CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-81560 json | A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of the fi... | |
| CVE-2026-81203 json | A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of ... | |
| CVE-2026-79921 json | amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to a... | |
| CVE-2026-77317 json | SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates ... | |
| CVE-2026-75601 json | Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances w... | |
| CVE-2026-65956 json | KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endp... | |
| CVE-2026-61792 json | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a ... | |
| CVE-2026-46370 json | Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-... | |
| CVE-2026-41012 json | Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter... | |
| CVE-2026-40526 json | Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitr... | |
| CVE-2026-32639 json | Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS... | |
| CVE-2026-81036 json | Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuratio... | |
| CVE-2026-81031 json | IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The upda... | |
| CVE-2026-80428 json | ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIA... | |
| CVE-2026-54614 json | DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature i... | |
| CVE-2026-54556 json | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, an unauthenticated HTTP/2 peer can cause an ou... | |
| CVE-2026-3129 json | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in a... | |
| CVE-2026-55867 json | Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tok... | |
| CVE-2026-55860 json | MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mar... | |
| CVE-2026-55859 json | MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mar... | |
| CVE-2026-55858 json | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5,... | |
| CVE-2026-55857 json | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5,... | |
| CVE-2026-55856 json | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5,... | |
| CVE-2026-55855 json | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4... | |
| CVE-2026-55854 json | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4... | |
| CVE-2026-55848 json | mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16... | |
| CVE-2026-59324 json | When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurren... | |
| CVE-2026-59322 json | The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeN... | |
| CVE-2026-59321 json | A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines that report THREAD... | |
| CVE-2026-59320 json | When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws ... | |
| CVE-2026-59319 json | RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values withou... | |
| CVE-2026-59317 json | DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passe... | |
| CVE-2026-59316 json | Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using th... | |
| CVE-2026-59315 json | The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Cloud Config 5.0.0... | |
| CVE-2026-59311 json | A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing b... | |
| CVE-2026-55841 json | Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog For... | |
| CVE-2026-55785 json | free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic au... | |
| CVE-2026-55784 json | free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-... | |
| CVE-2026-55779 json | Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() in src... | |
| CVE-2026-55764 json | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, Klever-Go allows a mint-role holder to... | |
| CVE-2026-80346 json | StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type rout... | |
| CVE-2026-80203 json | The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in Us... | |
| CVE-2026-80198 json | Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing ... | |
| CVE-2026-80193 json | Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesh... | |
| CVE-2026-79804 json | A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected b... | |
| CVE-2026-79654 json | A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Conte... | |
| CVE-2026-73108 json | RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before auth... | |
| CVE-2026-63404 json | Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnera... | |
| CVE-2026-59304 json | Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Str... | |
| CVE-2026-59303 json | Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud S... | |
| CVE-2026-59302 json | Potential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.... | |
| CVE-2026-59301 json | Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Functio... | |
| CVE-2026-59300 json | Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function ... | |
| CVE-2026-59299 json | Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring ... | |
| CVE-2026-57170 json | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior... | |
| CVE-2026-80104 json | DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload di... | |
| CVE-2026-79786 json | Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without ... | |
| CVE-2026-79782 json | rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on ... | |
| CVE-2026-79777 json | rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics... | |
| CVE-2026-79772 json | Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an e... | |
| CVE-2026-68513 json | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industr... | |
| CVE-2026-59981 json | OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture in... | |
| CVE-2026-55618 json | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as c... | |
| CVE-2026-55585 json | QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, ... | |
| CVE-2026-32637 json | Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. P... | |
| CVE-2026-55582 json | mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default securit... | |
| CVE-2026-55536 json | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome extensi... | |
| CVE-2026-8715 json | Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the App... | |
| CVE-2026-3639 json | The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp`... | |
| CVE-2024-58378 json | Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vuln... | |
| CVE-2026-82333 json | multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text... | |
| CVE-2026-82018 json | IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the GRUB b... | |
| CVE-2026-82017 json | IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allow... | |
| CVE-2026-81533 json | An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement ... | |
| CVE-2026-81532 json | A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-curso... | |
| CVE-2026-81520 json | A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open ind... | |
| CVE-2026-81518 json | When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the ... | |
| CVE-2026-81517 json | An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routin... | |
| CVE-2026-81490 json | A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling rout... | |
| CVE-2026-77078 json | multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafte... | |
| CVE-2026-77063 json | multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter toget... | |
| CVE-2026-77037 json | multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is aborted or... | |
| CVE-2026-76651 json | A buffer overflow vulnerability exists in the embedded HTTP service in TL-WR841N v14 when processing multipart/form-data re... | |
| CVE-2026-76650 json | A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP state variable q... | |
| CVE-2026-76649 json | A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP action requests. A... | |
| CVE-2026-75118 json | A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due... | |
| CVE-2026-55891 json | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, Request::getRequestUri()... | |
| CVE-2026-55763 json | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in ... | |
| CVE-2026-55696 json | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.setAtta... | |
| CVE-2026-55678 json | Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering accepts ... | |
| CVE-2026-51665 json | Incorrect access control in the getTracerouteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attacke... | |
| CVE-2026-51664 json | Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers t... | |
| CVE-2026-51663 json | Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attacke... | |
| CVE-2026-51662 json | Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated a... | |
| CVE-2026-51661 json | Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated atta... | |
| CVE-2026-22056 json | StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are suscept... | |
| CVE-2026-19295 json | IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the ... | |
| CVE-2026-19294 json | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's private flow... | |
| CVE-2026-19286 json | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of ... | |
| CVE-2026-18904 json | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized m... |