CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-58016 json | A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c fi... | |
| CVE-2026-49746 json | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory acc... | |
| CVE-2026-45204 json | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kernel nu... | |
| CVE-2026-45198 json | Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Fi... | |
| CVE-2026-19189 json | A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality i... | |
| CVE-2026-65668 json | Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-65667 json | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-62918 json | Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over ... | |
| CVE-2026-62896 json | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-65400 json | An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sono... | |
| CVE-2026-62873 json | Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate pri... | |
| CVE-2026-59118 json | Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-59115 json | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a n... | |
| CVE-2026-56161 json | Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. | |
| CVE-2026-50481 json | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges o... | |
| CVE-2026-41861 json | Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with parti... | |
| CVE-2026-19177 json | Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had c... | |
| CVE-2026-19176 json | Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer pr... | |
| CVE-2026-19174 json | Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a ... | |
| CVE-2026-19172 json | Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer p... | |
| CVE-2026-19170 json | Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform ... | |
| CVE-2026-19169 json | Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote atta... | |
| CVE-2026-19168 json | Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary co... | |
| CVE-2026-19165 json | Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a m... | |
| CVE-2026-19163 json | Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the... | |
| CVE-2026-19162 json | Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside... | |
| CVE-2026-19161 json | Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer... | |
| CVE-2026-19160 json | Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer... | |
| CVE-2026-19155 json | Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the rendere... | |
| CVE-2026-19154 json | Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the ... | |
| CVE-2026-19151 json | Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sa... | |
| CVE-2026-19150 json | Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary co... | |
| CVE-2026-19149 json | Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a s... | |
| CVE-2026-19146 json | Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised th... | |
| CVE-2026-19145 json | Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code insi... | |
| CVE-2026-19140 json | Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer pro... | |
| CVE-2026-19139 json | Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level p... | |
| CVE-2026-19138 json | Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised... | |
| CVE-2026-19137 json | Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the... | |
| CVE-2023-46847 json | Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB... | |
| CVE-2026-66036 json | FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that... | |
| CVE-2026-66032 json | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp... | |
| CVE-2026-43910 json | Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2... | |
| CVE-2026-66039 json | FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder th... | |
| CVE-2026-66038 json | FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder... | |
| CVE-2026-66037 json | FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxe... | |
| CVE-2026-66041 json | FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter t... | |
| CVE-2026-66040 json | FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG e... | |
| CVE-2026-70332 json | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a ... | |
| CVE-2026-68823 json | Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a networ... | |
| CVE-2026-63508 json | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate p... | |
| CVE-2026-62836 json | Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized atta... | |
| CVE-2026-62830 json | Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-56162 json | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-50515 json | Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. | |
| CVE-2026-49163 json | Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an aut... | |
| CVE-2026-17264 json | Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-boun... | |
| CVE-2026-66373 json | Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via... | |
| CVE-2026-65706 json | FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows at... | |
| CVE-2026-15805 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-65705 json | FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows a... | |
| CVE-2026-65704 json | FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplyin... | |
| CVE-2026-65703 json | FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote a... | |
| CVE-2026-66759 json | A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin ... | |
| CVE-2026-66758 json | A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation ... | |
| CVE-2026-45623 json | PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Synta... | |
| CVE-2026-71555 json | PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does no... | |
| CVE-2026-8325 json | A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicio... | |
| CVE-2026-7867 json | A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking ... | |
| CVE-2026-7406 json | A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vuln... | |
| CVE-2026-7405 json | A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds... | |
| CVE-2026-71554 json | h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header block... | |
| CVE-2026-71498 json | node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes fo... | |
| CVE-2026-71497 json | jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly han... | |
| CVE-2026-71488 json | league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted M... | |
| CVE-2026-71478 json | league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExten... | |
| CVE-2026-71476 json | Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hos... | |
| CVE-2026-71447 json | AIL Project contains a stored cross-site scripting vulnerability in the translation controls displayed for chat messages and ... | |
| CVE-2026-71446 json | AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawled URLs were embedded dir... | |
| CVE-2026-71445 json | AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred ... | |
| CVE-2026-71439 json | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 u... | |
| CVE-2026-71438 json | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 1... | |
| CVE-2026-71437 json | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.5.0 u... | |
| CVE-2026-71436 json | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 u... | |
| CVE-2026-71435 json | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") ... | |
| CVE-2026-71434 json | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did ... | |
| CVE-2026-71433 json | LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint sav... | |
| CVE-2026-71430 json | node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function buil... | |
| CVE-2026-71327 json | Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gate... | |
| CVE-2026-71326 json | Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth midd... | |
| CVE-2026-71325 json | Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and... | |
| CVE-2026-71324 json | Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP r... | |
| CVE-2026-70640 json | llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper w... | |
| CVE-2026-70639 json | llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where ... | |
| CVE-2026-70638 json | llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new... | |
| CVE-2026-70636 json | Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAu... | |
| CVE-2026-70635 json | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated a... | |
| CVE-2026-70634 json | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row... | |
| CVE-2026-70633 json | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compression ... | |
| CVE-2026-70632 json | FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro ... |