CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-66038 json FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder...
CVE-2026-65705 json FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows a...
CVE-2026-64785 json SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach ...
CVE-2026-64624 json FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire...
CVE-2026-56820 json Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2...
CVE-2026-55626 json xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the ...
CVE-2026-48034 json Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior ...
CVE-2026-47870 json VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access ma...
CVE-2026-47670 json DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RC...
CVE-2026-47669 json DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/...
CVE-2026-46737 json Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST...
CVE-2026-43820 json NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a bu...
CVE-2026-16401 json Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16372 json Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153...
CVE-2026-16366 json Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16365 json Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-15665 json The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2026-42574 json apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1....
CVE-2026-42571 json Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 t...
CVE-2026-42562 json Plainpad is a self hosted note taking app. Prior to version 1.1.1, Plainpad allows a low-privilege authenticated user to self...
CVE-2026-42560 json auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, t...
CVE-2026-42461 json Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.18.0, four GET endpo...
CVE-2026-42333 json Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to version...
CVE-2026-42311 json Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead ...
CVE-2026-42310 json Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that ...
CVE-2026-42309 json Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs...
CVE-2026-42308 json Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, ...
CVE-2026-42301 json pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI packa...
CVE-2026-3828 json Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution du...
CVE-2026-42556 json Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can cr...
CVE-2026-42456 json AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. P...
CVE-2026-42455 json Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In version...
CVE-2026-42297 json Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version...
CVE-2026-42295 json Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version...
CVE-2026-42183 json Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version...
CVE-2026-41311 json LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.7, a circular bloc...
CVE-2026-41163 json bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is instal...
CVE-2026-42454 json Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to versio...
CVE-2026-42451 json Grimmory is a self-hosted digital library. Prior to version 2.3.1, a stored cross-site scripting (XSS) vulnerability in Grimm...
CVE-2026-42354 json Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulner...
CVE-2026-42352 json pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, O...
CVE-2026-42351 json pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, a...
CVE-2026-42350 json Kargo manages and automates the promotion of software artifacts. Prior to versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2, Kargo i...
CVE-2026-42346 json Postiz is an AI social media scheduling tool. From version 2.16.6 to before version 2.21.7, all SSRF protections added in v2....
CVE-2026-42345 json FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/s...
CVE-2026-42344 json FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/s...
CVE-2026-42343 json FastGPT is an AI Agent building platform. In versions 4.14.13 and prior, the code-sandbox component suffers from insufficient...
CVE-2026-42339 json New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-a...
CVE-2026-42307 json Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in t...
CVE-2026-42302 json FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of Fast...
CVE-2026-42298 json Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish...
CVE-2026-41950 json Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full co...
CVE-2026-40331 json Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7....
CVE-2026-40330 json Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7....
CVE-2026-40110 json Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses...
CVE-2026-40075 json OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 th...
CVE-2026-40068 json In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file w...
CVE-2026-39849 json Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the ...
CVE-2026-39402 json lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line()...
CVE-2026-39383 json Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can fo...
CVE-2026-35579 json CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations i...
CVE-2026-35527 json Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an ou...
CVE-2026-42167 json mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there i...
CVE-2026-41649 json Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0.86.0...
CVE-2026-41446 json Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that re...
CVE-2026-41372 json OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass o...
CVE-2026-40560 json Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly pr...
CVE-2026-40329 json Masa CMS is an open source content management system. In versions 7.5.2 and earlier, a SQL injection vulnerability exists in ...
CVE-2026-40280 json Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists for the...
CVE-2026-38947 json FluentCMS 1.2.3 is vulnerable to Cross Site Scripting (XSS) in TextHTML plugin.
CVE-2026-38432 json ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permi...
CVE-2026-38431 json ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or...
CVE-2026-38429 json OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing ...
CVE-2026-35397 json Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in...
CVE-2026-41371 json OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers...
CVE-2026-41370 json OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary fil...
CVE-2026-41369 json OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter ...
CVE-2026-41368 json OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails to b...
CVE-2026-41367 json OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and...
CVE-2026-41366 json OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that allows m...
CVE-2026-41365 json OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph API. ...
CVE-2026-41364 json OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers t...
CVE-2026-41363 json OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploadInpu...
CVE-2026-41362 json OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation vulnerability in the Zalo webhook replay-ded...
CVE-2026-40976 json In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. Fo...
CVE-2026-39399 json
CVE-2026-39387 json BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versio...
CVE-2026-35589 json nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability ex...
CVE-2026-35034 json Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability in t...
CVE-2026-35033 json Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read...
CVE-2026-35032 json Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3...
CVE-2026-35031 json Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle ...
CVE-2026-40683 json In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when ...
CVE-2026-40291 json Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object modifica...
CVE-2026-40037 json OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allow...
CVE-2026-40036 json Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attac...
CVE-2026-40035 json Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by...
CVE-2026-40032 json UAC (Unix-like Artifacts Collector) before 3.3.0-rc1 contains a command injection vulnerability in the placeholder substituti...
CVE-2026-39907 json Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP p...
CVE-2026-39906 json Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that a...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report