CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-46729 json NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects A...
CVE-2026-42528 json A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV lo...
CVE-2026-42356 json Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI program...
CVE-2020-8664 json CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same secret...
CVE-2020-8661 json CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.
CVE-2020-8659 json CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many smal...
CVE-2026-56153 json Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2....
CVE-2026-48005 json Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platfo...
CVE-2026-100256 json In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects
CVE-2026-98163 json In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero refcoun...
CVE-2026-47360 json Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. ...
CVE-2026-100260 json In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset
CVE-2026-100259 json In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access
CVE-2026-100258 json In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings
CVE-2026-100257 json In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export
CVE-2026-82040 json UTMStack before 11.2.16 contains a server-side request forgery vulnerability in IdentityProviderService.validateMetadataUrl()...
CVE-2026-82039 json UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authe...
CVE-2026-39718 json Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue...
CVE-2026-12392 json An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an u...
CVE-2026-104994 json Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the ...
CVE-2026-104991 json Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_ge...
CVE-2026-104988 json A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment ...
CVE-2026-104873 json LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Pyt...
CVE-2026-104872 json OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Pr...
CVE-2026-104871 json The Angular SSR is a server-rise rendering tool for Angular applications. Prior to versions 20.3.36, 21.2.23, and 22.1.7, the...
CVE-2026-104019 json OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x b...
CVE-2026-103918 json oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.10, the @or...
CVE-2026-103036 json oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.9, the @orp...
CVE-2026-103958 json Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow ...
CVE-2026-103957 json Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote...
CVE-2026-103956 json Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote act...
CVE-2026-67989 json crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-ser...
CVE-2026-63575 json Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle...
CVE-2026-63574 json Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers (SignatureSubpacket...
CVE-2026-63573 json Observable discrepancy in the CMS RSA PKCS#1 v1.5 key-transport unwrap (KeyTransRecipientInformation.UnwrapKey) in Legion of ...
CVE-2026-63572 json Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-...
CVE-2026-51907 json In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attacke...
CVE-2026-104054 json A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of...
CVE-2026-103765 json Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler t...
CVE-2026-103097 json An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, e...
CVE-2026-103096 json API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embe...
CVE-2026-93367 json The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripti...
CVE-2026-92820 json The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and inc...
CVE-2026-84925 json The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting v...
CVE-2026-63571 json Improper verification of cryptographic signature in the attribute certificate path validator (PkixAttrCertPathValidator, also...
CVE-2026-63570 json Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc-csharp before ...
CVE-2026-15896 json The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to,...
CVE-2025-71427 json Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read ...
CVE-2026-100263 json In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
CVE-2026-71454 json Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scr...
CVE-2026-71453 json - External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue ...
CVE-2026-71448 json : Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. T...
CVE-2026-64893 json - Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Att...
CVE-2026-64892 json - Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Lo...
CVE-2026-51858 json In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_exec allows prompt-driven shell command execution ...
CVE-2026-34494 json - On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Location...
CVE-2026-34493 json - On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. ...
CVE-2026-18397 json This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of c...
CVE-2026-100262 json In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite proj...
CVE-2026-100261 json In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission
CVE-2026-95326 json Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineeri...
CVE-2026-95275 json Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web...
CVE-2026-95314 json Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the rend...
CVE-2026-95303 json Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineeri...
CVE-2026-95285 json Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had comp...
CVE-2026-95278 json Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the r...
CVE-2026-73555 json vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/...
CVE-2026-71486 json vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat...
CVE-2026-96940 json Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
CVE-2026-19856 json The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content deriv...
CVE-2023-54405 json H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary f...
CVE-2026-104861 json probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/par...
CVE-2026-104123 json A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an un...
CVE-2026-103552 json Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter...
CVE-2026-102795 json Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 throu...
CVE-2026-102626 json An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-b...
CVE-2026-93698 json Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
CVE-2026-93697 json There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
CVE-2026-63569 json Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legion of the Bouncy Castle I...
CVE-2020-37278 json Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to access arbitrar...
CVE-2014-125130 json CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arb...
CVE-2026-104480 json Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized ...
CVE-2026-104356 json PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cry...
CVE-2026-104053 json A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of...
CVE-2026-104002 json A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to ...
CVE-2026-103764 json Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows una...
CVE-2026-103098 json Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than H...
CVE-2026-86344 json A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first ...
CVE-2026-71452 json - OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO ...
CVE-2026-71449 json : Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data...
CVE-2026-51895 json Ragflow 0.24.0 and prior contains improper access control in update_metadata_setting (api/apps/kb_app.py). Depending on the e...
CVE-2026-27873 json - Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects Ea...
CVE-2026-21140 json Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary ap...
CVE-2026-104020 json Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to cra...
CVE-2026-71451 json - OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO F...
CVE-2026-64849 json MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in ...
CVE-2026-27874 json : Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded ...
CVE-2026-86326 json An improper verification of cryptographic signature vulnerability exists in protocol gateways because the device does not pr...
CVE-2026-86325 json A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is c...
CVE-2026-94418 json Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to kee...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report