CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-77810 json | In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the... | |
| CVE-2026-76876 json | Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sensitive... | |
| CVE-2026-74252 json | Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Comme... | |
| CVE-2026-67362 json | Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - Fou... | |
| CVE-2026-67361 json | Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.... | |
| CVE-2026-67360 json | Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An ... | |
| CVE-2026-67359 json | Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An unauthentic... | |
| CVE-2026-67358 json | Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authe... | |
| CVE-2026-62960 json | Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle U... | |
| CVE-2026-50290 json | SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, CSS value sanitization stripped `ex... | |
| CVE-2026-77795 json | A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. This issue affects the function FlwInstanceController/F... | |
| CVE-2026-77237 json | Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task o... | |
| CVE-2026-77236 json | Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to corr... | |
| CVE-2026-77235 json | Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users... | |
| CVE-2026-63004 json | Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem ... | |
| CVE-2026-55850 json | Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/component... | |
| CVE-2026-54681 json | DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporter.Cor... | |
| CVE-2026-54073 json | VeraCrypt provides disk encryption with strong security based on TrueCrypt. From 1.26.6 until 1.26.29, file-hosted hidden vol... | |
| CVE-2026-50288 json | SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new URL()` throws a parse err... | |
| CVE-2026-35163 json | OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command not... | |
| CVE-2026-30866 json | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive v... | |
| CVE-2026-30819 json | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulne... | |
| CVE-2026-27490 json | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authe... | |
| CVE-2026-27463 json | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login pag... | |
| CVE-2026-27462 json | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid us... | |
| CVE-2026-77234 json | Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute c... | |
| CVE-2026-75484 json | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows an unauthenticated remote... | |
| CVE-2026-74836 json | Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote attacke... | |
| CVE-2026-71494 json | Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_... | |
| CVE-2026-68560 json | Wekan is open source kanban built with Meteor. Prior to 9.75, models/fileValidation.js interpolated the uploaded fileObj.path... | |
| CVE-2026-66797 json | Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure. Th... | |
| CVE-2026-62317 json | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's email subaddressing block... | |
| CVE-2026-61712 json | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior ... | |
| CVE-2026-55703 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and r... | |
| CVE-2026-55482 json | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkA... | |
| CVE-2026-55085 json | Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the ... | |
| CVE-2026-53425 json | Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticate... | |
| CVE-2026-53424 json | Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a... | |
| CVE-2026-20679 json | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 2... | |
| CVE-2026-75149 json | marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to ... | |
| CVE-2026-75145 json | FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc... | |
| CVE-2026-72717 json | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ... | |
| CVE-2026-71868 json | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ... | |
| CVE-2026-66794 json | A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an u... | |
| CVE-2026-62681 json | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an... | |
| CVE-2026-62673 json | Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt security rules omit ... | |
| CVE-2026-62666 json | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, Grav... | |
| CVE-2026-48024 json | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0... | |
| CVE-2026-41424 json | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.9.0 until 4.10.4 and 4.1... | |
| CVE-2026-76614 json | OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestore_sel POST pa... | |
| CVE-2026-76241 json | stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second expl... | |
| CVE-2026-76236 json | stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-f... | |
| CVE-2026-76230 json | Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-provide... | |
| CVE-2026-76225 json | ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation that fa... | |
| CVE-2026-71960 json | Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto M... | |
| CVE-2026-61607 json | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.2, the ... | |
| CVE-2026-53451 json | Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prio... | |
| CVE-2026-49253 json | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm uses rem... | |
| CVE-2026-44252 json | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh ... | |
| CVE-2026-76215 json | phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks before returning child resources including comments and att... | |
| CVE-2026-76210 json | phpMyFAQ before 4.1.6 does not adequately sanitize HTML in FAQ answers before generating PDFs via TCPDF. An attacker with per... | |
| CVE-2026-76205 json | phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by truncating... | |
| CVE-2026-76048 json | A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function o... | |
| CVE-2026-75987 json | A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of the f... | |
| CVE-2026-75978 json | A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the funct... | |
| CVE-2026-75916 json | SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup. In ge... | |
| CVE-2026-75900 json | An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffe... | |
| CVE-2026-62988 json | Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.g... | |
| CVE-2026-62291 json | libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image sequence with a 2x2 primar... | |
| CVE-2026-53959 json | 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enum... | |
| CVE-2026-53759 json | linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version... | |
| CVE-2026-53454 json | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio confi... | |
| CVE-2026-52873 json | Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.... | |
| CVE-2026-47699 json | Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From 0.16.... | |
| CVE-2026-74960 json | Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox... | |
| CVE-2026-74959 json | Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firef... | |
| CVE-2026-74957 json | Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ES... | |
| CVE-2026-74945 json | Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Fire... | |
| CVE-2026-74234 json | Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript ... | |
| CVE-2026-67443 json | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorizat... | |
| CVE-2026-47719 json | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVIC... | |
| CVE-2026-41921 json | Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion ... | |
| CVE-2026-19501 json | CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters... | |
| CVE-2026-16730 json | A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (n... | |
| CVE-2026-48507 json | Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user holding... | |
| CVE-2026-42318 json | GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, ... | |
| CVE-2026-39878 json | Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form th... | |
| CVE-2026-35198 json | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the... | |
| CVE-2026-76046 json | Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised... | |
| CVE-2026-76045 json | Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside t... | |
| CVE-2026-76044 json | Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer pro... | |
| CVE-2026-76043 json | Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code insi... | |
| CVE-2026-76042 json | Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised t... | |
| CVE-2026-76041 json | Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin ... | |
| CVE-2026-76040 json | Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engi... | |
| CVE-2026-76039 json | Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker lever... | |
| CVE-2026-73894 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-73893 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-73892 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-71110 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... |