CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-70870 json | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Web Client - Unicode... | |
| CVE-2026-60970 json | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Sup... | |
| CVE-2026-60958 json | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Sup... | |
| CVE-2026-60947 json | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Sup... | |
| CVE-2026-60946 json | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Sup... | |
| CVE-2026-60921 json | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Sup... | |
| CVE-2026-60916 json | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Sup... | |
| CVE-2026-60866 json | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). The supp... | |
| CVE-2026-77815 json | to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does... | |
| CVE-2026-77814 json | is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(... | |
| CVE-2026-77812 json | DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption... | |
| CVE-2026-77087 json | Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary ... | |
| CVE-2026-75501 json | A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote attack... | |
| CVE-2026-63343 json | Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yam... | |
| CVE-2026-63125 json | Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user... | |
| CVE-2026-62941 json | Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, th... | |
| CVE-2026-62940 json | Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluste... | |
| CVE-2026-62867 json | Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.... | |
| CVE-2026-62313 json | Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricted.con... | |
| CVE-2026-55622 json | Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for insta... | |
| CVE-2026-55621 json | Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custo... | |
| CVE-2026-50278 json | iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a... | |
| CVE-2026-77645 json | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability ma... | |
| CVE-2026-77029 json | Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66 | |
| CVE-2026-59318 json | In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enfo... | |
| CVE-2026-59308 json | In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts cou... | |
| CVE-2026-59279 json | The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it ... | |
| CVE-2026-48769 json | Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus ... | |
| CVE-2026-48756 json | Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in... | |
| CVE-2026-48755 json | Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup ... | |
| CVE-2026-48754 json | Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromBackup... | |
| CVE-2026-48753 json | Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerabl... | |
| CVE-2026-48752 json | Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup... | |
| CVE-2026-48751 json | Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.co... | |
| CVE-2026-48750 json | Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/insta... | |
| CVE-2026-48749 json | Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to rea... | |
| CVE-2026-47753 json | Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `in... | |
| CVE-2026-70859 json | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affe... | |
| CVE-2026-70857 json | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affe... | |
| CVE-2026-70853 json | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported v... | |
| CVE-2026-70851 json | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported v... | |
| CVE-2026-70850 json | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported v... | |
| CVE-2026-69550 json | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | |
| CVE-2026-67446 json | Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attachments... | |
| CVE-2026-65770 json | Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassa... | |
| CVE-2026-55894 json | Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() functi... | |
| CVE-2026-54509 json | TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src/rout... | |
| CVE-2026-50192 json | Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path... | |
| CVE-2026-21580 json | This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced... | |
| CVE-2026-19449 json | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to exec... | |
| CVE-2026-19446 json | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a rea... | |
| CVE-2026-18840 json | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improper validati... | |
| CVE-2026-61265 json | Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Secur... | |
| CVE-2026-61258 json | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported v... | |
| CVE-2026-61248 json | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported v... | |
| CVE-2026-61241 json | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported v... | |
| CVE-2026-61231 json | Vulnerability in the Oracle Virtual Directory product of Oracle Fusion Middleware (component: Virtual Directory Server). Sup... | |
| CVE-2026-61118 json | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versi... | |
| CVE-2026-61066 json | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versi... | |
| CVE-2026-61003 json | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Suppo... | |
| CVE-2026-61002 json | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). Supported versions that a... | |
| CVE-2026-61001 json | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Sup... | |
| CVE-2026-60998 json | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active Direc... | |
| CVE-2026-60971 json | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Sup... | |
| CVE-2026-60956 json | Vulnerability in the JD Edwards EnterpriseOne US Payroll product of Oracle JD Edwards (component: Payroll). The supported v... | |
| CVE-2026-60915 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-60895 json | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions ... | |
| CVE-2026-60889 json | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions ... | |
| CVE-2026-60853 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-60850 json | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions ... | |
| CVE-2026-60841 json | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions ... | |
| CVE-2026-60830 json | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are a... | |
| CVE-2026-60822 json | Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Ag... | |
| CVE-2026-60808 json | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Email Marketing). Supported versions t... | |
| CVE-2026-60803 json | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that ar... | |
| CVE-2026-60769 json | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported ve... | |
| CVE-2026-60720 json | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versi... | |
| CVE-2025-9566 json | There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file ... | |
| CVE-2026-76366 json | In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (REST)... | |
| CVE-2026-76365 json | In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Structur... | |
| CVE-2026-76362 json | In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOAR and... | |
| CVE-2026-76356 json | In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Aut... | |
| CVE-2026-70856 json | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supported versions that are ... | |
| CVE-2026-62594 json | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions t... | |
| CVE-2026-62587 json | Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). Supported versions t... | |
| CVE-2026-62586 json | Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). Supported versions t... | |
| CVE-2026-62585 json | Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). Supported versions t... | |
| CVE-2026-60865 json | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported... | |
| CVE-2026-60861 json | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported... | |
| CVE-2026-60860 json | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported... | |
| CVE-2026-8497 json | Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and ... | |
| CVE-2023-54357 json | Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to ... | |
| CVE-2026-76370 json | In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use the Representational State... | |
| CVE-2026-76369 json | In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automatio... | |
| CVE-2026-76368 json | In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permission could view metadata ... | |
| CVE-2026-76367 json | In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role could store JavaScript in a n... | |
| CVE-2026-76364 json | In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Structur... | |
| CVE-2026-76363 json | In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run arbitrary Structured Query Lan... | |
| CVE-2026-76361 json | In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../check_... | |
| CVE-2026-76360 json | In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to gathe... |