CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-23985 json | A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vuln... | |
| CVE-2026-23981 json | An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update c... | |
| CVE-2026-13379 json | The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pol... | |
| CVE-2026-47122 json | Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shoul... | |
| CVE-2026-14996 json | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management. | |
| CVE-2026-9205 json | IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function. | |
| CVE-2026-9201 json | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic ... | |
| CVE-2026-9196 json | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assista... | |
| CVE-2026-9130 json | IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authen... | |
| CVE-2026-8478 json | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improp... | |
| CVE-2026-70612 json | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9... | |
| CVE-2026-70611 json | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9... | |
| CVE-2026-70608 json | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.... | |
| CVE-2026-70432 json | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers... | |
| CVE-2026-63457 json | A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78. | |
| CVE-2026-48168 json | PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerabl... | |
| CVE-2026-18485 json | There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver. This may allow a loca... | |
| CVE-2026-17633 json | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injec... | |
| CVE-2026-17632 json | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper v... | |
| CVE-2026-17624 json | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3... | |
| CVE-2026-10547 json | IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/ver... | |
| CVE-2026-9081 json | IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability i... | |
| CVE-2026-8470 json | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-... | |
| CVE-2026-8183 json | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3... | |
| CVE-2026-8182 json | IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server with... | |
| CVE-2026-7869 json | IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bas... | |
| CVE-2026-7658 json | IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traver... | |
| CVE-2026-7657 json | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffecti... | |
| CVE-2026-70607 json | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9... | |
| CVE-2026-70431 json | Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script ... | |
| CVE-2026-70428 json | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file paramet... | |
| CVE-2026-70427 json | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during ... | |
| CVE-2026-70426 json | In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.... | |
| CVE-2026-44605 json | A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability whe... | |
| CVE-2026-17626 json | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive hos... | |
| CVE-2026-17625 json | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3... | |
| CVE-2026-17623 json | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improp... | |
| CVE-2026-14587 json | Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. Whe... | |
| CVE-2026-9203 json | A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated use... | |
| CVE-2026-9195 json | A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remo... | |
| CVE-2026-9193 json | An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.... | |
| CVE-2026-9192 json | An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an... | |
| CVE-2026-9190 json | An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a... | |
| CVE-2026-9077 json | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions an... | |
| CVE-2026-8709 json | An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 1... | |
| CVE-2026-8400 json | IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw i... | |
| CVE-2026-7646 json | IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users'... | |
| CVE-2026-7557 json | An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Ser... | |
| CVE-2026-7329 json | An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Serv... | |
| CVE-2026-7327 json | An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server befo... | |
| CVE-2026-71190 json | In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastro... | |
| CVE-2026-70604 json | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.... | |
| CVE-2026-70603 json | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9... | |
| CVE-2026-70599 json | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9... | |
| CVE-2026-70598 json | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.... | |
| CVE-2026-67862 json | open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. Thi... | |
| CVE-2026-67860 json | open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is us... | |
| CVE-2026-67856 json | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription... | |
| CVE-2026-67855 json | open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEM... | |
| CVE-2026-45103 json | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP mess... | |
| CVE-2026-16443 json | A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for i... | |
| CVE-2026-16442 json | A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authenticatio... | |
| CVE-2026-16102 json | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. ... | |
| CVE-2026-16100 json | A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error mess... | |
| CVE-2026-16071 json | A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directorie... | |
| CVE-2026-15656 json | IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. ... | |
| CVE-2026-15573 json | A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security polic... | |
| CVE-2026-15572 json | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Typ... | |
| CVE-2026-12730 json | IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.... | |
| CVE-2026-70588 json | Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to... | |
| CVE-2026-70490 json | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal W... | |
| CVE-2026-65986 json | CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain... | |
| CVE-2026-54332 json | gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder ... | |
| CVE-2026-48388 json | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbit... | |
| CVE-2026-48372 json | Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the... | |
| CVE-2026-18812 json | A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executi... | |
| CVE-2026-16242 json | A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was star... | |
| CVE-2026-15057 json | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled... | |
| CVE-2026-14615 json | A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. Wh... | |
| CVE-2026-14614 json | A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 i... | |
| CVE-2026-14209 json | A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass security r... | |
| CVE-2026-11986 json | A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilitie... | |
| CVE-2026-9800 json | A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization po... | |
| CVE-2026-4629 json | A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by inj... | |
| CVE-2026-40683 json | In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when ... | |
| CVE-2026-9798 json | A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily lock... | |
| CVE-2026-9793 json | A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectl... | |
| CVE-2026-9689 json | A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured... | |
| CVE-2026-63248 json | In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymo... | |
| CVE-2026-54345 json | gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an A... | |
| CVE-2026-63252 json | In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks ... | |
| CVE-2026-66713 json | Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache... | |
| CVE-2026-66391 json | Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache ... | |
| CVE-2026-66390 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This is... | |
| CVE-2026-65946 json | Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0 | |
| CVE-2026-65944 json | Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0 | |
| CVE-2026-65943 json | Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0 | |
| CVE-2026-65885 json | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authent... | |
| CVE-2026-65884 json | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided use... | |
| CVE-2026-65883 json | Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged ... |