remote | Memory Corruption
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-67290 — FreeRDP before 3.29.0 Heap Out-of-Bounds Read via TSMF

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malforme…

freerdp | Remote | Memory Corruption
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
9.8 CRITICAL
CVE-2026-67289 — FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client…

freerdp | Remote | Server-Side Request Forgery
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-67288 — FreeRDP before 3.29.0 Denial of Service via smartcard cache

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRIT…

freerdp | Remote | Memory Corruption
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
9.8 CRITICAL
CVE-2026-66402 — FreeRDP before 3.29.0 TLS Certificate Identity Validation Bypass

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names().…

freerdp | Remote | Authentication
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
2.1 LOW
CVE-2026-66401 — FreeRDP before 3.29.0 Out-of-Bounds Read via UVC H.264

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attack…

freerdp | Memory Corruption
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.5 MEDIUM
CVE-2026-2411 — Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, bypassing encr…

Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose permission is hard-coded to BT_GATT_PERM_READ, and a Characteristic Value attr…

zephyr zephyr | Authorization
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
5.4 MEDIUM
CVE-2026-10773 — Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name)

The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char * name table after a faulty bounds check. The guard used msg_type <= sizeof…

zephyr zephyr | Denial of Service
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
5.1 MEDIUM
CVE-2025-71404 — better-auth before 1.1.16 Reflected XSS via error parameter

better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where the value of the 'error' URL parameter is reflected…

better-auth\/oauth-provider | Remote | Cross-Site Scripting
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.1 HIGH
CVE-2025-71403 — better-auth before 1.1.20 Open Redirect via trustedOrigins Bypass

better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parame…

better-auth\/oauth-provider | Remote | Authentication
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
2.0 LOW
CVE-2025-71402 — better-auth before 1.4.0 Session Revocation via Forged Cookie

better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-out after-hook, which trusts raw multi-session cookies and forwards extracted val…

better-auth\/oauth-provider | Remote | Authentication
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
0.0 NA
CVE-2026-18536 — Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are a…

| Misconfiguration
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.5 MEDIUM
CVE-2026-6453 — CubeWP Framework <= 1.1.30 - Authenticated (Subscriber+) SQL Injection via 'relation_id' …

The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. This is due to insufficient input sanitization in the cubewp_remove_relation() AJA…

cubewp | Remote | Injection
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.4 MEDIUM
CVE-2026-18435 — Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 't…

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'toggleIcon' Block Attribute in all versions up to, and including,…

gutenberg_blocks_with_ai | Remote | Cross-Site Scripting
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.1 MEDIUM
CVE-2026-18344 — Responsive Thumbnail Slider < 1.1.53 - Reflected Cross-Site Scripting via 'id' Parameter

The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. This is due to insufficient in…

Remote | Cross-Site Scripting
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.4 MEDIUM
CVE-2026-18062 — Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via …

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Identity Block Inner Image Content in all versions up to, and incl…

gutenberg_blocks_with_ai | Remote | Cross-Site Scripting
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
5.3 MEDIUM
CVE-2026-18059 — PixelYourSite <= 11.2.1 - Unauthenticated Sensitive Information Exposure via Order-Receiv…

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.2.1 via the getWooPurchaseEventP…

Remote | Information Disclosure
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.6 MEDIUM
CVE-2026-17605 — Payment forms, Buy now buttons, and Invoicing System | GetPaid <= 2.8.56 - Authenticated …

The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form…

Remote | Path Traversal
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
Showing 20 of 9300 Results