Total CVEs

131,459

Critical Severity

2,797

High Severity

9,990

Last 7 Days

1,107
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,381 - 1,400 of 27,864 CVEs

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD
CVE-2026-27766 MEDIUM - 5.5

in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD
CVE-2026-27648 HIGH - 8.8

in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD
CVE-2026-25850 MEDIUM - 5.5

in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD
CVE-2026-25781 HIGH - 8.4

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD
CVE-2026-24792 HIGH - 8.1

in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD
CVE-2026-22069 HIGH - 7.3

A local privilege escalation vulnerability exists in O+ Connect because it fails to validate the identity of the caller on the pipe interface.

Vendor: OPPO
Product: O+ Connect
Published: May 19, 2026
Source: NVD

Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, an authenticated user on a Discourse instance with the form templates feature enabled can read the name and structured content of form templates that are intended exclusively for...

Vendor: discourse
Product: discourse
Published: May 19, 2026
Source: NVD
CVE-2026-33234 MEDIUM - 5.0

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.1.0 through 0.6.51, SendEmailBlock in autogpt_platform/backend/backend/blocks/email_block.py accepts a user-supplied smtp_server (string) and smtp_port (integer) ...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: May 19, 2026
Source: NVD
CVE-2026-33233 HIGH - 7.6

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.6.34 through 0.6.51, the backend deserializes Redis cache bytes using pickle.loads without integrity/authenticity checks. The write path serializes values with pic...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: May 19, 2026
Source: NVD
CVE-2026-33232 HIGH - 7.5

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.4.2 through 0.6.51 are vulnerable to an unauthenticated Denial of Service (DoS) through the server due to uncontrolled disk space consumption. The download_agent_file...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: May 19, 2026
Source: NVD
CVE-2026-32323 HIGH - 7.3

Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may allow local privilege escalation during installation or upgrade. The installer package executes binaries from /Applications/Mullvad VPN.app without verifying if the bundle is atta...

Vendor: mullvad
Product: mullvadvpn-app
Published: May 19, 2026
Source: NVD
CVE-2026-32312 MEDIUM - 4.3

GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue has been fixed in version 11.0.7.

Vendor: glpi-project
Product: glpi
Published: May 19, 2026
Source: NVD
CVE-2026-32244 MEDIUM - 5.3

Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summaries can leak removed content to anonymous and unprivileged users who cannot regenerate summaries. This issue has been fixed in versions 2026.1.4, 2026.3....

Vendor: discourse
Product: discourse
Published: May 19, 2026
Source: NVD
CVE-2026-30950 HIGH - 7.1

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijacking via IDOR. If an authenticated attacker can determine the session_id of another user's sessi...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: May 18, 2026
Source: NVD
CVE-2026-27737 MEDIUM - 6.5

BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public chat. This allowed for a malicious actor to craft and carry out a targeted XSS attack, activated on anyone replaying the recordi...

Vendor: bigbluebutton, blindsidenetworks
Product: bigbluebutton, scalite, bbb-playback
Published: May 18, 2026
Source: NVD
CVE-2026-8851 HIGH - 8.1

SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL subqueries through the uid parameter of the addUserInAcls endpoint. Attackers can inj...

Published: May 18, 2026
Source: NVD
CVE-2026-8838 CRITICAL - 9.8

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate this issue, users should upgrade to version 2.1.14.

Published: May 18, 2026
Source: NVD
CVE-2026-4137 HIGH - 7.0

In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates temporary directories with world-writable permissions (0o777), and the `_create_model_downloading_tmp_dir()` function in `mlflow/pyfunc/__init__.py` creates directories with ...

Published: May 18, 2026
Source: NVD