CVE Tools

Freerdp

236 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Freerdp, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.

Freerdp CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Freerdp CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-051
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-121
2026-0117
2026-0227
2026-0317
2026-041
2026-055
2026-060
2026-078
2026-0834
2026-0922

Severity

How the 236 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical4921%
  • High6829%
  • Medium8737%
  • Low3113%

Latest CVEs

The 15 most recently published vulnerabilities affecting Freerdp.

  1. CVE-2026-91964FreeRDP 2.0.0 through 3.30.0 Heap Buffer Overflow via RoutingToken8.8
  2. CVE-2026-91963FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc6.5
  3. CVE-2026-91961FreeRDP before 3.31.0 Denial of Service via URBDRC6.5
  4. CVE-2026-91962FreeRDP before 3.31.0 Integer Overflow via audin Apple backends6.3
  5. CVE-2026-91960FreeRDP before 3.31.0 Integer Overflow Double Free6.5
  6. CVE-2026-91959FreeRDP before 3.31.0 Buffer Over-read via RTS Gateway6.5
  7. CVE-2026-91958FreeRDP 3.11.0 through 3.30.0 Heap Buffer Overflow via Monitor Index6.6
  8. CVE-2026-91957FreeRDP before 3.31.0 Use-After-Free via smartcard worker3.1
  9. CVE-2026-91956FreeRDP before 3.31.0 Out-of-Bounds Read via URBDRC6.5
  10. CVE-2026-91955FreeRDP before 3.31.0 Denial of Service via Desktop Dimensions7.5
  11. CVE-2026-91954FreeRDP before 3.31.0 NULL Pointer Dereference via NSCodec6.5
  12. CVE-2026-91952FreeRDP before 3.31.0 Denial of Service via pool_decode_rect6.5
  13. CVE-2026-91953FreeRDP before 3.31.0 Heap Buffer Overflow via LB_LOAD_BALANCE_INFO6.5
  14. CVE-2026-91951FreeRDP 3.14.0 through 3.30.0 Out-of-bounds Write via urbdrc6.5
  15. CVE-2026-91949FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass9.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store