Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,985
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,301 - 3,320 of 12,514 CVEs
CVE-2026-22069 HIGH - 7.3

A local privilege escalation vulnerability exists in O+ Connect because it fails to validate the identity of the caller on the pipe interface.

Vendor: OPPO
Product: O+ Connect
Published: May 19, 2026
Source: NVD
CVE-2026-33233 HIGH - 7.6

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.6.34 through 0.6.51, the backend deserializes Redis cache bytes using pickle.loads without integrity/authenticity checks. The write path serializes values with pic...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: May 19, 2026
Source: NVD
CVE-2026-33232 HIGH - 7.5

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.4.2 through 0.6.51 are vulnerable to an unauthenticated Denial of Service (DoS) through the server due to uncontrolled disk space consumption. The download_agent_file...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: May 19, 2026
Source: NVD
CVE-2026-32323 HIGH - 7.3

Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may allow local privilege escalation during installation or upgrade. The installer package executes binaries from /Applications/Mullvad VPN.app without verifying if the bundle is atta...

Vendor: mullvad
Product: mullvadvpn-app
Published: May 19, 2026
Source: NVD
CVE-2026-30950 HIGH - 7.1

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijacking via IDOR. If an authenticated attacker can determine the session_id of another user's sessi...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: May 18, 2026
Source: NVD
CVE-2026-8851 HIGH - 8.1

SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL subqueries through the uid parameter of the addUserInAcls endpoint. Attackers can inj...

Published: May 18, 2026
Source: NVD
CVE-2026-4137 HIGH - 7.0

In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates temporary directories with world-writable permissions (0o777), and the `_create_model_downloading_tmp_dir()` function in `mlflow/pyfunc/__init__.py` creates directories with ...

Published: May 18, 2026
Source: NVD
CVE-2026-46522 HIGH - 7.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a missing check in the MIFF decoder, a crafted file could cause an infinite loop resulting in CPU exhaustion. Versions 7.1.2.23 and 6.9.13-48 fix the issue.

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-46520 HIGH - 7.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when reading multiple images with different dimensions an out of bounds heap write can occur. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-45367 HIGH - 7.5

HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

Vendor: maven
Product: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2
Published: May 18, 2026
Source: GitHub
CVE-2026-45553 HIGH - 7.5

NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without disabling file insertion directives. When a NiceGUI application passes attacker-controlled content to ui.restructured_text(), an attacker can use standar...

Vendor: pip
Product: nicegui
Published: May 18, 2026
Source: GitHub
CVE-2026-45686 HIGH - 7.5

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's memcached text protocol parser can crash the OBI process and cause denial of service. When parsing mem...

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45685 HIGH - 7.5

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught panics in the MongoDB TCP parser, allowing a remote unauthenticated attacker to crash the telemetry a...

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-47092 HIGH - 7.8

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment variable. Attackers can set COMSPEC to an arbitrary binary path before claude-hud performs its version ch...

Vendor: jarrodwatts
Product: claude-hud
Published: May 18, 2026
Source: NVD
CVE-2026-45245 HIGH - 7.4

Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon requests using stored tokens without verifying event trustworthiness. ...

Vendor: steipete
Product: summarize
Published: May 18, 2026
Source: NVD
CVE-2026-45242 HIGH - 7.1

Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write files to arbitrary directories by supplying an absolute path or directory traversal sequence in the slidesDir request parameter. Attackers can exploit thi...

Vendor: steipete
Product: summarize
Published: May 18, 2026
Source: NVD
CVE-2026-45495 HIGH - 8.8

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Vendor: microsoft
Product: edge_chromium
Published: May 18, 2026
Source: NVD
CVE-2026-29963 HIGH - 7.5

HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text parameter is used to construct file paths without adequate normalization or restriction to a safe base directory. A remote attacker can exploit this fl...

Vendor: hsclabs
Product: mailinspector
Published: May 18, 2026
Source: NVD
CVE-2026-29962 HIGH - 7.5

HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controlled parameters that directly affect file access operations without adequate validation, sanitization, ...

Vendor: hsclabs
Product: mailinspector
Published: May 18, 2026
Source: NVD
CVE-2026-45678 HIGH - 7.5

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a valid NUL-terminated portal name. A crafted empty or unterminated payload can make OBI slice beyond the e...

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub