CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-85444 json MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that...
CVE-2026-85439 json MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() ...
CVE-2026-85434 json MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attack...
CVE-2026-85429 json MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from th...
CVE-2026-85424 json MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with ful...
CVE-2026-85225 json A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the...
CVE-2026-9736 json IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due t...
CVE-2026-85395 json UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin ...
CVE-2026-85390 json Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion ro...
CVE-2026-85207 json A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the fi...
CVE-2026-63376 json toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a t...
CVE-2026-33630 json c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-com...
CVE-2026-85309 json Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access C...
CVE-2026-85305 json Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress...
CVE-2026-85236 json A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a sta...
CVE-2026-85137 json A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_n...
CVE-2026-84847 json Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
CVE-2026-84812 json Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.
CVE-2026-84774 json Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.
CVE-2026-84766 json Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
CVE-2026-84758 json Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.
CVE-2026-84753 json Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
CVE-2026-82023 json LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated...
CVE-2026-81773 json Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
CVE-2026-81281 json Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.
CVE-2026-79419 json A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vu...
CVE-2026-75602 json OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api...
CVE-2026-85210 json Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered use...
CVE-2026-85179 json Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal ser...
CVE-2026-85174 json SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search reque...
CVE-2026-85164 json WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpo...
CVE-2026-85159 json AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cancelUri ...
CVE-2026-85154 json WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revoca...
CVE-2026-85106 json A vulnerability has been found in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file apps...
CVE-2026-75036 json A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet control...
CVE-2026-75035 json A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ...
CVE-2026-71222 json A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metada...
CVE-2026-56126 json pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject arbit...
CVE-2026-55658 json Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with cus...
CVE-2026-85090 json FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444...
CVE-2026-85030 json A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32ced735adf7c19ed8175adb1c8df. The affected element is an ...
CVE-2026-84886 json A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageData of...
CVE-2026-84841 json A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipu...
CVE-2026-84381 json HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/...
CVE-2026-75135 json UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover th...
CVE-2026-74769 json Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API...
CVE-2026-66786 json A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Cus...
CVE-2026-53671 json PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstract tr...
CVE-2026-17084 json The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint at...
CVE-2026-86100 json Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL...
CVE-2026-52777 json YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability...
CVE-2026-52775 json YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL...
CVE-2026-52774 json YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter...
CVE-2026-52773 json YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflect...
CVE-2026-52772 json YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field...
CVE-2026-52771 json YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates...
CVE-2026-52770 json YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable t...
CVE-2026-52769 json YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox...
CVE-2026-52767 json YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() ...
CVE-2026-52766 json YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamed...
CVE-2026-52763 json YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts...
CVE-2026-52762 json YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injecti...
CVE-2026-86098 json ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that write...
CVE-2026-86097 json PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_back...
CVE-2026-86096 json PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race conditi...
CVE-2026-86095 json Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attr...
CVE-2026-48019 json Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's em...
CVE-2026-86091 json ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-adminis...
CVE-2026-86090 json ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authe...
CVE-2026-82684 json Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could...
CVE-2026-77393 json In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated...
CVE-2026-76925 json A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.Sy...
CVE-2026-75925 json Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as r...
CVE-2026-78012 json An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the ...
CVE-2026-69249 json python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42...
CVE-2026-61884 json The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on firs...
CVE-2026-55985 json The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a c...
CVE-2026-46636 json Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() uncond...
CVE-2026-85787 json An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version...
CVE-2026-85704 json A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue ...
CVE-2026-85703 json A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is...
CVE-2026-85702 json A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affe...
CVE-2026-85701 json A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affec...
CVE-2026-82712 json Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This ...
CVE-2026-79426 json An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated...
CVE-2026-79423 json An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers...
CVE-2026-77847 json Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. Thi...
CVE-2026-75439 json An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component
CVE-2026-75438 json Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_pa...
CVE-2026-53769 json Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct ...
CVE-2026-50894 json easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface wh...
CVE-2026-19795 json Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY payloa...
CVE-2025-67066 json SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype par...
CVE-2022-26961 json Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IB...
CVE-2025-70082 json The administrator password can be changed without knowledge of the current password. When chained with an authentication bypa...
CVE-2025-67041 json An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser pag...
CVE-2025-67039 json An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending...
CVE-2025-67038 json An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user'...
CVE-2025-67037 json An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" pa...
CVE-2025-67036 json An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their n...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report