Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-67308 — Wazuh GitHub Actions Shell Injection via Fork Pull Request

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json file…

Remote | Injection
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.3 MEDIUM
CVE-2026-67307 — Wazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory Sync

Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, while validating only the agentid against …

Remote | Misconfiguration
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
5.4 MEDIUM
CVE-2026-67306 — FreeRDP before 3.29.0 Out-of-Bounds Read via Planar RLE

FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder functions planar_decompress_plane_rle and planar_decompress_plane_rle_only in lib…

Remote | Memory Corruption
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
9.4 CRITICAL
CVE-2026-67305 — FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-p…

Remote | Memory Corruption
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-67304 — FreeRDP before 3.29.0 NULL Dereference via smartcard cleanup

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP reques…

Remote | Memory Corruption
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
4.3 MEDIUM
CVE-2026-67303 — FreeRDP before 3.29.0 Denial of Service via serial DeviceControl

FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == BytesReturned)) in serial_process_irp_device_control() in channels/serial/client/serial_main.c. When serial de…

Remote | Denial of Service
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
4.3 MEDIUM
CVE-2026-67302 — FreeRDP rdpecam StartStreamsRequest divide-by-zero denial of service

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redirection client. ecam_dev_process_start_streams_request() parses a server-controll…

Remote | Denial of Service
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-67301 — FreeRDP before 3.29.0 Out-of-bounds Read via Polygon async message-proxy

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp…

Remote | Memory Corruption
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-67300 — FreeRDP before 3.29.0 Use-After-Free via async message proxy

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. W…

Remote | Memory Corruption
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-67299 — FreeRDP before 3.29.0 Use-After-Free via WindowIcon async message

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_W…

Remote | Memory Corruption
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-67298 — FreeRDP 3.28.0 Heap Buffer Overflow via RAIL orderLength Underflow

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL …

Remote | Memory Corruption
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-67297 — FreeRDP before 3.29.0 Resource Exhaustion via chunked HTTP response

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway end…

Remote | Denial of Service
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-67296 — FreeRDP before 3.29.0 Denial of Service via RDPEI PDU

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client ca…

Remote | Denial of Service
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.3 MEDIUM
CVE-2026-67295 — FreeRDP before 3.29.0 Path Traversal via drive redirection

FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. A malicious RD…

Remote | Path Traversal
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
5.9 MEDIUM
CVE-2026-67294 — FreeRDP before 3.29.0 TLS Certificate EKU Bypass

FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication. In x509_utils_verify(), when server-purpose (X509…

Remote | Authentication
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
4.2 MEDIUM
CVE-2026-67293 — FreeRDP before 3.29.0 Improper Certificate Hostname Validation

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) trea…

Remote | Cryptography
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.5 MEDIUM
CVE-2026-67292 — FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure

FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte respon…

Remote | Information Disclosure
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-67291 — FreeRDP before 3.29.0 Heap Out-of-Bounds Read via GLYPH_FRAGMENT_ADD

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYP…

Remote | Memory Corruption
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-67290 — FreeRDP before 3.29.0 Heap Out-of-Bounds Read via TSMF

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malforme…

Remote | Memory Corruption
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
9.8 CRITICAL
CVE-2026-67289 — FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client…

Remote | Server-Side Request Forgery
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
Showing 20 of 9350 Results