CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-90804 json A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of ...
CVE-2026-90803 json A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_re...
CVE-2026-90802 json A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the comp...
CVE-2026-90801 json A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of t...
CVE-2026-90796 json A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /mod...
CVE-2026-84445 json gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow...
CVE-2026-76461 json A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated,...
CVE-2026-76443 json As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Sec...
CVE-2026-76442 json As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Sec...
CVE-2026-76441 json As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Sec...
CVE-2026-76440 json As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Sec...
CVE-2026-61701 json Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until 2.25...
CVE-2026-59960 json Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-controlled ...
CVE-2026-57579 json Alchemy is an open source content management system engine written in Ruby on Rails. Prior to 7.4.15, 8.0.15, 8.1.14, and 8.2...
CVE-2026-57497 json webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go ...
CVE-2026-55837 json dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/o...
CVE-2026-55451 json gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2i18ne...
CVE-2026-55416 json Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated us...
CVE-2026-55102 json hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vaul...
CVE-2026-55073 json WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive...
CVE-2026-55072 json Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects pe...
CVE-2026-90994 json A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_...
CVE-2026-90794 json A vulnerability was found in GPAC up to f1219cde. The affected element is the function gf_sg_script_load of the file scenegra...
CVE-2026-90792 json A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegraph/b...
CVE-2026-90463 json A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially...
CVE-2026-54452 json safeurl is a server-side request forgery protection library. Prior to 0.2.4, the privateNetworks list in ip.go omits the IPv6...
CVE-2026-54156 json node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonce ca...
CVE-2026-54155 json node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication...
CVE-2026-53496 json ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL load...
CVE-2026-20353 json As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Sec...
CVE-2026-15923 json The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O loop t...
CVE-2026-90691 json A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted...
CVE-2026-72524 json Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or m...
CVE-2026-68570 json Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data...
CVE-2026-57131 json PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.creat...
CVE-2026-57127 json PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware whe...
CVE-2026-56839 json PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass works...
CVE-2026-55236 json langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, the langgraph-api run-creation...
CVE-2026-54529 json SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.py acc...
CVE-2026-53708 json ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A...
CVE-2026-47701 json The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator Tar...
CVE-2026-25832 json In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised...
CVE-2026-90602 json A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the fu...
CVE-2026-38924 json In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed t...
CVE-2026-33967 json An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In t...
CVE-2026-33964 json An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs w...
CVE-2026-33960 json An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, a...
CVE-2026-23792 json An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400...
CVE-2026-23790 json An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A...
CVE-2026-23787 json An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A...
CVE-2023-50461 json An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend mod...
CVE-2023-46035 json The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.
CVE-2023-45858 json A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.
CVE-2023-37252 json An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that ha...
CVE-2023-28148 json A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.
CVE-2023-24285 json Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unu...
CVE-2023-22632 json PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.
CVE-2026-90648 json wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, a...
CVE-2026-90597 json A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown...
CVE-2026-90594 json A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function Permissi...
CVE-2026-90584 json A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameCo...
CVE-2026-90555 json vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated ...
CVE-2026-90513 json A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affec...
CVE-2026-79300 json SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an ...
CVE-2026-52297 json FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_r...
CVE-2026-37008 json CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnera...
CVE-2026-29810 json CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.
CVE-2026-90550 json WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins medi...
CVE-2026-90545 json WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the comment...
CVE-2026-90540 json WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVid...
CVE-2026-90535 json Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort ...
CVE-2026-90472 json msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deseria...
CVE-2026-78159 json The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.1...
CVE-2026-15451 json The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and includin...
CVE-2026-11355 json The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a miss...
CVE-2026-90460 json An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 creden...
CVE-2026-90450 json The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its t...
CVE-2026-90449 json When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administra...
CVE-2026-90448 json A deployment mode intended to expose only read access to stored data proxies a set of application programming interface route...
CVE-2026-90447 json A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of ...
CVE-2026-54241 json libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to c...
CVE-2026-54174 json melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange...
CVE-2026-49992 json Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery ...
CVE-2026-84828 json A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploi...
CVE-2026-71640 json An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehi...
CVE-2026-52630 json SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.cla...
CVE-2026-49462 json NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, ...
CVE-2026-45057 json matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk...
CVE-2026-88763 json A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communicati...
CVE-2026-77827 json Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper ...
CVE-2026-71807 json In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, multiple core task APIs in FlwTaskController lack permission annot...
CVE-2026-71802 json A stored Cross-Site Scripting (XSS) vulnerability exists in the announcement preview component of REBUILD 4.4.3. Although the...
CVE-2024-53920 json In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on un...
CVE-2022-29567 json The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication ...
CVE-2026-90996 json A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Net...
CVE-2026-90995 json A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable...
CVE-2026-90947 json A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not prop...
CVE-2026-90943 json parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that ...
CVE-2026-90795 json A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function of the...
CVE-2026-90793 json A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/base_...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report