CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-71554 json | h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header block... | |
| CVE-2026-71476 json | Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hos... | |
| CVE-2026-71435 json | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") ... | |
| CVE-2026-71326 json | Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth midd... | |
| CVE-2026-70636 json | Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAu... | |
| CVE-2026-70631 json | FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the n... | |
| CVE-2026-70558 json | Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and f... | |
| CVE-2026-19192 json | A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\Dee... | |
| CVE-2026-11907 json | The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This is du... | |
| CVE-2026-64677 json | Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequ... | |
| CVE-2026-64655 json | GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify builds the certificate Sub... | |
| CVE-2026-62857 json | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affe... | |
| CVE-2026-48088 json | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version ... | |
| CVE-2026-48083 json | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version ... | |
| CVE-2026-48078 json | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version ... | |
| CVE-2026-48071 json | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version ... | |
| CVE-2026-45573 json | Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.r... | |
| CVE-2026-19108 json | A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesS... | |
| CVE-2026-19067 json | A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown functi... | |
| CVE-2026-19061 json | A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownlo... | |
| CVE-2026-5857 json | Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic... | |
| CVE-2025-4805 json | A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the... | |
| CVE-2025-4804 json | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Firew... | |
| CVE-2025-4106 json | An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a dia... | |
| CVE-2025-2782 json | The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-d... | |
| CVE-2025-2781 json | The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a no... | |
| CVE-2025-1910 json | The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escala... | |
| CVE-2025-1239 json | A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the... | |
| CVE-2026-47364 json | In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUI... | |
| CVE-2026-47363 json | In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an att... | |
| CVE-2026-47362 json | In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content ... | |
| CVE-2026-47361 json | In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard a... | |
| CVE-2026-44965 json | In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetAc... | |
| CVE-2026-13505 json | In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series),... | |
| CVE-2026-70646 json | aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deseri... | |
| CVE-2026-66707 json | Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions. | |
| CVE-2026-66701 json | Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions. | |
| CVE-2026-66692 json | Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 v... | |
| CVE-2026-66684 json | Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions. | |
| CVE-2026-66664 json | Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions. | |
| CVE-2026-66452 json | Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions. | |
| CVE-2026-66425 json | Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom ... | |
| CVE-2026-64564 json | In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP pr... | |
| CVE-2026-44964 json | In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no p... | |
| CVE-2026-43632 json | llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokeniz... | |
| CVE-2026-43627 json | llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unche... | |
| CVE-2026-19047 json | A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/execut... | |
| CVE-2026-7867 json | A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking ... | |
| CVE-2024-9355 json | A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer... | |
| CVE-2026-47427 json | GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go ac... | |
| CVE-2026-8798 json | In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the C... | |
| CVE-2026-71559 json | Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial ... | |
| CVE-2026-71560 json | Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0... | |
| CVE-2026-71558 json | Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.... | |
| CVE-2026-56793 json | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unaut... | |
| CVE-2026-56794 json | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low pri... | |
| CVE-2026-14540 json | A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbo... | |
| CVE-2026-14539 json | An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to an... | |
| CVE-2026-14538 json | An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp... | |
| CVE-2026-14537 json | Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allo... | |
| CVE-2025-6947 json | A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the... | |
| CVE-2024-8424 json | Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) a... | |
| CVE-2024-6594 json | Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the clien... | |
| CVE-2024-6593 json | Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an at... | |
| CVE-2024-6592 json | An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Sin... | |
| CVE-2026-14541 json | An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-too... | |
| CVE-2026-52880 json | Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a... | |
| CVE-2026-52879 json | Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message i... | |
| CVE-2026-52878 json | Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-... | |
| CVE-2026-49343 json | Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie sync... | |
| CVE-2026-48122 json | Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS C... | |
| CVE-2026-48120 json | Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be explo... | |
| CVE-2026-48047 json | XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to versi... | |
| CVE-2026-48026 json | lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the ope... | |
| CVE-2026-47249 json | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logi... | |
| CVE-2026-47243 json | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that pe... | |
| CVE-2026-47127 json | Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-URL han... | |
| CVE-2026-46409 json | OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to versio... | |
| CVE-2025-4438 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2024-4944 json | A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to exe... | |
| CVE-2026-71847 json | Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSO... | |
| CVE-2026-66062 json | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the conten... | |
| CVE-2026-64676 json | Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versi... | |
| CVE-2026-58262 json | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts t... | |
| CVE-2026-48170 json | `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH... | |
| CVE-2026-48169 json | PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failure... | |
| CVE-2026-48098 json | NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions ... | |
| CVE-2026-46405 json | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method... | |
| CVE-2026-45808 json | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide mult... | |
| CVE-2026-20348 json | A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condit... | |
| CVE-2026-19213 json | A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCore/Tr... | |
| CVE-2026-17435 json | File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When the fil... | |
| CVE-2026-11743 json | The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length on its... | |
| CVE-2026-11742 json | The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, reading t... | |
| CVE-2026-11430 json | Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook feature is... | |
| CVE-2026-20347 json | A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS con... | |
| CVE-2026-20345 json | A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condit... | |
| CVE-2026-20339 json | A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS con... | |
| CVE-2026-71381 json | Adobe Genuine Software Integrity Service was affected by an Incorrect Authorization vulnerability that could result in a Secu... | |
| CVE-2026-70624 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |