CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-78555 json RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Although the...
CVE-2026-78553 json RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key file was...
CVE-2026-78551 json RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to enume...
CVE-2026-78430 json A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall of the...
CVE-2026-77923 json Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the p...
CVE-2026-77310 json jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to ...
CVE-2026-76816 json Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttE...
CVE-2026-76098 json Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through de...
CVE-2026-75509 json joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. P...
CVE-2026-75369 json An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT OBC s...
CVE-2026-75368 json A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Den...
CVE-2026-72714 json Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the ...
CVE-2026-78541 json A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated...
CVE-2026-78475 json A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocat...
CVE-2026-72711 json The Lean 4 kernel does not check that the body of an opaque declaration is closed. environment::add_opaque omits the check_no...
CVE-2026-72705 json The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own arguments. A fixpoint may pass...
CVE-2026-72704 json The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after that...
CVE-2026-72703 json The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without examining calls between th...
CVE-2026-71511 json Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated att...
CVE-2026-71510 json Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with ...
CVE-2026-71508 json Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows atta...
CVE-2026-71507 json Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write ...
CVE-2026-71505 json Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account wr...
CVE-2026-71503 json Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template wh...
CVE-2026-63693 json Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged a...
CVE-2026-61419 json Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker w...
CVE-2026-39975 json Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file...
CVE-2026-30864 json Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting ...
CVE-2020-37268 json Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition re...
CVE-2026-76836 json AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guardin...
CVE-2026-76835 json OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, becaus...
CVE-2026-71939 json Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. The vu...
CVE-2026-71934 json Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is c...
CVE-2026-71929 json Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability ...
CVE-2026-71924 json Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is ca...
CVE-2026-71919 json Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is...
CVE-2026-71914 json Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is cau...
CVE-2026-71909 json Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is c...
CVE-2026-71904 json Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability ...
CVE-2026-66908 json Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from ...
CVE-2026-66907 json Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0....
CVE-2026-66906 json Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from ...
CVE-2026-60093 json Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Camel: fr...
CVE-2026-78140 json A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/java/co...
CVE-2026-71514 json NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus...
CVE-2026-71366 json A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, ...
CVE-2026-71364 json A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts zip ...
CVE-2026-70626 json NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read ...
CVE-2026-65915 json NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a...
CVE-2026-63310 json NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. A...
CVE-2026-62385 json NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows a...
CVE-2026-59230 json Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9, from ...
CVE-2026-19874 json A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lo...
CVE-2026-19685 json NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connectio...
CVE-2026-8445 json justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text...
CVE-2026-4559 json The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'delay' sh...
CVE-2026-77413 json JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an...
CVE-2026-77220 json PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a point...
CVE-2026-62382 json PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. T...
CVE-2026-62381 json luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) wh...
CVE-2026-62243 json Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS ...
CVE-2026-61824 json Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image v...
CVE-2026-60084 json SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint tha...
CVE-2026-59808 json AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns vi...
CVE-2026-58003 json WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpo...
CVE-2026-56380 json AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated a...
CVE-2026-53541 json OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in the e...
CVE-2026-53530 json RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint `rat...
CVE-2026-53524 json WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module'...
CVE-2026-53468 json Typemill is a flat-file, Markdown-based content management system designed for informational documentation websites. Versions...
CVE-2026-4245 json The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. ...
CVE-2026-71694 json An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68c9619 allow...
CVE-2026-70839 json Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business Suite (component: Internal Operations). Support...
CVE-2026-70838 json Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported v...
CVE-2026-70827 json Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations)...
CVE-2026-70826 json Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported v...
CVE-2026-61539 json Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passe...
CVE-2026-55185 json Miniflux 2 is an open source feed reader. Prior to 2.3.1, IsRelativePath in internal/urllib/url.go accepts redirect targets c...
CVE-2026-51367 json An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the api_ve...
CVE-2026-51366 json SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code v...
CVE-2026-50720 json The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the RSA signature output agai...
CVE-2026-50719 json The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from th...
CVE-2026-50538 json LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or man-in-...
CVE-2026-30865 json Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulne...
CVE-2026-70825 json Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported v...
CVE-2026-70824 json Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported v...
CVE-2026-70821 json Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported v...
CVE-2026-70810 json Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported version...
CVE-2026-70804 json Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing)....
CVE-2026-70802 json Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing)....
CVE-2026-70801 json Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supporte...
CVE-2026-70799 json Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supp...
CVE-2026-70798 json Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versio...
CVE-2026-70797 json Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versio...
CVE-2026-70784 json Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported vers...
CVE-2026-70783 json Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported...
CVE-2026-70782 json Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supporte...
CVE-2026-70766 json Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported vers...
CVE-2026-70765 json Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported vers...
CVE-2026-70763 json Vulnerability in the Oracle Operations Intelligence product of Oracle E-Business Suite (component: Daily Business Intelligenc...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report