CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-93965 json | A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/serv... | |
| CVE-2026-93964 json | A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertifi... | |
| CVE-2026-93963 json | A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function of t... | |
| CVE-2026-93962 json | A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_mallo... | |
| CVE-2026-93961 json | A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of the ... | |
| CVE-2026-93960 json | A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Control... | |
| CVE-2026-88097 json | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally. | |
| CVE-2026-86553 json | SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using t... | |
| CVE-2026-86552 json | SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired... | |
| CVE-2026-93959 json | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown proce... | |
| CVE-2026-94084 json | Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.respon... | |
| CVE-2026-94083 json | Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is e... | |
| CVE-2026-93958 json | A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi o... | |
| CVE-2026-93957 json | A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function SearchEngine::matchesSingleFilter... | |
| CVE-2026-86551 json | The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by qu... | |
| CVE-2026-90971 json | Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows ... | |
| CVE-2026-90969 json | Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticat... | |
| CVE-2026-88922 json | The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompressi... | |
| CVE-2026-84850 json | Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Se... | |
| CVE-2026-82837 json | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3... | |
| CVE-2026-81898 json | In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stor... | |
| CVE-2026-78030 json | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD... | |
| CVE-2026-77875 json | The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authent... | |
| CVE-2026-76672 json | A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An au... | |
| CVE-2026-68532 json | Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-... | |
| CVE-2026-18425 json | Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemapUpd... | |
| CVE-2026-18424 json | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a host's... | |
| CVE-2026-13327 json | Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows ... | |
| CVE-2026-9858 json | The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and inclu... | |
| CVE-2026-92078 json | Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156,... | |
| CVE-2026-92077 json | Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and ... | |
| CVE-2026-92067 json | Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156,... | |
| CVE-2026-92063 json | Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | |
| CVE-2026-92060 json | Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunder... | |
| CVE-2026-92058 json | Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, an... | |
| CVE-2026-92056 json | Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 1... | |
| CVE-2026-91966 json | AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability func... | |
| CVE-2026-91959 json | FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transp... | |
| CVE-2026-91951 json | FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_f... | |
| CVE-2026-91941 json | Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows u... | |
| CVE-2026-91935 json | Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect reque... | |
| CVE-2026-91930 json | Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing au... | |
| CVE-2026-91836 json | A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_s... | |
| CVE-2026-39919 json | Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_ope... | |
| CVE-2026-18113 json | In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them ... | |
| CVE-2026-13210 json | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 b... | |
| CVE-2026-12910 json | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 b... | |
| CVE-2026-12749 json | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticate... | |
| CVE-2026-12101 json | IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improp... | |
| CVE-2026-11927 json | IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services. | |
| CVE-2026-11918 json | IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanism... | |
| CVE-2026-92049 json | Use-after-free in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 15... | |
| CVE-2026-92046 json | Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, an... | |
| CVE-2026-92042 json | Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thund... | |
| CVE-2026-92040 json | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | |
| CVE-2026-92029 json | Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Fir... | |
| CVE-2026-92028 json | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ES... | |
| CVE-2026-92024 json | Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Fir... | |
| CVE-2026-92023 json | Use-after-free in the XML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Fir... | |
| CVE-2026-92022 json | Use-after-free in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ES... | |
| CVE-2026-92021 json | Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 140.16 and Thunderbird 14... | |
| CVE-2026-92018 json | Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ES... | |
| CVE-2026-92016 json | Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Fire... | |
| CVE-2026-91081 json | Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous atta... | |
| CVE-2026-90940 json | novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint ... | |
| CVE-2026-90780 json | SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processin... | |
| CVE-2026-90525 json | A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /... | |
| CVE-2026-90520 json | A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. Th... | |
| CVE-2026-82519 json | Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows aut... | |
| CVE-2026-13272 json | IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the vict... | |
| CVE-2024-58383 json | Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the X... | |
| CVE-2026-90515 json | A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown f... | |
| CVE-2026-90509 json | A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.bef... | |
| CVE-2026-89266 json | stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size i... | |
| CVE-2026-87824 json | zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to r... | |
| CVE-2026-86774 json | Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cas... | |
| CVE-2026-86769 json | Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoin... | |
| CVE-2026-86764 json | Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /ap... | |
| CVE-2026-86759 json | Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reas... | |
| CVE-2026-86754 json | Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated us... | |
| CVE-2026-71642 json | An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker... | |
| CVE-2026-94057 json | Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends ... | |
| CVE-2026-94056 json | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitia... | |
| CVE-2026-94055 json | Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free. | |
| CVE-2026-94054 json | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. | |
| CVE-2026-93993 json | Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git ... | |
| CVE-2026-93992 json | Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbi... | |
| CVE-2026-93991 json | Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails... | |
| CVE-2026-93990 json | Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 seq... | |
| CVE-2026-93989 json | vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in Samplin... | |
| CVE-2026-93988 json | QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authen... | |
| CVE-2026-93956 json | A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighlights... | |
| CVE-2026-93955 json | A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function str... | |
| CVE-2026-89155 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-93954 json | A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingC... | |
| CVE-2026-82560 json | Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives... | |
| CVE-2026-45363 json | ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token,... | |
| CVE-2026-82672 json | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a m... | |
| CVE-2026-76757 json | Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. | |
| CVE-2026-94001 json | A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used... |