CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-62742 json Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an...
CVE-2026-62720 json Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an...
CVE-2026-62718 json Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an...
CVE-2026-62716 json Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an...
CVE-2026-62715 json Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an...
CVE-2026-62714 json Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an...
CVE-2026-70315 json Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70314 json Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-62908 json Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows a...
CVE-2026-71390 json CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature byp...
CVE-2026-71389 json CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an applic...
CVE-2026-70329 json Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-65661 json Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-65657 json Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64911 json Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63518 json Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-63513 json Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-62882 json Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a n...
CVE-2026-48446 json CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vuln...
CVE-2026-48445 json CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application de...
CVE-2026-48444 json CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application de...
CVE-2026-48443 json CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application deni...
CVE-2026-48442 json CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vuln...
CVE-2026-48439 json CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application deni...
CVE-2026-48438 json CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of...
CVE-2026-48437 json CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security featu...
CVE-2026-48436 json CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature byp...
CVE-2026-48435 json CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an applic...
CVE-2026-48434 json CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application deni...
CVE-2026-48387 json CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application de...
CVE-2026-47922 json CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege esca...
CVE-2026-13381 json VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files ...
CVE-2026-13380 json VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticate...
CVE-2026-73633 json Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to pop...
CVE-2026-69101 json Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perf...
CVE-2026-58224 json A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received...
CVE-2026-19880 json Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerabil...
CVE-2026-19879 json A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method perfor...
CVE-2026-73673 json Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated ...
CVE-2026-72859 json Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows B...
CVE-2026-72837 json File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisio...
CVE-2026-72834 json filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum (?checksum=) branch of r...
CVE-2026-72832 json Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() func...
CVE-2026-72829 json The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create(...
CVE-2026-72827 json Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-pri...
CVE-2026-53472 json A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authe...
CVE-2026-19871 json Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticat...
CVE-2026-19870 json Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows auth...
CVE-2026-19827 json A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin/cont...
CVE-2026-19768 json Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2....
CVE-2026-1621 json Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of Trus...
CVE-2026-73670 json A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inj...
CVE-2026-72824 json The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwi...
CVE-2026-72819 json Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that all...
CVE-2026-72813 json actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for s...
CVE-2026-19822 json A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the function lstAdd of the f...
CVE-2026-19812 json A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the ...
CVE-2026-19786 json A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown processing of the file Mo...
CVE-2026-19784 json A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This affects the function DBUpdate of the file Discipline/Ref...
CVE-2026-19764 json A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects a...
CVE-2026-64920 json Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64919 json Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64914 json Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64907 json Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-64905 json Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-62915 json Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
CVE-2026-62910 json Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to...
CVE-2026-62890 json Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.
CVE-2026-62823 json Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
CVE-2026-64912 json Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64904 json Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute ...
CVE-2026-64899 json Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-63533 json Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63530 json Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-63526 json Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63093 json Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary ...
CVE-2026-61498 json Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoin...
CVE-2026-60121 json Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that...
CVE-2026-63528 json Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-19830 json A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the fil...
CVE-2026-19829 json A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4-20260107. This vulnerability affects unknown code of t...
CVE-2026-19828 json A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-20260107. This affects an unknown part of the file PlayCont...
CVE-2026-73051 json actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts request...
CVE-2026-19825 json A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an ...
CVE-2026-19767 json A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of ...
CVE-2026-19761 json A vulnerability has been found in DTStack Taier 1.4.0. Affected is the function MultipartFile.getOriginalFilename of the file...
CVE-2026-19617 json A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with ...
CVE-2026-18511 json IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Nati...
CVE-2026-18086 json IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to impro...
CVE-2026-17502 json IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
CVE-2026-17468 json IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use of a...
CVE-2026-12743 json The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-based S...
CVE-2026-64917 json Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-64915 json Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-64908 json Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64906 json Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-63531 json Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-18085 json An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows A...
CVE-2026-18084 json Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry ...
CVE-2026-70345 json Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report