CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-19328 json A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSki...
CVE-2026-19327 json A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession of th...
CVE-2026-19326 json A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the file ...
CVE-2026-46579 json A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend do...
CVE-2026-19325 json A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983...
CVE-2026-19324 json A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by this is...
CVE-2026-16242 json A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was star...
CVE-2026-1784 json The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that...
CVE-2026-17510 json Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BM...
CVE-2026-71993 json MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that all...
CVE-2026-71992 json MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that a...
CVE-2026-71991 json MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used f...
CVE-2026-71990 json MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used f...
CVE-2026-71989 json MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that ...
CVE-2026-71988 json MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allo...
CVE-2026-71987 json MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows ...
CVE-2026-71986 json MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows ...
CVE-2026-71985 json MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function th...
CVE-2026-71984 json MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that a...
CVE-2026-19323 json A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by th...
CVE-2026-71983 json MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that al...
CVE-2026-11612 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-71502 json CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expr...
CVE-2026-71958 json D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnera...
CVE-2026-71957 json D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnera...
CVE-2026-71956 json D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulne...
CVE-2026-71955 json D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulne...
CVE-2026-71954 json D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injectio...
CVE-2026-71953 json D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injectio...
CVE-2026-71952 json D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injectio...
CVE-2026-71951 json D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injectio...
CVE-2026-71950 json D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injectio...
CVE-2026-71949 json D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injectio...
CVE-2026-71948 json D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injectio...
CVE-2026-71947 json D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injectio...
CVE-2026-71946 json D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injectio...
CVE-2026-71945 json D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injectio...
CVE-2025-8419 json A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection...
CVE-2025-7365 json A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during ...
CVE-2025-7195 json Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a ra...
CVE-2025-5278 json A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The prog...
CVE-2024-10973 json A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups ...
CVE-2024-9621 json A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user...
CVE-2026-71944 json D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injectio...
CVE-2025-49796 json A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corru...
CVE-2025-49794 json A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstance...
CVE-2025-7425 json A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory manage...
CVE-2025-5914 json A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() fu...
CVE-2024-5971 json A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and ...
CVE-2026-67620 json Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, ...
CVE-2026-42170 json A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file d...
CVE-2026-17107 json A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHA...
CVE-2026-2100 json A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remo...
CVE-2026-64601 json In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anc...
CVE-2026-64599 json In the Linux kernel, the following vulnerability has been resolved: crypto: amlogic - avoid double cleanup in meson_crypto_p...
CVE-2026-64598 json In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_alloc() The...
CVE-2026-64597 json In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A r...
CVE-2026-64588 json In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix data races on ring->ready On weakly-ord...
CVE-2026-64587 json In the Linux kernel, the following vulnerability has been resolved: net: ethernet: arc: emac: quiesce interrupts before requ...
CVE-2026-64586 json In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device removal ...
CVE-2026-64585 json In the Linux kernel, the following vulnerability has been resolved: can: esd_usb: kill anchored URBs before freeing netdevs ...
CVE-2026-64584 json In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: cancel pending IN work before freei...
CVE-2026-64583 json In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake_noti...
CVE-2026-64582 json In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_...
CVE-2026-64581 json In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_policy()...
CVE-2026-64580 json In the Linux kernel, the following vulnerability has been resolved: xfrm6: clear dst.dev on error to avoid double netdev_put...
CVE-2026-64578 json In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before reading Str...
CVE-2026-64577 json In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_echo_res...
CVE-2026-64576 json In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_migrate() n...
CVE-2026-64575 json In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock release on batch realloc bpf_...
CVE-2026-64574 json In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: tear down new links on vif update error ...
CVE-2026-64570 json In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix fils_discovery double free on alloc ...
CVE-2026-64568 json In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix unsol_bcast_probe_resp double free o...
CVE-2026-64567 json In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries than pa...
CVE-2026-64566 json In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_ad...
CVE-2026-64564 json In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP pr...
CVE-2026-64563 json In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhasht...
CVE-2026-64562 json In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR free_ne...
CVE-2026-64561 json In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making...
CVE-2026-4878 json A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in t...
CVE-2026-19288 json A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affec...
CVE-2026-19287 json A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the componen...
CVE-2026-19285 json A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnera...
CVE-2026-19284 json A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProject of...
CVE-2026-19282 json A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the ...
CVE-2026-7163 json A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multiclu...
CVE-2026-19281 json A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart...
CVE-2025-11393 json A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this...
CVE-2026-19279 json A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The impacted element is the function load_pdf of the file sr...
CVE-2026-68082 json In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode_lockers()...
CVE-2026-68081 json In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due...
CVE-2026-19270 json A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_journey...
CVE-2026-19268 json A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts the fu...
CVE-2026-19266 json A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file s...
CVE-2026-19263 json A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted element i...
CVE-2026-19259 json A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping_varA...
CVE-2026-16955 json The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding th...
CVE-2026-16953 json The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, a...
CVE-2026-16948 json The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes ...
CVE-2026-16608 json The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX ...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report