|
281
|
5.5 |
MEDIUM
Local
|
-
|
-
|
in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.
New
|
CWE-364
Signal Handler Race Condition
|
CVE-2026-27766
|
2026-05-19 23:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282
|
3.3 |
LOW
Local
|
-
|
-
|
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-27781
|
2026-05-19 23:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283
|
6.5 |
MEDIUM
Local
|
-
|
-
|
in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution.
New
|
CWE-416
Use After Free
|
CVE-2026-28733
|
2026-05-19 23:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284
|
3.3 |
LOW
Local
|
-
|
-
|
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
New
|
CWE-20
Improper Input Validation
|
CVE-2026-28751
|
2026-05-19 23:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285
|
3.3 |
LOW
Local
|
-
|
-
|
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
New
|
CWE-364
Signal Handler Race Condition
|
CVE-2026-33565
|
2026-05-19 23:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary …
New
|
CWE-94
Code Injection
|
CVE-2026-8838
|
2026-05-19 23:24 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287
|
- |
|
-
|
-
|
Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering
The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cxf-rest, CxfHeaderFil…
New
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-2026-47323
|
2026-05-19 23:23 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288
|
7.3 |
HIGH
Network
|
-
|
-
|
Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections.
The values from the set_add method were not checked for newlines, colons or pipes. Metrics generated from untrusted sour…
New
|
CWE-93
CRLF Injection
|
CVE-2026-8788
|
2026-05-19 23:16 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289
|
9.8 |
CRITICAL
Network
|
radare
|
radare2
|
radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbi…
Update
|
CWE-416
Use After Free
|
CVE-2026-8696
|
2026-05-19 23:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290
|
- |
|
-
|
-
|
Rejected reason: Voluntarily withdrawn
New
|
-
|
CVE-2026-6354
|
2026-05-19 23:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|