CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-78618 json | A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations wi... | |
| CVE-2026-78617 json | WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a r... | |
| CVE-2026-78616 json | A Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's Trusted CA certificate configuration allows an au... | |
| CVE-2026-78615 json | A Reflected Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's report detail page allows an attacker to execu... | |
| CVE-2026-78614 json | WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authen... | |
| CVE-2026-78613 json | WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenti... | |
| CVE-2026-78612 json | WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an au... | |
| CVE-2026-78610 json | WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who c... | |
| CVE-2026-78500 json | A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows an au... | |
| CVE-2026-78499 json | A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenticated... | |
| CVE-2026-78498 json | A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticat... | |
| CVE-2026-78495 json | A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Remote Backup Connection Test configuration allows an... | |
| CVE-2026-78195 json | A Cross-Site Scripting (XSS) vulnerability in the WatchGuard Dimension Backup Historical Data feature allows an authenticated... | |
| CVE-2026-78174 json | WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privilege... | |
| CVE-2026-78103 json | WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endp... | |
| CVE-2026-78047 json | A stored cross-site scripting (XSS) vulnerability in WatchGuard Dimension's task scheduling feature allows a low-privileged a... | |
| CVE-2026-78011 json | An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to cre... | |
| CVE-2026-78010 json | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attac... | |
| CVE-2026-78009 json | An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to cr... | |
| CVE-2026-78008 json | A buffer overflow vulnerability in the WatchGuard Fireware OS Management Web UI allows an authenticated administrator with ne... | |
| CVE-2026-61802 json | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In ver... | |
| CVE-2026-61800 json | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In ver... | |
| CVE-2026-38822 json | In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status... | |
| CVE-2026-38821 json | A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the cap... | |
| CVE-2026-38820 json | openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas quer... | |
| CVE-2026-71166 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that... | |
| CVE-2026-38819 json | Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all... | |
| CVE-2026-19318 json | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attack... | |
| CVE-2026-19317 json | An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to cr... | |
| CVE-2026-19316 json | A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a D... | |
| CVE-2026-19315 json | A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to exec... | |
| CVE-2026-19314 json | An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to cre... | |
| CVE-2026-19313 json | An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute... | |
| CVE-2026-13108 json | WatchGuard Dimension is susceptible to a denial-of-service condition when an attacker sends a high volume of TCP SYN packets ... | |
| CVE-2026-13086 json | A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature... | |
| CVE-2025-13911 json | Ignition by Inductive Automation, when installed with default OS service account settings, may expose the host system to an ... | |
| CVE-2026-48419 json | Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in th... | |
| CVE-2026-48418 json | Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in th... | |
| CVE-2026-48421 json | Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in th... | |
| CVE-2026-48420 json | Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in th... | |
| CVE-2026-48423 json | Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution... | |
| CVE-2026-48422 json | Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution... | |
| CVE-2026-82072 json | Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside t... | |
| CVE-2026-81851 json | A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash the I... | |
| CVE-2026-81848 json | A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.2. The impacted element is the function s_fetch_p... | |
| CVE-2026-81847 json | A vulnerability was found in MAA-AI MaaMCP up to 1.1.1.dev6+g2e4a41287. The affected element is the function save_pipeline/lo... | |
| CVE-2026-81845 json | A vulnerability has been found in arben-adm mcp-sequential-thinking up to 0.5.0. Impacted is the function import_session/expo... | |
| CVE-2026-81837 json | A flaw has been found in RooCodeInc Roo-Code up to 3.51.1. This issue affects the function path.resolve of the file src/core/... | |
| CVE-2026-81836 json | A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file src/int... | |
| CVE-2026-81835 json | A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.1. This affects the function fetch_instructions ... | |
| CVE-2026-80179 json | A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numer... | |
| CVE-2026-78239 json | Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacke... | |
| CVE-2026-78037 json | Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker ... | |
| CVE-2026-77977 json | Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive admi... | |
| CVE-2026-77358 json | cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client free... | |
| CVE-2026-77341 json | cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0, the chunked-response trailer output path writes trail... | |
| CVE-2026-76945 json | The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An attac... | |
| CVE-2026-76943 json | Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass i... | |
| CVE-2026-76940 json | The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout mechan... | |
| CVE-2026-76179 json | An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication token... | |
| CVE-2026-76060 json | An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP re... | |
| CVE-2026-75814 json | The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface... | |
| CVE-2026-75813 json | Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or m... | |
| CVE-2026-75548 json | The affected Ebyte device web management interface does not restrict the interface from being rendered within an external fr... | |
| CVE-2026-75419 json | go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/servic... | |
| CVE-2026-75418 json | A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.14 on Windows. An attacke... | |
| CVE-2026-75417 json | A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within application/a... | |
| CVE-2026-75339 json | The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbi... | |
| CVE-2026-75337 json | The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-co... | |
| CVE-2026-73839 json | Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the risk o... | |
| CVE-2026-73809 json | A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management... | |
| CVE-2026-73125 json | Ebyte device web management interface does not consistently enforce authentication before granting access to administrative ... | |
| CVE-2026-71396 json | Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control. | |
| CVE-2026-71187 json | The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may... | |
| CVE-2026-69658 json | MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers... | |
| CVE-2026-68967 json | Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that coul... | |
| CVE-2026-68929 json | FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, the WeC... | |
| CVE-2026-67560 json | Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A craft... | |
| CVE-2026-61783 json | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In ver... | |
| CVE-2026-54330 json | Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 an... | |
| CVE-2026-54085 json | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In ver... | |
| CVE-2026-5706 json | In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack ... | |
| CVE-2026-54084 json | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In ver... | |
| CVE-2026-54083 json | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. The ... | |
| CVE-2026-50152 json | Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 an... | |
| CVE-2026-44629 json | Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appli... | |
| CVE-2026-39944 json | Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 an... | |
| CVE-2026-38350 json | An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers... | |
| CVE-2026-38349 json | An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to... | |
| CVE-2026-38348 json | An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of ... | |
| CVE-2026-38347 json | A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows at... | |
| CVE-2026-38346 json | An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to... | |
| CVE-2026-38345 json | A Division-by-Zero vulnerability in the ff_sws_init_single_context function (/libswscale/utils.c) of FFmpeg N-122528-gdd2976b... | |
| CVE-2026-38344 json | A NULL pointer dereference in the get_min_buffer_size function (/libswscale/slice.c) of FFmpeg N-122528-gdd2976b9e1 allows at... | |
| CVE-2026-38343 json | An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial... | |
| CVE-2026-18965 json | PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on the Pa... | |
| CVE-2026-18717 json | ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker to i... | |
| CVE-2026-81530 json | A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management crede... | |
| CVE-2026-81529 json | Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Dri... | |
| CVE-2026-81528 json | A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths ap... |