Total CVEs

133,052

Critical Severity

2,915

High Severity

10,581

Last 7 Days

2,055
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,961 - 2,980 of 29,457 CVEs
CVE-2026-8830 MEDIUM - 4.3

A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occurs because the server-side processAction() fails to validate that the newly created credential's parameters, such as public...

Published: May 19, 2026
Source: NVD
CVE-2026-8814 MEDIUM - 5.3

Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in maximum decompressed output size. When asynchronous parsing is enabled, a crafted PNG file containin...

Vendor: npm
Product: exifreader
Published: May 19, 2026
Source: NVD
CVE-2026-8813 HIGH - 7.5

This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the same record and appends entries to an array without sufficient b...

Vendor: npm
Product: exifreader
Published: May 19, 2026
Source: NVD
CVE-2026-47311 HIGH - 7.8

Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

Vendor: Samsung Open Source
Product: Escargot
Published: May 19, 2026
Source: NVD
CVE-2026-47310 HIGH - 7.8

Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

Vendor: Samsung Open Source
Product: Escargot
Published: May 19, 2026
Source: NVD
CVE-2026-47309 MEDIUM - 5.5

Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Oversized Serialized Data Payloads. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

Vendor: Samsung Open Source
Product: Escargot
Published: May 19, 2026
Source: NVD
CVE-2025-15609 HIGH - 7.5

The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allowing them to query Fortis' API and retrieve sensitive customer information, like past orders, PII, etc.

Vendor: Unknown
Product: Fortis for WooCommerce
Published: May 19, 2026
Source: NVD
CVE-2026-47308 MEDIUM - 5.5

NULL pointer dereference vulnerability in Samsung Open Source Walrus allows Pointer Manipulation. This issue affects Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9.

Vendor: Samsung Open Source
Product: Walrus
Published: May 19, 2026
Source: NVD
CVE-2026-32994 MEDIUM - 5.3

The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any authenticated user to retrieve the full content of any message from any room (private groups, direct messages, channels) by simply ...

Vendor: Rocket.Chat
Product: Rocket.Chat
Published: May 19, 2026
Source: NVD
CVE-2026-47307 MEDIUM - 5.5

NULL pointer dereference vulnerability in Samsung Open Source Walrus allows an attacker to cause a denial of service via a crafted WebAssembly module containing deeply nested instructions. This issue affects Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9.

Vendor: Samsung Open Source
Product: Walrus
Published: May 19, 2026
Source: NVD

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD
CVE-2026-28733 MEDIUM - 6.5

in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD
CVE-2026-27766 MEDIUM - 5.5

in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD
CVE-2026-27648 HIGH - 8.8

in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD
CVE-2026-25850 MEDIUM - 5.5

in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD
CVE-2026-25781 HIGH - 8.4

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD
CVE-2026-24792 HIGH - 8.1

in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD