CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-95653 json Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of r...
CVE-2026-94540 json DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrie...
CVE-2026-94536 json lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authe...
CVE-2026-94535 json lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authentic...
CVE-2026-94534 json lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing ...
CVE-2026-94533 json lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated us...
CVE-2026-93344 json MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_conte...
CVE-2026-93343 json MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_vendors_...
CVE-2026-93342 json MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_duplicate_prod...
CVE-2026-93341 json MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_send_refund AJ...
CVE-2026-63104 json Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace members...
CVE-2026-94532 json lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenti...
CVE-2026-93873 json Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forg...
CVE-2026-93872 json Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plu...
CVE-2026-93871 json Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated use...
CVE-2026-93870 json Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge rati...
CVE-2026-93869 json Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destina...
CVE-2026-93868 json Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a ...
CVE-2026-93839 json LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows una...
CVE-2026-93736 json Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attacker...
CVE-2026-93659 json Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin ...
CVE-2026-93657 json hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolv...
CVE-2026-93340 json Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attac...
CVE-2026-77929 json ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code e...
CVE-2023-54399 json Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories que...
CVE-2026-93456 json django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attac...
CVE-2026-93455 json django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account ...
CVE-2026-93454 json Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. ...
CVE-2026-92984 json HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, all...
CVE-2026-92983 json InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because ...
CVE-2026-92980 json HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to...
CVE-2026-92971 json InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that all...
CVE-2026-92970 json HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated ...
CVE-2026-92921 json admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation fun...
CVE-2026-92920 json admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authen...
CVE-2026-92919 json admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write...
CVE-2026-92918 json admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Att...
CVE-2026-77928 json ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbit...
CVE-2026-77927 json ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbit...
CVE-2026-92816 json ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitra...
CVE-2026-92815 json changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers ...
CVE-2026-92814 json changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup inj...
CVE-2026-92812 json decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix compa...
CVE-2026-92811 json browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allo...
CVE-2026-92803 json LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access t...
CVE-2026-92802 json kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guest...
CVE-2026-92800 json Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. At...
CVE-2026-92796 json Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL request...
CVE-2026-92793 json GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to...
CVE-2026-92789 json Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after foll...
CVE-2026-91996 json lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to ...
CVE-2026-94501 json jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticate...
CVE-2026-94497 json jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource ty...
CVE-2026-94496 json jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify ...
CVE-2026-94495 json jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticat...
CVE-2026-94494 json jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' re...
CVE-2026-94414 json jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticate...
CVE-2026-94413 json jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsal...
CVE-2026-43643 json Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module...
CVE-2026-43642 json Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module ...
CVE-2026-43641 json Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module...
CVE-2026-94412 json jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticat...
CVE-2026-94411 json jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticat...
CVE-2026-94111 json Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin valid...
CVE-2026-94107 json NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates...
CVE-2026-94105 json NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller that a...
CVE-2026-94104 json NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to val...
CVE-2026-93993 json Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git ...
CVE-2026-93339 json Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows a...
CVE-2025-71421 json UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that all...
CVE-2025-71420 json UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows aut...
CVE-2025-71419 json UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration iden...
CVE-2026-93992 json Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbi...
CVE-2026-93988 json QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authen...
CVE-2026-93985 json OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template valid...
CVE-2026-93984 json OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic ha...
CVE-2026-93983 json OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to in...
CVE-2026-93982 json OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext ...
CVE-2026-93838 json SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to val...
CVE-2026-93688 json SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_roo...
CVE-2026-81946 json PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use MD5-b...
CVE-2026-81945 json PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions bfore 1.2412b260707 and 2.2412b260519 contain a ...
CVE-2019-25776 json Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL...
CVE-2026-93660 json SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authentica...
CVE-2026-93453 json SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauth...
CVE-2026-93014 json RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authe...
CVE-2026-92987 json roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits on attr...
CVE-2026-92972 json SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bo...
CVE-2026-92915 json WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVeri...
CVE-2026-92914 json AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares chall...
CVE-2026-92913 json AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator w...
CVE-2026-81944 json PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a...
CVE-2026-81943 json PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a...
CVE-2026-81942 json PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a...
CVE-2026-92912 json AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in ...
CVE-2026-92586 json AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api...
CVE-2026-92585 json AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API l...
CVE-2026-92584 json AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated vi...
CVE-2026-92583 json AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limi...
CVE-2026-92582 json AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.ph...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report