CVE Database

137969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-33841
7.8 HIGH

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-33840
7.8 HIGH

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-33839
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-33838
7.8 HIGH

Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-33837
7.8 HIGH

Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-33835
7.8 HIGH

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-33834
7.8 HIGH

Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-33833
8.2 HIGH

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over …

May 12, 2026
CVE-2026-33821
7.7 HIGH

Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.

May 12, 2026
CVE-2026-33117
9.1 CRITICAL

Improper authentication in Azure SDK allows an unauthorized attacker to bypass a security feature over a network.

May 12, 2026
CVE-2026-33112
8.8 HIGH

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

May 12, 2026
CVE-2026-33110
8.8 HIGH

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

May 12, 2026
CVE-2026-32209
4.4 MEDIUM

Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.

May 12, 2026
CVE-2026-32204
7.8 HIGH

External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-32185
5.5 MEDIUM

Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.

May 12, 2026
CVE-2026-32177
7.3 HIGH

Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-32175
4.3 MEDIUM

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories …

May 12, 2026
CVE-2026-32170
6.7 MEDIUM

Double free in Windows Rich Text Edit Control allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-32161
7.5 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an …

May 12, 2026
CVE-2026-31245
5.3 MEDIUM

The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary …

May 12, 2026
CVE-2026-31244
6.5 MEDIUM

The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories/{memory_id}). The endpoint allows unauthenticated users to delete arbitrary …

May 12, 2026
CVE-2026-31243
6.5 MEDIUM

The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functionality accessible via the DELETE /memories endpoint. An unauthenticated …

May 12, 2026
CVE-2026-31242
9.1 CRITICAL

The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send …

May 12, 2026
CVE-2026-31241
6.5 MEDIUM

The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory …

May 12, 2026
CVE-2026-31240
7.5 HIGH

The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are …

May 12, 2026
CVE-2026-31239
9.8 CRITICAL

The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hub. The MambaLMHeadModel.from_pretrained() method uses torch.load() …

May 12, 2026
CVE-2026-31238
9.8 CRITICAL

The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. When starting a model server with the ludwig serve …

May 12, 2026
CVE-2026-31237
9.8 CRITICAL

The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When a user provides a dataset file path to the …

May 12, 2026
CVE-2026-31236
9.8 CRITICAL

The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument. This argument is intended to allow users to …

May 12, 2026
CVE-2026-31235
9.8 CRITICAL

The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py module. The class uses Python's pickle module to …

May 12, 2026
CVE-2026-31234
9.8 CRITICAL

Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. The KVStore server, used for distributed task coordination, lacks authentication …

May 12, 2026
CVE-2026-31233
9.8 CRITICAL

Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the …

May 12, 2026
CVE-2026-31232
8.8 HIGH

The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading process. When loading model files (.pt) from a …

May 12, 2026
CVE-2026-31231
9.8 CRITICAL

Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. The endpoint is designed to execute arbitrary Python …

May 12, 2026
CVE-2026-31230
9.8 CRITICAL

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_evaluation_fgsm_pytorch.py). The script uses the unsafe eval() function …

May 12, 2026
CVE-2026-31229
9.8 CRITICAL

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality. When loading model weights from …

May 12, 2026
CVE-2026-29204
9.1 CRITICAL

Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized …

May 12, 2026
CVE-2026-26083
9.8 CRITICAL

A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox …

May 12, 2026
CVE-2026-25690
4.3 MEDIUM

An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3, FortiDeceptor 5.2.0 through …

May 12, 2026
CVE-2026-25088
5.4 MEDIUM

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiNDR 7.6.0 through 7.6.2, FortiNDR 7.4.0 through 7.4.9, FortiNDR …

May 12, 2026
CVE-2026-21530
6.7 MEDIUM

Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-20767
7.8 HIGH

Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow an escalation of privilege. …

May 12, 2026
CVE-2026-20714
7.8 HIGH

Out-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a escalation of privilege. Unprivileged …

May 12, 2026
CVE-2025-67604
5.3 MEDIUM

A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, …

May 12, 2026
CVE-2025-53870
6.7 MEDIUM

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, …

May 12, 2026
CVE-2025-53844
8.8 HIGH

A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or …

May 12, 2026
CVE-2025-53681
7.2 HIGH

An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through …

May 12, 2026
CVE-2025-53680
6.7 MEDIUM

An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 …

May 12, 2026
CVE-2025-46311
7.5 HIGH

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS …

May 12, 2026
CVE-2025-43524
8.8 HIGH

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app …

May 12, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.