Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-20717 — Intel QAT Denial of Service Vulnerability

Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with a…

| Denial of Service
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
9.8 CRITICAL
CVE-2025-65719 — Kubernetes Kubectl MCP Server Cross-Site Scripting (XSS)

An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page.

Remote | Cross-Site Scripting
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
5.4 MEDIUM
CVE-2025-36515 — Ring AI Playground Privilege Escalation Vulnerability

Uncontrolled search path for some AI Playground software before version 3.0.0 alpha within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an auth…

| Path Traversal
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
6.8 MEDIUM
CVE-2025-36510 — Windows Display Virtualization for Windows OS Driver Denial of Service Vulnerability

Improper buffer restrictions for some Display Virtualization for Windows OS driver software within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an authen…

| Denial of Service
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
5.6 MEDIUM
CVE-2025-35991 — Intel UEFI Firmware Information Disclosure

Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an information disclosure. System software adversary with a privileged user combined with …

| Information Disclosure
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.7 HIGH
CVE-2025-35990 — Intel Endpoint Management Assistant (EMA) Privilege Escalation Vulnerability

Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged softwar…

| Authorization
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
6.8 MEDIUM
CVE-2025-35979 — Intel(R) Processors VMX Non-Root Guest Information Disclosure Vulnerability

Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Processors within VMX non-root (guest) operation may allow …

| Information Disclosure
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
5.4 MEDIUM
CVE-2025-35969 — Intel Server Firmware Update Utility Software Uncontrolled Search Path Privilege Escalati…

Uncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version 16.0.12. within Ring 3: User Applications may allow an escalation of privilege. System software adver…

| Path Traversal
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
6.8 MEDIUM
CVE-2025-27723 — Intel(R) Ethernet 800 series Linux Kernel "Use After Free" Denial of Service Vulnerability

Use after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an aut…

| Memory Corruption
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
0.0 NA
CVE-2026-43515 — Apache Tomcat: Security constraints not correctly applied

Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21,…

tomcat | Authorization
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
0.0 NA
CVE-2026-43514 — Apache Tomcat: AJP secret compared in non-constant time

Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M…

tomcat | Misconfiguration
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
0.0 NA
CVE-2026-43513 — Apache Tomcat: LockOutRealm treats user names as case-sensitive

Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 …

tomcat | Authentication
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
0.0 NA
CVE-2026-43512 — Apache Tomcat: Digest authenticator will authenticate any unknown user

DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, fr…

tomcat | Authentication
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
7.3 HIGH
CVE-2026-42498 — Apache Tomcat: WebSocket authentication header exposure

Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1…

tomcat | Remote | Authentication
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
0.0 NA
CVE-2026-41293 — Apache Tomcat: HTTP/2 request headers not validated

Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0…

tomcat | Injection
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
7.5 HIGH
CVE-2026-41284 — Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 t…

tomcat | Remote | Denial of Service
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
7.6 HIGH
CVE-2026-34187 — SQL Injection in Graph Container Parameter

Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 through 800

pandora_fms | Remote | Injection
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
9.8 CRITICAL
CVE-2026-31228 — Apache Kubeflow ART Remote Code Execution Vulnerability

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow component. The robustness evaluation function for PyTorch models uses the unsafe ev…

Remote | Injection
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
9.8 CRITICAL
CVE-2026-31226 — "TinyZero HDFS File Operation Utilities Command Injection Vulnerability"

The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injection vulnerability (CWE-78) in its HDFS file operation utilities. The vulnerabi…

Remote | Injection
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.8 HIGH
CVE-2026-31225 — Apache Superduper Remote Code Execution Vulnerability

The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing component. The _parse_op_part() function in query.py uses the unsafe eval() function t…

Remote | Injection
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
Showing 20 of 6350 Results