|
3101
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Keycloak's OpenID Connect (OIDC) Introspection feature fails to properly honor the…
|
CWE-303
Incorrect Implementation of Authentication Algorithm
|
CVE-2026-8922
|
2026-05-19 23:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3102
|
8.1 |
HIGH
Network
|
-
|
-
|
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
|
CWE-364
Signal Handler Race Condition
|
CVE-2026-24792
|
2026-05-19 23:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3103
|
3.3 |
LOW
Local
|
-
|
-
|
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-25110
|
2026-05-19 23:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3104
|
8.4 |
HIGH
Local
|
-
|
-
|
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.
|
CWE-787
Out-of-bounds Write
|
CVE-2026-25781
|
2026-05-19 23:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3105
|
5.5 |
MEDIUM
Local
|
-
|
-
|
in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak
|
CWE-281
Improper Preservation of Permissions
|
CVE-2026-25850
|
2026-05-19 23:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3106
|
8.8 |
HIGH
Network
|
-
|
-
|
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
|
CWE-787
Out-of-bounds Write
|
CVE-2026-27648
|
2026-05-19 23:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3107
|
5.5 |
MEDIUM
Local
|
-
|
-
|
in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.
|
CWE-364
Signal Handler Race Condition
|
CVE-2026-27766
|
2026-05-19 23:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3108
|
3.3 |
LOW
Local
|
-
|
-
|
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-27781
|
2026-05-19 23:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3109
|
6.5 |
MEDIUM
Local
|
-
|
-
|
in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution.
|
CWE-416
Use After Free
|
CVE-2026-28733
|
2026-05-19 23:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3110
|
3.3 |
LOW
Local
|
-
|
-
|
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
|
CWE-20
Improper Input Validation
|
CVE-2026-28751
|
2026-05-19 23:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|