CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-65650 json | Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload. | |
| CVE-2026-65011 json | Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definit... | |
| CVE-2026-64833 json | FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to ... | |
| CVE-2026-64832 json | FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/... | |
| CVE-2026-46737 json | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST... | |
| CVE-2026-22049 json | ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerabilit... | |
| CVE-2026-16624 json | Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any ... | |
| CVE-2026-16607 json | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows f... | |
| CVE-2026-16606 json | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows f... | |
| CVE-2026-16157 json | Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Install... | |
| CVE-2026-7328 json | Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD com... | |
| CVE-2026-3482 json | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2... | |
| CVE-2026-65599 json | n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google S... | |
| CVE-2026-65593 json | n8n versions before 1.123.64 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints tha... | |
| CVE-2026-65015 json | n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution too... | |
| CVE-2026-50045 json | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed... | |
| CVE-2026-46582 json | In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be brief... | |
| CVE-2026-44690 json | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with prema... | |
| CVE-2026-44191 json | A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises... | |
| CVE-2026-16560 json | A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server... | |
| CVE-2026-16473 json | A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio pa... | |
| CVE-2026-16270 json | Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a... | |
| CVE-2026-13321 json | The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. Th... | |
| CVE-2026-13204 json | If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only on... | |
| CVE-2026-12617 json | The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DN... | |
| CVE-2026-11721 json | It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone i... | |
| CVE-2026-11622 json | A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway mem... | |
| CVE-2026-11605 json | The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records i... | |
| CVE-2026-11331 json | An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to... | |
| CVE-2026-10822 json | If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently... | |
| CVE-2026-10723 json | BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN re... | |
| CVE-2026-8152 json | Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. ... | |
| CVE-2026-65315 json | Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote... | |
| CVE-2026-61315 json | Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). Supported versions that are aff... | |
| CVE-2026-61314 json | Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: All Miscellaneous EDI Issues). Suppor... | |
| CVE-2026-61312 json | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versi... | |
| CVE-2026-61311 json | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versi... | |
| CVE-2026-61304 json | Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported ... | |
| CVE-2026-61303 json | Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). Supported versi... | |
| CVE-2026-61301 json | Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operatio... | |
| CVE-2026-61299 json | Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Operation... | |
| CVE-2026-61297 json | Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Internal Operations). Supported ... | |
| CVE-2026-61294 json | Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchronizat... | |
| CVE-2026-61292 json | Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Sup... | |
| CVE-2026-61289 json | Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality ... | |
| CVE-2026-16517 json | A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in arc... | |
| CVE-2026-16486 json | A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /... | |
| CVE-2026-15787 json | The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widge... | |
| CVE-2026-61287 json | Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations)... | |
| CVE-2026-61267 json | Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). ... | |
| CVE-2026-61266 json | Vulnerability in the Oracle Supply Chain Globalization product of Oracle E-Business Suite (component: Copy Inventory Organiza... | |
| CVE-2026-61264 json | Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: RDBMS and UI). Supported v... | |
| CVE-2026-61263 json | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Scripting Admin). Supported versions th... | |
| CVE-2026-61262 json | Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts). Support... | |
| CVE-2026-61254 json | Vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Business Suite (component: Korean Payroll). Support... | |
| CVE-2026-61249 json | Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supported... | |
| CVE-2026-61247 json | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported... | |
| CVE-2026-61245 json | Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration). ... | |
| CVE-2026-61244 json | Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina product of Oracle PeopleSoft (component: Manufacturing... | |
| CVE-2026-61243 json | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). ... | |
| CVE-2026-61242 json | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). ... | |
| CVE-2026-61240 json | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eSettlements... | |
| CVE-2026-61239 json | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement... | |
| CVE-2026-61238 json | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement... | |
| CVE-2026-61237 json | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration)... | |
| CVE-2026-61221 json | Vulnerability in the Oracle Item Master product of Oracle E-Business Suite (component: iSet-up bugs). Supported versions tha... | |
| CVE-2026-63080 json | Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authentica... | |
| CVE-2026-61220 json | Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configuration).... | |
| CVE-2026-61218 json | Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search I... | |
| CVE-2026-61217 json | Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supported... | |
| CVE-2026-61216 json | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll). Supported versions that are aff... | |
| CVE-2026-61214 json | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that ar... | |
| CVE-2026-61211 json | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31 and 23.... | |
| CVE-2026-61210 json | Vulnerability in the PeopleSoft Enterprise SCM Manufacturing product of Oracle PeopleSoft (component: Security). The suppor... | |
| CVE-2026-61209 json | Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). Th... | |
| CVE-2026-61207 json | Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requisition Statu... | |
| CVE-2026-61200 json | Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supporte... | |
| CVE-2026-56816 json | Netty is a network application framework for development of protocol servers and clients. Prior to 4.2.16.Final, Netty's `Htt... | |
| CVE-2026-47689 json | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-b... | |
| CVE-2026-47685 json | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-b... | |
| CVE-2026-47254 json | libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, `Track::init_sample_timing_table()` in `... | |
| CVE-2026-43945 json | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticate... | |
| CVE-2026-64880 json | Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escap... | |
| CVE-2026-64879 json | A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an a... | |
| CVE-2026-64878 json | Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in re... | |
| CVE-2026-56583 json | HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijack... | |
| CVE-2026-56582 json | HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitiv... | |
| CVE-2026-56581 json | HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data ... | |
| CVE-2026-56580 json | HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publi... | |
| CVE-2026-56579 json | HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed informatio... | |
| CVE-2026-56578 json | HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affec... | |
| CVE-2026-56577 json | HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or cre... | |
| CVE-2026-56146 json | Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration... | |
| CVE-2026-56145 json | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-13... | |
| CVE-2026-56144 json | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit i... | |
| CVE-2026-55082 json | DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. DHIS2 SQL View ... | |
| CVE-2026-49092 json | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Ac... | |
| CVE-2026-47418 json | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure... | |
| CVE-2026-42397 json | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Alloca... | |
| CVE-2026-30633 json | Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools. |