Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-25850 — filemanagement_storage_service has an improper preservation of permissions vulnerability

in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak

openharmony | Information Disclosure
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.4 HIGH
CVE-2026-25781 — kernel_liteos_a has an out-of-bounds write vulnerability

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.

openharmony | Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
3.3 LOW
CVE-2026-25110 — Sensors_medical_sensor has a NULL pointer dereference vulnerability

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

openharmony | Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.1 HIGH
CVE-2026-24792 — web_webview has a Race Condition vulnerability

in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.

openharmony | Remote | Memory Corruption
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.3 HIGH
CVE-2026-22069 — O+ Connect Local Privilege Escalation Vulnerability

A local privilege escalation vulnerability exists in O+ Connect because it fails to validate the identity of the caller on the pipe interface.

| Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.0 MEDIUM
CVE-2026-33514 — Discourse: Information Disclosure in Form Template API Due to Missing Authorization

Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, an authenticated user on a Discourse instance with the form templates feature…

discourse | Remote | Authorization
May 19, 2026 Jun 01, 2026
May 19, 2026
Jun 01, 2026
5.0 MEDIUM
CVE-2026-33234 — AutoGPT: SendEmailBlock's IP blocklist bypass allows SSRF via user-controlled SMTP server

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.1.0 through 0.6.51, SendEmailBlock in autogpt_platform/backen…

autogpt_platform | Remote | Server-Side Request Forgery
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.6 HIGH
CVE-2026-33233 — AutoGPT Platform: Remote Code Execution via Unsafe Pickle Deserialization of Redis Cache …

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.6.34 through 0.6.51, the backend deserializes Redis cache byte…

autogpt_platform | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.5 HIGH
CVE-2026-33232 — AutoGPT: Unauthenticated DoS via Disk Space Exhaustion

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.4.2 through 0.6.51 are vulnerable to an unauthenticated Denial of…

autogpt_platform | Remote | Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.3 MEDIUM
CVE-2026-33052 — MantisBT: Authorization Bypass in Global Profile Creation

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authenticated user assigned the "add_profile_threshold" permission to create a global …

mantisbt | Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.8 HIGH
CVE-2026-32323 — Mullvad VPN for macOS: Local Privilege Escalation via unverified bundle path in installer

Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may allow local privilege escalation during installation or upgrade. The installer…

mullvad_vpn | Authorization
May 19, 2026 May 22, 2026
May 19, 2026
May 22, 2026
5.1 MEDIUM
CVE-2026-32312 — GLPI: Unauthorized export of form structure

GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue…

glpi | Remote | Authorization
May 19, 2026 May 21, 2026
May 19, 2026
May 21, 2026
5.3 MEDIUM
CVE-2026-32244 — Discourse: Cached outdated summaries can leak removed content

Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summaries can leak removed content to anonymous and unpriv…

discourse | Remote | Information Disclosure
May 19, 2026 Jun 01, 2026
May 19, 2026
Jun 01, 2026
7.1 HIGH
CVE-2026-30950 — AutoGPT has Authenticated Session Hijacking via IDOR

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijac…

autogpt_platform | Remote | Authentication
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
3.9 LOW
CVE-2026-27964 — FacturaScripts: Reflected Cross-Site Scripting (XSS) via Cookie Manipulation

FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNick cookie parameter. The app…

facturascripts | Cross-Site Scripting
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-27892 — FacturaScripts: Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/D…

FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images byte-for-byte, without stripping EXIF/XMP/IPTC meta…

facturascripts | Remote | Information Disclosure
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
7.2 HIGH
CVE-2026-27891 — Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism

FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the …

facturascripts | Remote | Path Traversal
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-27737 — BigBlueButton has Stored XSS in bbb-playback replay

BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public chat. This allowed for a malicio…

bigbluebutton | Remote | Cross-Site Scripting
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
8.6 HIGH
CVE-2026-8851 — SOGo < 5.12.8 SQL Injection via addUserInAcls endpoint

SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database b…

Remote | Injection
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
9.8 CRITICAL
CVE-2026-8838 — Remote Code Execution via eval() Injection in amazon-redshift-python-driver

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary …

May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
Showing 20 of 7162 Results