Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,046
Quick preset (or use dates below)
Clear Filters
Showing 3,101 - 3,120 of 13,527 CVEs
CVE-2026-31379 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue aff...

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31378 MEDIUM - 6.5

Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-29220 MEDIUM - 6.5

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-29207 MEDIUM - 6.5

Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. Please note that in the updated version, "Data Resource" re...

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-44408 MEDIUM - 6.3

There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker canΒ  modify configuration through the interface.

Vendor: ZTE
Product: MU5250
Published: May 19, 2026
Source: NVD
CVE-2026-8922 MEDIUM - 5.4

A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Keycloak's OpenID Connect (OIDC) Introspection feature fails to properly honor the realm-level policy. This allows tokens that should have been revoked to remain active, potentia...

Published: May 19, 2026
Source: NVD
CVE-2026-47317 MEDIUM - 5.5

Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Excessive Allocation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

Vendor: Samsung Open Source
Product: Escargot
Published: May 19, 2026
Source: NVD
CVE-2026-47316 MEDIUM - 5.5

Improper Check or Handling of Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

Vendor: Samsung Open Source
Product: Escargot
Published: May 19, 2026
Source: NVD
CVE-2026-47315 MEDIUM - 5.5

Improper Check for Unusual or Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

Vendor: Samsung Open Source
Product: Escargot
Published: May 19, 2026
Source: NVD
CVE-2026-47313 MEDIUM - 5.5

Memory allocation with excessive size value vulnerability in Samsung Open Source Escargot allows Excessive Allocation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

Vendor: Samsung Open Source
Product: Escargot
Published: May 19, 2026
Source: NVD
CVE-2026-47312 MEDIUM - 5.5

Release of invalid pointer or reference vulnerability in Samsung Open Source Escargot allows Buffer Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

Vendor: Samsung Open Source
Product: Escargot
Published: May 19, 2026
Source: NVD
CVE-2026-8830 MEDIUM - 4.3

A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occurs because the server-side processAction() fails to validate that the newly created credential's parameters, such as public...

Published: May 19, 2026
Source: NVD
CVE-2026-8814 MEDIUM - 5.3

Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in maximum decompressed output size. When asynchronous parsing is enabled, a crafted PNG file containin...

Vendor: npm
Product: exifreader
Published: May 19, 2026
Source: NVD
CVE-2026-47309 MEDIUM - 5.5

Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Oversized Serialized Data Payloads. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

Vendor: Samsung Open Source
Product: Escargot
Published: May 19, 2026
Source: NVD
CVE-2026-47308 MEDIUM - 5.5

NULL pointer dereference vulnerability in Samsung Open Source Walrus allows Pointer Manipulation. This issue affects Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9.

Vendor: Samsung Open Source
Product: Walrus
Published: May 19, 2026
Source: NVD
CVE-2026-32994 MEDIUM - 5.3

The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any authenticated user to retrieve the full content of any message from any room (private groups, direct messages, channels) by simply ...

Vendor: Rocket.Chat
Product: Rocket.Chat
Published: May 19, 2026
Source: NVD
CVE-2026-47307 MEDIUM - 5.5

NULL pointer dereference vulnerability in Samsung Open Source Walrus allows an attacker to cause a denial of service via a crafted WebAssembly module containing deeply nested instructions. This issue affects Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9.

Vendor: Samsung Open Source
Product: Walrus
Published: May 19, 2026
Source: NVD
CVE-2026-28733 MEDIUM - 6.5

in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD
CVE-2026-27766 MEDIUM - 5.5

in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD
CVE-2026-25850 MEDIUM - 5.5

in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD