CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-34342
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-34341
7.0 HIGH

Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-34340
7.0 HIGH

Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-34338
7.8 HIGH

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-34337
7.8 HIGH

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-34336
7.8 HIGH

Buffer over-read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

May 12, 2026
CVE-2026-34334
7.8 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-34333
7.8 HIGH

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-34332
8.0 HIGH

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.

May 12, 2026
CVE-2026-34331
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-34330
7.8 HIGH

Integer overflow or wraparound in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-34329
8.8 HIGH

Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network.

May 12, 2026
CVE-2026-33841
7.8 HIGH

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-33840
7.8 HIGH

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-33839
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-33838
7.8 HIGH

Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-33837
7.8 HIGH

Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-33835
7.8 HIGH

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-33834
7.8 HIGH

Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-33833
8.2 HIGH

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over …

May 12, 2026
CVE-2026-33821
7.7 HIGH

Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.

May 12, 2026
CVE-2026-33112
8.8 HIGH

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

May 12, 2026
CVE-2026-33110
8.8 HIGH

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

May 12, 2026
CVE-2026-32204
7.8 HIGH

External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-32177
7.3 HIGH

Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-32161
7.5 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an …

May 12, 2026
CVE-2026-31240
7.5 HIGH

The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are …

May 12, 2026
CVE-2026-31232
8.8 HIGH

The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading process. When loading model files (.pt) from a …

May 12, 2026
CVE-2026-20767
7.8 HIGH

Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow an escalation of privilege. …

May 12, 2026
CVE-2026-20714
7.8 HIGH

Out-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a escalation of privilege. Unprivileged …

May 12, 2026
CVE-2025-53844
8.8 HIGH

A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or …

May 12, 2026
CVE-2025-53681
7.2 HIGH

An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through …

May 12, 2026
CVE-2025-46311
7.5 HIGH

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS …

May 12, 2026
CVE-2025-43524
8.8 HIGH

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app …

May 12, 2026
CVE-2026-5089
7.3 HIGH

YAML::Syck versions before 1.38 for Perl has an out-of-bounds read. The base60 (sexagesimal) parsing code in perl_syck.h has a buffer underflow bug in both int#base60 …

May 12, 2026
CVE-2026-43993
8.2 HIGH

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the WAVS bridge's computeDataVerify called fetch() on agent-supplied URLs without validating scheme, …

May 12, 2026
CVE-2026-43991
8.4 HIGH

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, substring-based blocklist in plugin-shell's command-safety check could be bypassed by adversarial argument …

May 12, 2026
CVE-2026-43990
8.4 HIGH

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped every agent-supplied command in 'sh -c' / 'cmd /C' …

May 12, 2026
CVE-2026-43989
8.5 HIGH

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a filesystem path from the agent and …

May 12, 2026
CVE-2026-43513
7.5 HIGH

Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from …

May 12, 2026
CVE-2026-42498
7.3 HIGH

Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from …

May 12, 2026
CVE-2026-41284
7.5 HIGH

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from …

May 12, 2026
CVE-2026-31225
8.8 HIGH

The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing component. The _parse_op_part() function in query.py uses the unsafe …

May 12, 2026
CVE-2026-31224
8.8 HIGH

The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier.load() method of the MultitaskClassifier class. The method loads model weight files …

May 12, 2026
CVE-2026-31223
8.8 HIGH

The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler.load() method of the BaseLabeler class. The method loads serialized labeler …

May 12, 2026
CVE-2026-31222
8.8 HIGH

The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer class. The method loads model checkpoint files …

May 12, 2026
CVE-2026-31221
7.8 HIGH

PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load …

May 12, 2026
CVE-2026-31219
8.8 HIGH

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CWE-502). When a user provides …

May 12, 2026
CVE-2026-31218
8.8 HIGH

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CWE-502). When loading a model …

May 12, 2026
CVE-2026-30810
8.8 HIGH

Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800

May 12, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.