CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-57990 json | Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to dis... | |
| CVE-2026-57989 json | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a net... | |
| CVE-2026-57978 json | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network... | |
| CVE-2026-48561 json | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows a... | |
| CVE-2024-11831 json | A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not prope... | |
| CVE-2026-17497 json | NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitra... | |
| CVE-2026-17496 json | NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DO... | |
| CVE-2025-7195 json | Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a ra... | |
| CVE-2025-7425 json | A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory manage... | |
| CVE-2025-6020 json | A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allow... | |
| CVE-2025-5914 json | A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() fu... | |
| CVE-2025-5318 json | A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handl... | |
| CVE-2025-5278 json | A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The prog... | |
| CVE-2024-12085 json | A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipu... | |
| CVE-2026-10840 json | A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:a... | |
| CVE-2026-17459 json | A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLo... | |
| CVE-2026-17458 json | A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/br... | |
| CVE-2026-9804 json | A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a pa... | |
| CVE-2026-17457 json | A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNaviga... | |
| CVE-2026-7374 json | A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit pe... | |
| CVE-2026-4878 json | A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in t... | |
| CVE-2026-64530 json | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent... | |
| CVE-2026-1784 json | The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that... | |
| CVE-2024-14040 json | In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS networks, ... | |
| CVE-2026-46579 json | A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend do... | |
| CVE-2026-17434 json | A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/... | |
| CVE-2026-17433 json | A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the fi... | |
| CVE-2026-15962 json | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includ... | |
| CVE-2026-17432 json | A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionalit... | |
| CVE-2020-19909 json | Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large value as the retry delay. NOTE: many parties repo... | |
| CVE-2026-2100 json | A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remo... | |
| CVE-2026-16766 json | Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Optio... | |
| CVE-2026-7163 json | A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multiclu... | |
| CVE-2025-11393 json | A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this... | |
| CVE-2026-10681 json | In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread pe... | |
| CVE-2026-66013 json | OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthen... | |
| CVE-2026-66012 json | SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by ... | |
| CVE-2026-66011 json | ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options ar... | |
| CVE-2021-47927 json | WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated atta... | |
| CVE-2021-47926 json | Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inje... | |
| CVE-2021-47925 json | CMDBuild 3.3.2 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject arb... | |
| CVE-2021-47924 json | Ultimate Product Catalogue 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to ... | |
| CVE-2021-47923 json | OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitra... | |
| CVE-2026-42453 json | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to versio... | |
| CVE-2026-42452 json | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to versio... | |
| CVE-2026-32683 json | Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmissio... | |
| CVE-2026-3208 json | The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing ... | |
| CVE-2026-1749 json | There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user t... | |
| CVE-2025-71256 json | In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional ex... | |
| CVE-2025-71253 json | In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional e... | |
| CVE-2025-15634 json | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sen... | |
| CVE-2025-15633 json | An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges ... | |
| CVE-2021-47922 json | Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject ... | |
| CVE-2021-47910 json | AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to in... | |
| CVE-2021-47907 json | Rocket LMS 1.1 contains a persistent cross-site scripting vulnerability in the support ticket module that allows authenticate... | |
| CVE-2026-40934 json | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentic... | |
| CVE-2026-32936 json | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized... | |
| CVE-2026-32934 json | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into u... | |
| CVE-2026-32699 json | FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to... | |
| CVE-2026-32603 json | Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial of s... | |
| CVE-2026-31893 json | Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any local... | |
| CVE-2026-31835 json | Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authentication flo... | |
| CVE-2026-30923 json | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity... | |
| CVE-2026-28780 json | Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP... | |
| CVE-2026-27960 json | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 throug... | |
| CVE-2026-25589 json | RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does ... | |
| CVE-2026-25588 json | RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not pro... | |
| CVE-2025-71251 json | In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with n... | |
| CVE-2024-52911 json | Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is 0.14... | |
| CVE-2026-33023 json | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built with t... | |
| CVE-2026-33021 json | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-after-f... | |
| CVE-2026-32649 json | A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras. | |
| CVE-2026-32644 json | Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys. | |
| CVE-2026-28747 json | A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be... | |
| CVE-2026-27785 json | Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials. | |
| CVE-2026-25243 json | Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly va... | |
| CVE-2026-23773 json | Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A lo... | |
| CVE-2026-23631 json | Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can... | |
| CVE-2026-23479 json | Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle a... | |
| CVE-2026-1460 json | A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyx... | |
| CVE-2026-0711 json | A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions throu... | |
| CVE-2026-33020 json | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer ov... | |
| CVE-2026-27307 json | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could... | |
| CVE-2026-27301 json | Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to me... | |
| CVE-2026-27300 json | Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could lead... | |
| CVE-2026-27299 json | Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead to ar... | |
| CVE-2026-27298 json | Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion')... | |
| CVE-2026-27297 json | Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that cou... | |
| CVE-2026-27296 json | Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that cou... | |
| CVE-2026-27295 json | Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitr... | |
| CVE-2026-27294 json | Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file,... | |
| CVE-2026-27293 json | Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in ... | |
| CVE-2026-27292 json | Adobe Framemaker versions 2022.8 and earlier are affected by a Use After Free vulnerability that could result in arbitrary co... | |
| CVE-2026-27290 json | Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow attacker... | |
| CVE-2026-27306 json | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result ... | |
| CVE-2026-27305 json | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Director... | |
| CVE-2026-27304 json | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result ... | |
| CVE-2026-27289 json | Photoshop Desktop versions 27.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, ... | |
| CVE-2026-27282 json | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result ... | |
| CVE-2026-25133 json | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-sit... |