Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-47307 — Samsung Open Source Walrus Null Pointer Dereference Denial of Service Vulnerability

NULL pointer dereference vulnerability in Samsung Open Source Walrus allows an attacker to cause a denial of service via a crafted WebAssembly module containing deeply nested instructions. This issu…

| Memory Corruption
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
3.3 LOW
CVE-2026-33565 — kernel_linux_common_modules has a Race Condition vulnerability

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

| Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
3.3 LOW
CVE-2026-28751 — filemanagement_storage_service has an improper input validation vulnerability

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

| Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-28733 — filemanagement_storage_service has an use after free vulnerability

in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution.

| Memory Corruption
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
3.3 LOW
CVE-2026-27781 — kernel_liteos_a has an integer overflow vulnerability

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

| Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.5 MEDIUM
CVE-2026-27766 — multimedia_audio_framework has a Race Condition vulnerability

in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.

| Information Disclosure
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.8 HIGH
CVE-2026-27648 — web_webview has an out-of-bounds write vulnerability

in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.

Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.5 MEDIUM
CVE-2026-25850 — filemanagement_storage_service has an improper preservation of permissions vulnerability

in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak

| Information Disclosure
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.4 HIGH
CVE-2026-25781 — kernel_liteos_a has an out-of-bounds write vulnerability

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.

| Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
3.3 LOW
CVE-2026-25110 — Sensors_medical_sensor has a NULL pointer dereference vulnerability

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

| Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.1 HIGH
CVE-2026-24792 — web_webview has a Race Condition vulnerability

in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.

Remote | Memory Corruption
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.3 HIGH
CVE-2026-22069 — O+ Connect Local Privilege Escalation Vulnerability

A local privilege escalation vulnerability exists in O+ Connect because it fails to validate the identity of the caller on the pipe interface.

| Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.0 MEDIUM
CVE-2026-33514 — Discourse: Information Disclosure in Form Template API Due to Missing Authorization

Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, an authenticated user on a Discourse instance with the form templates feature…

Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.0 MEDIUM
CVE-2026-33234 — AutoGPT: SendEmailBlock's IP blocklist bypass allows SSRF via user-controlled SMTP server

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.1.0 through 0.6.51, SendEmailBlock in autogpt_platform/backen…

Remote | Server-Side Request Forgery
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.6 HIGH
CVE-2026-33233 — AutoGPT Platform: Remote Code Execution via Unsafe Pickle Deserialization of Redis Cache …

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.6.34 through 0.6.51, the backend deserializes Redis cache byte…

| Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.5 HIGH
CVE-2026-33232 — AutoGPT: Unauthenticated DoS via Disk Space Exhaustion

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.4.2 through 0.6.51 are vulnerable to an unauthenticated Denial of…

Remote | Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.3 MEDIUM
CVE-2026-33052 — MantisBT: Authorization Bypass in Global Profile Creation

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authenticated user assigned the "add_profile_threshold" permission to create a global …

mantisbt | Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.3 HIGH
CVE-2026-32323 — Mullvad VPN for macOS: Local Privilege Escalation via unverified bundle path in installer

Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may allow local privilege escalation during installation or upgrade. The installer…

| Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.1 MEDIUM
CVE-2026-32312 — GLPI: Unauthorized export of form structure

GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue…

Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.3 MEDIUM
CVE-2026-32244 — Discourse: Cached outdated summaries can leak removed content

Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summaries can leak removed content to anonymous and unpriv…

Remote | Information Disclosure
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
Showing 20 of 6279 Results