CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-67867 json Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alarm/Con...
CVE-2026-67866 json Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the LockedSta...
CVE-2026-67863 json In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Su...
CVE-2026-19026 json H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_values[0] through cd_values[4] without validating that cd...
CVE-2026-19025 json H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout dimens...
CVE-2026-19024 json NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.1.1 allows attackers to cause a denial of service via a datase...
CVE-2026-19023 json Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.1.1 allows attackers to c...
CVE-2026-71321 json Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer...
CVE-2026-71320 json Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a tem...
CVE-2026-71319 json Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a ...
CVE-2026-71318 json Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top...
CVE-2026-71316 json Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /...
CVE-2026-67865 json S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denial of ...
CVE-2026-67864 json An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-in...
CVE-2026-18839 json An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width...
CVE-2025-63823 json My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attac...
CVE-2025-63822 json SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user...
CVE-2026-55767 json Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attrib...
CVE-2026-18739 json A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repe...
CVE-2026-15927 json A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/...
CVE-2024-9355 json A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer...
CVE-2022-1353 json A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, u...
CVE-2021-3501 json A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an ar...
CVE-2021-3483 json A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked...
CVE-2026-71315 json Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys ...
CVE-2026-71314 json Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker ...
CVE-2026-71313 json rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 un...
CVE-2026-71312 json rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75....
CVE-2026-71311 json rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0...
CVE-2026-71310 json rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0...
CVE-2026-71309 json rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 unt...
CVE-2026-34966 json Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF...
CVE-2026-18959 json A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::destroyF...
CVE-2026-18953 json Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-serv...
CVE-2026-18411 json The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key ac...
CVE-2026-17583 json The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited...
CVE-2026-15996 json A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to caus...
CVE-2022-30190 json A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Wo...
CVE-2019-15107 json An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerabilit...
CVE-2012-4681 json Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remot...
CVE-2026-65891 json Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Jo...
CVE-2026-62927 json In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers ...
CVE-2026-58080 json In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On serv...
CVE-2026-17346 json The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex t...
CVE-2026-10695 json IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries...
CVE-2026-10535 json IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
CVE-2024-13461 json The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2026-70618 json Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to en...
CVE-2026-70617 json Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker t...
CVE-2026-70616 json boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanently exh...
CVE-2026-70615 json boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tun...
CVE-2026-69111 json Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to t...
CVE-2026-68746 json Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to obta...
CVE-2026-66885 json Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's browse...
CVE-2026-66881 json Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with atta...
CVE-2026-66298 json Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger session...
CVE-2026-66297 json Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev livebo...
CVE-2026-55524 json PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the ...
CVE-2026-55523 json PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_cr...
CVE-2026-70612 json Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9...
CVE-2026-70609 json Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9...
CVE-2026-63457 json A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.
CVE-2026-55522 json PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praise...
CVE-2026-48168 json PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerabl...
CVE-2026-21766 json The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.  Und...
CVE-2026-18958 json A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf...
CVE-2026-18954 json Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow a...
CVE-2026-18485 json There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.  This may allow a loca...
CVE-2026-17633 json IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injec...
CVE-2026-17632 json IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper v...
CVE-2026-17624 json IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3...
CVE-2026-17556 json A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete ...
CVE-2026-10547 json IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/ver...
CVE-2026-9201 json IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic ...
CVE-2026-9130 json IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authen...
CVE-2026-8478 json IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improp...
CVE-2026-8470 json IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-...
CVE-2026-8182 json IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server with...
CVE-2026-7658 json IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traver...
CVE-2026-70448 json Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when...
CVE-2026-70447 json Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to en...
CVE-2026-70446 json Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enume...
CVE-2026-70444 json A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Re...
CVE-2026-70443 json Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, al...
CVE-2026-70442 json Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials l...
CVE-2026-70441 json Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, r...
CVE-2026-70440 json Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a Java...
CVE-2026-70439 json Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropria...
CVE-2026-67979 json Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attacke...
CVE-2026-55996 json A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent componen...
CVE-2026-54876 json Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by send...
CVE-2026-52370 json A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute ar...
CVE-2026-39923 json Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reu...
CVE-2026-16613 json The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable with...
CVE-2026-16605 json The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the ...
CVE-2026-15573 json A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security polic...
CVE-2026-7326 json A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a rem...
CVE-2026-0516 json A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to mani...
CVE-2025-70962 json Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in th...
CVE-2026-70553 json MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report