CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-97365 json A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file crates/...
CVE-2026-97326 json A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue ...
CVE-2026-97325 json A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is th...
CVE-2026-97324 json A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderP...
CVE-2026-97323 json A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFile...
CVE-2026-97322 json A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file y...
CVE-2026-93354 json Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to reg...
CVE-2026-48543 json Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers t...
CVE-2026-48542 json Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers t...
CVE-2026-48541 json Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers t...
CVE-2026-48540 json Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers t...
CVE-2026-97321 json A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoVi...
CVE-2026-97320 json A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDo...
CVE-2026-97233 json A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the file P...
CVE-2026-97232 json A vulnerability was determined in volotat Anagnorisis up to 0.4.2. Affected by this vulnerability is the function get_file_co...
CVE-2026-97231 json A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is an unknown function of the file app.py of the...
CVE-2026-96749 json An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur...
CVE-2026-96748 json PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated ...
CVE-2026-96747 json The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending ...
CVE-2026-94281 json An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers...
CVE-2026-93545 json An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an a...
CVE-2026-89325 json An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-pr...
CVE-2026-86860 json ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulne...
CVE-2026-86859 json ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This secu...
CVE-2026-86858 json ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This s...
CVE-2026-86857 json ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This secu...
CVE-2026-13016 json ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability...
CVE-2026-93544 json An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to...
CVE-2026-93543 json An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an atta...
CVE-2026-93542 json An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used ...
CVE-2026-88390 json An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScrip...
CVE-2026-88385 json Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing. Specially crafted XML i...
CVE-2026-88384 json OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file containing...
CVE-2026-88383 json libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data contai...
CVE-2026-88382 json hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate parser.
CVE-2026-88378 json QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag().
CVE-2026-88377 json Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially craft...
CVE-2026-88376 json Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A specially ...
CVE-2026-88373 json libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is c...
CVE-2026-88372 json libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files...
CVE-2026-88367 json NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization...
CVE-2026-96750 json MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a ...
CVE-2026-96746 json An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who cont...
CVE-2026-96745 json Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded ...
CVE-2026-96744 json Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration f...
CVE-2026-93541 json An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a
CVE-2026-88371 json ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in the Code 128 decode6() function. When processing special...
CVE-2026-88370 json libconfini 1.16.4 contains a heap out-of-bounds write condition involving the bundled load_ini_buffer.h utility and strip_ini...
CVE-2026-88369 json zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondump.c dump().
CVE-2026-88368 json NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() functio...
CVE-2026-88366 json NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__pathArcTo() when parsing SVG arc com...
CVE-2026-88365 json minimp3 commit ea99364f contains an integer overflow vulnerability in mp3dec_skip_id3v1() when parsing the APEv2 tag-size fie...
CVE-2026-88362 json MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted JavaSc...
CVE-2026-88361 json SumatraPDF 3.6.1 contains an integer overflow vulnerability in EngineMupdf::BuildPageLabelRec() when parsing PDF PageLabels /...
CVE-2026-88358 json simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in dom::parser::parse_unpadded(). A specially crafted tru...
CVE-2026-88357 json nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted network...
CVE-2026-88355 json An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr(). For arity-0 expression no...
CVE-2026-97404 json In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-...
CVE-2026-97362 json HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a co...
CVE-2026-97360 json HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated at...
CVE-2026-97359 json HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauth...
CVE-2026-97224 json A vulnerability was detected in Excalidraw up to 0.18.1. The impacted element is an unknown function of the file packages/exc...
CVE-2026-97061 json Black Candy through 3.2.1 fails to scope playlist search queries to the authenticated session user, allowing any authenticate...
CVE-2026-90959 json A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users...
CVE-2026-90481 json In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via...
CVE-2026-88351 json An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specially c...
CVE-2026-73064 json In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inj...
CVE-2026-52001 json An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE tran...
CVE-2026-51997 json An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functio...
CVE-2026-51996 json An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils....
CVE-2026-51995 json An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/...
CVE-2026-51994 json mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL ...
CVE-2026-97059 json DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without vali...
CVE-2026-97058 json sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without val...
CVE-2026-97057 json redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trig...
CVE-2026-95521 json A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain ...
CVE-2026-95519 json A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `r...
CVE-2026-88360 json libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images. If the PFM text header length...
CVE-2026-88359 json libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML d...
CVE-2026-77798 json Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock manageme...
CVE-2026-77797 json Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed...
CVE-2026-97311 json A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retriev...
CVE-2026-97185 json A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly valid...
CVE-2026-97177 json A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled...
CVE-2026-97155 json Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via we...
CVE-2026-97152 json Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due...
CVE-2026-97151 json mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Co...
CVE-2026-97149 json In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL si...
CVE-2026-97056 json SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (which w...
CVE-2026-97055 json SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZE...
CVE-2026-87739 json An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report gene...
CVE-2026-82077 json An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of...
CVE-2026-79680 json Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a...
CVE-2026-19072 json Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoi...
CVE-2026-14780 json A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and a...
CVE-2026-11744 json An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails t...
CVE-2026-96808 json In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivileged...
CVE-2026-96807 json In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_l...
CVE-2026-96762 json A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of ...
CVE-2026-96754 json orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report