CVE Vulnerability Database
Search and browse 398,020 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36510 | MEDIUM | 6.8 | 0.1% | May 12, 2026 | Improper buffer restrictions for some Display Virtualization for Windows OS driver software within Ring 2: Device Driver... |
| CVE-2025-35991 | MEDIUM | 5.6 | 0.1% | May 12, 2026 | Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an informat... |
| CVE-2025-35990 | HIGH | 8.8 | 0.2% | May 12, 2026 | Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring ... |
| CVE-2025-35979 | MEDIUM | 6.8 | 0.1% | May 12, 2026 | Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient executio... |
| CVE-2025-35969 | MEDIUM | 5.4 | 0.1% | May 12, 2026 | Uncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version 16.0.12. within Ring 3... |
| CVE-2025-27723 | MEDIUM | 6.8 | 0.1% | May 12, 2026 | Use after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Ke... |
| CVE-2026-43515 | CRITICAL | 9.1 | 0.8% | May 12, 2026 | Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Ap... |
| CVE-2026-43514 | LOW | 3.7 | 0.4% | May 12, 2026 | Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomca... |
| CVE-2026-43513 | HIGH | 7.5 | 0.5% | May 12, 2026 | Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat:... |
| CVE-2026-43512 | CRITICAL | 9.8 | 0.9% | May 12, 2026 | DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Ap... |
| CVE-2026-42498 | HIGH | 7.3 | 0.5% | May 12, 2026 | Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomca... |
| CVE-2026-41293 | CRITICAL | 9.8 | 1.0% | May 12, 2026 | Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0... |
| CVE-2026-41284 | HIGH | 7.5 | 0.8% | May 12, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: ... |
| CVE-2026-34187 | CRITICAL | 9.8 | 0.3% | May 12, 2026 | Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph containe... |
| CVE-2026-31228 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow comp... |
| CVE-2026-31226 | CRITICAL | 9.8 | 1.2% | May 12, 2026 | The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injec... |
| CVE-2026-31225 | HIGH | 8.8 | 0.4% | May 12, 2026 | The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing compone... |
| CVE-2026-31224 | HIGH | 8.8 | 0.4% | May 12, 2026 | The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier... |
| CVE-2026-31223 | HIGH | 8.8 | 0.4% | May 12, 2026 | The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler... |
| CVE-2026-31222 | HIGH | 8.8 | 0.4% | May 12, 2026 | The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() meth... |
| CVE-2026-31221 | HIGH | 7.8 | 0.4% | May 12, 2026 | PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoi... |
| CVE-2026-31220 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient val... |
| CVE-2026-31219 | HIGH | 8.8 | 0.6% | May 12, 2026 | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370... |
| CVE-2026-31218 | HIGH | 8.8 | 0.6% | May 12, 2026 | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370... |
| CVE-2026-31217 | CRITICAL | 9.8 | 0.4% | May 12, 2026 | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370... |
