CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-81486 json A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_context of...
CVE-2026-81485 json A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the func...
CVE-2026-19398 json “unsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a ...
CVE-2026-79111 json Improper input validation in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute ar...
CVE-2026-79045 json Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to read ...
CVE-2026-79044 json Missing authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who h...
CVE-2026-81421 json A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of ...
CVE-2026-80183 json In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped ...
CVE-2026-47874 json The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty ...
CVE-2026-47863 json In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Deni...
CVE-2026-47862 json An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can...
CVE-2026-47861 json An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the...
CVE-2026-47860 json An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consum...
CVE-2026-47859 json RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, tr...
CVE-2026-47857 json In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Deni...
CVE-2026-47856 json Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and ...
CVE-2026-79124 json Information leak in Intents in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to leak sensitive...
CVE-2026-79123 json Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who h...
CVE-2026-79122 json Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information ...
CVE-2026-79121 json Improper input validation in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised...
CVE-2026-79119 json Use after free in PDF in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the ...
CVE-2026-47852 json A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spri...
CVE-2026-47851 json Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spri...
CVE-2026-47850 json Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT a...
CVE-2026-47845 json In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enab...
CVE-2026-79024 json Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive infor...
CVE-2026-79023 json Incorrect authorization in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive info...
CVE-2026-79041 json Missing authorization in Browser in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging socia...
CVE-2026-79038 json Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive i...
CVE-2026-79034 json Information leak in CORS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer p...
CVE-2026-79030 json Observable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive info...
CVE-2026-63044 json Server-Side Request Forgery (SSRF) vulnerability in Apache InLong.  Any authenticated user (no admin role required) can ca...
CVE-2026-63043 json Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue affe...
CVE-2026-63042 json Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the mana...
CVE-2026-63040 json
CVE-2026-63039 json Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This all...
CVE-2026-63038 json Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This all...
CVE-2026-63037 json Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This ap...
CVE-2026-81203 json A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of ...
CVE-2026-80158 json A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, use...
CVE-2026-77998 json Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO <...
CVE-2026-75340 json The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vuln...
CVE-2026-75338 json disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching...
CVE-2026-75336 json Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json.
CVE-2026-75332 json Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().
CVE-2026-75330 json The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to...
CVE-2026-69129 json KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 2.0.0, cluster-scoped APIs do not cons...
CVE-2026-65956 json KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endp...
CVE-2026-47666 json Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to sto...
CVE-2026-47665 json Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to sto...
CVE-2026-21808 json HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensiti...
CVE-2026-21807 json HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an a...
CVE-2026-18823 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-62341 json HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing ...
CVE-2026-76827 json A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with o...
CVE-2026-75485 json A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object...
CVE-2026-73834 json A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Cust...
CVE-2026-71846 json A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets g...
CVE-2026-71845 json A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, inc...
CVE-2026-71475 json A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into ...
CVE-2026-71474 json A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can...
CVE-2026-71468 json A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuse...
CVE-2026-64927 json A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to...
CVE-2026-63048 json Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2 - The Joom...
CVE-2026-48864 json A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data...
CVE-2026-18874 json A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Mar...
CVE-2026-14330 json Multiple unbounded alloca() calls in the PulseAudio protocol server.
CVE-2026-14324 json RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
CVE-2026-3833 json A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints`...
CVE-2026-81202 json A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of t...
CVE-2026-77611 json SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal with ...
CVE-2026-77368 json SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler chec...
CVE-2026-77317 json SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates ...
CVE-2026-77298 json SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3 API accepts an external O...
CVE-2026-75333 json yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File()...
CVE-2026-75331 json tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in Fil...
CVE-2026-78416 json Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code executi...
CVE-2026-75329 json The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. At...
CVE-2026-75328 json In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary fi...
CVE-2026-65930 json LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fie...
CVE-2026-65647 json Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.
CVE-2026-65646 json Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and ...
CVE-2026-65642 json Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated use...
CVE-2026-65641 json A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.
CVE-2026-64632 json A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.
CVE-2026-63360 json LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user ...
CVE-2026-61617 json Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, t...
CVE-2026-58070 json A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with...
CVE-2026-55182 json LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to co...
CVE-2026-45694 json LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable t...
CVE-2026-43621 json Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability i...
CVE-2026-21810 json HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which ...
CVE-2026-21809 json HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it enc...
CVE-2026-16809 json LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow...
CVE-2026-76139 json A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote sourc...
CVE-2026-73137 json A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant ...
CVE-2026-71472 json A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or ...
CVE-2026-71470 json A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) ...
CVE-2026-70496 json A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, all...
CVE-2026-70495 json A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report