Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44895
Total
3603
Critical
13333
High
13202
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-72717 | UNKNOWN | — | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a schema … | Aug 19, 2026 |
| CVE-2026-72716 | UNKNOWN | — | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a query … | Aug 19, 2026 |
| CVE-2026-71871 | UNKNOWN | — | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a header … | Aug 19, 2026 |
| CVE-2026-71869 | UNKNOWN | — | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an array … | Aug 19, 2026 |
| CVE-2026-71868 | UNKNOWN | — | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an enum … | Aug 19, 2026 |
| CVE-2026-71867 | UNKNOWN | — | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name … | Aug 19, 2026 |
| CVE-2026-71866 | UNKNOWN | — | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. From version 8.19.0 until 8.21.0, a double quote in a schema … | Aug 19, 2026 |
| CVE-2026-71865 | UNKNOWN | — | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a query parameter name … | Aug 19, 2026 |
| CVE-2026-71864 | UNKNOWN | — | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a header parameter name … | Aug 19, 2026 |
| CVE-2026-69159 | MEDIUM | 5.4 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.29.0, planar_decompress_plane_rle and planar_decompress_plane_rle_only in libfreerdp/codec/planar.c verify that a control byte exists but … | Aug 19, 2026 |
| CVE-2026-67581 | UNKNOWN | — | Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer. MPP.Methods.EVM.verify/2 accepts a … | Aug 19, 2026 |
| CVE-2026-66794 | CRITICAL | 9.3 | A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, … | Aug 19, 2026 |
| CVE-2026-63652 | UNKNOWN | — | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU … | Aug 19, 2026 |
| CVE-2026-63633 | UNKNOWN | — | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded … | Aug 19, 2026 |
| CVE-2026-63117 | MEDIUM | 6.5 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advertise DVI ADPCM with nBlockAlign equal to … | Aug 19, 2026 |
| CVE-2026-62682 | UNKNOWN | — | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in servers[0].url is emitted into … | Aug 19, 2026 |
| CVE-2026-62681 | UNKNOWN | — | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in an OpenAPI path is … | Aug 19, 2026 |
| CVE-2026-62680 | HIGH | 7.1 | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.0, Orval resolves remote and local external $ref values … | Aug 19, 2026 |
| CVE-2026-61518 | HIGH | 8.8 | ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into … | Aug 19, 2026 |
| CVE-2026-55648 | UNKNOWN | — | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in libfreerdp/codec/color.c calculates nWidth multiplied by nHeight multiplied by FreeRDPGetBytesPerPixel(format) in … | Aug 19, 2026 |
| CVE-2026-55564 | MEDIUM | 5.4 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_get function in libfreerdp/cache/glyph.c checks whether index is greater than cache->number … | Aug 19, 2026 |
| CVE-2026-55194 | UNKNOWN | — | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the … | Aug 19, 2026 |
| CVE-2026-55193 | UNKNOWN | — | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c … | Aug 19, 2026 |
| CVE-2026-55192 | UNKNOWN | — | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP H.264 decoder backends can return YUV planes sized from the bitstream … | Aug 19, 2026 |
| CVE-2026-55191 | UNKNOWN | — | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend calculate … | Aug 19, 2026 |