CVE Vulnerability Database

Search and browse 398,020 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-36510MEDIUM6.8Improper buffer restrictions for some Display Virtualization for Windows OS driver software within Ring 2: Device Driver...
CVE-2025-35991MEDIUM5.6Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an informat...
CVE-2025-35990HIGH8.8Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring ...
CVE-2025-35979MEDIUM6.8Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient executio...
CVE-2025-35969MEDIUM5.4Uncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version 16.0.12. within Ring 3...
CVE-2025-27723MEDIUM6.8Use after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Ke...
CVE-2026-43515CRITICAL9.1Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Ap...
CVE-2026-43514LOW3.7Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomca...
CVE-2026-43513HIGH7.5Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat:...
CVE-2026-43512CRITICAL9.8DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Ap...
CVE-2026-42498HIGH7.3Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomca...
CVE-2026-41293CRITICAL9.8Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0...
CVE-2026-41284HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: ...
CVE-2026-34187CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph containe...
CVE-2026-31228CRITICAL9.8The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow comp...
CVE-2026-31226CRITICAL9.8The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injec...
CVE-2026-31225HIGH8.8The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing compone...
CVE-2026-31224HIGH8.8The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier...
CVE-2026-31223HIGH8.8The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler...
CVE-2026-31222HIGH8.8The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() meth...
CVE-2026-31221HIGH7.8PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoi...
CVE-2026-31220CRITICAL9.8PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient val...
CVE-2026-31219HIGH8.8The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370...
CVE-2026-31218HIGH8.8The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370...
CVE-2026-31217CRITICAL9.8The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370...