CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-27766
5.5 MEDIUM

in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.

May 19, 2026
CVE-2026-27648
8.8 HIGH

in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.

May 19, 2026
CVE-2026-25850
5.5 MEDIUM

in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak

May 19, 2026
CVE-2026-25781
8.4 HIGH

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.

May 19, 2026
CVE-2026-25110
3.3 LOW

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

May 19, 2026
CVE-2026-24792
8.1 HIGH

in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.

May 19, 2026
CVE-2026-22069
7.3 HIGH

A local privilege escalation vulnerability exists in O+ Connect because it fails to validate the identity of the caller on the pipe interface.

May 19, 2026
CVE-2026-33514

Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, an authenticated user on a Discourse instance with the form …

May 19, 2026
CVE-2026-33234
5.0 MEDIUM

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.1.0 through 0.6.51, SendEmailBlock in autogpt_platform/backend/backend/blocks/email_block.py accepts a …

May 19, 2026
CVE-2026-33233
7.6 HIGH

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.6.34 through 0.6.51, the backend deserializes Redis cache …

May 19, 2026
CVE-2026-33232
7.5 HIGH

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.4.2 through 0.6.51 are vulnerable to an unauthenticated Denial …

May 19, 2026
CVE-2026-33052

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authenticated user assigned the "add_profile_threshold" permission to create …

May 19, 2026
CVE-2026-32323
7.3 HIGH

Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may allow local privilege …

May 19, 2026
CVE-2026-32312
4.3 MEDIUM

GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the …

May 19, 2026
CVE-2026-32244
5.3 MEDIUM

Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summaries can leak removed content to anonymous …

May 19, 2026
CVE-2026-30950
7.1 HIGH

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijacking …

May 18, 2026
CVE-2026-27964
3.9 LOW

FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNick cookie parameter. …

May 18, 2026
CVE-2026-27892
6.5 MEDIUM

FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images byte-for-byte, without stripping …

May 18, 2026
CVE-2026-27891
7.2 HIGH

FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to …

May 18, 2026
CVE-2026-27737
6.5 MEDIUM

BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public chat. This …

May 18, 2026
CVE-2026-8851
8.1 HIGH

SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data …

May 18, 2026
CVE-2026-8838
9.8 CRITICAL

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute …

May 18, 2026
CVE-2026-4137
7.0 HIGH

In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates temporary directories with world-writable permissions (0o777), and the `_create_model_downloading_tmp_dir()` function in `mlflow/pyfunc/__init__.py` creates …

May 18, 2026
CVE-2026-27130
9.9 CRITICAL

Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues …

May 18, 2026
CVE-2026-26978

FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially …

May 18, 2026
CVE-2026-25244
9.8 CRITICAL

WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection …

May 18, 2026
CVE-2026-22810
8.2 HIGH

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability …

May 18, 2026
CVE-2026-47092
7.8 HIGH

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC …

May 18, 2026
CVE-2026-47091
3.3 LOW

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path …

May 18, 2026
CVE-2026-47090
4.6 MEDIUM

Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd and branchUrl values without stripping control characters …

May 18, 2026
CVE-2026-45246
5.5 MEDIUM

Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite path that allows local users to read sensitive credentials by …

May 18, 2026
CVE-2026-45245
7.4 HIGH

Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing …

May 18, 2026
CVE-2026-45244
5.4 MEDIUM

Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automation actions without per-call user approval when the extension automation …

May 18, 2026
CVE-2026-21789
4.6 MEDIUM

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

May 18, 2026
CVE-2025-65954
6.1 MEDIUM

SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout …

May 18, 2026
CVE-2026-8836
9.8 CRITICAL

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing …

May 18, 2026
CVE-2026-45243
6.1 MEDIUM

Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages to perform unauthorized operations on automation …

May 18, 2026
CVE-2026-45242
7.1 HIGH

Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write files to arbitrary directories by …

May 18, 2026
CVE-2026-45231
6.1 MEDIUM

DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, description, modelNumber, serialNumber, and tags that are stored without server-side sanitization …

May 18, 2026
CVE-2026-45495
8.8 HIGH

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

May 18, 2026
CVE-2026-45494
5.4 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

May 18, 2026
CVE-2026-45492
5.4 MEDIUM

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

May 18, 2026
CVE-2026-45230
9.1 CRITICAL

DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary files …

May 18, 2026
CVE-2026-42822
10.0 CRITICAL

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

May 18, 2026
CVE-2026-32849
5.5 MEDIUM

NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where the local variable iov_len is declared as …

May 18, 2026
CVE-2026-32848
4.7 MEDIUM

NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition …

May 18, 2026
CVE-2026-29965
6.1 MEDIUM

HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to improper neutralization of user-supplied input that uses alternate or …

May 18, 2026
CVE-2026-29964
6.1 MEDIUM

HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to improper neutralization of user-controlled input using alternate or obfuscated JavaScript …

May 18, 2026
CVE-2026-29963
7.5 HIGH

HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text parameter is used to …

May 18, 2026
CVE-2026-29962
7.5 HIGH

HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controlled parameters that …

May 18, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.