CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-107845 json Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment who...
CVE-2026-78797 json An issue in iStoreOS istoreos-24.10.7 and before allows a remote attacker to execute arbitrary code via the task_id in tasks-...
CVE-2026-108160 json AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to de...
CVE-2026-107935 json A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unau...
CVE-2026-107844 json Contao is an Open Source CMS. From version 5.0.0 until 5.3.50 and 5.7.12, ImagesController joins the user-controlled {path} p...
CVE-2026-107843 json Contao is an Open Source CMS. From version 4.1.0 until 5.3.50 and 5.7.12, ModuleRegistration::compile() enters its follow-up ...
CVE-2026-107842 json Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, ModuleSearch can disclose protected page titles, UR...
CVE-2026-107840 json yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middl...
CVE-2026-107812 json Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade mechanism validates a dow...
CVE-2026-105883 json Missing Authorization vulnerability in ThemeHunk Th Shop Mania th-shop-mania allows Exploiting Incorrectly Configured Access ...
CVE-2026-104758 json Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-73364. Reason: This candidate is a reser...
CVE-2026-104084 json SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role ...
CVE-2026-94067 json Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuel...
CVE-2026-94058 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Treck treck ...
CVE-2026-62042 json Missing Authorization vulnerability in unFocus Projects Scripts n Styles scripts-n-styles allows Exploiting Incorrectly Confi...
CVE-2026-62026 json Cross-Site Request Forgery (CSRF) vulnerability in MIGHTYminnow Dashboard Notes dashboard-notes allows Cross Site Request For...
CVE-2025-8457 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2016-20098 json Moderator Toolbox (reddit-moderator-toolbox) before 4.0.14 contains a stored cross-site scripting vulnerability in the remova...
CVE-2026-107802 json SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, src/SelectionTranslate.cpp embeds selected or pasted t...
CVE-2026-105697 json Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transpor...
CVE-2013-4590 json Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" infor...
CVE-2013-4444 json Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.F...
CVE-2013-4322 json Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly ...
CVE-2013-4286 json Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, do...
CVE-2013-2067 json java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 thro...
CVE-2012-5886 json The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before ...
CVE-2012-5885 json The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before...
CVE-2012-5568 json Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, a...
CVE-2012-4534 json org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector ...
CVE-2012-4431 json org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote ...
CVE-2012-3544 json Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, w...
CVE-2012-2524 json Microsoft Office 2007 SP2 and SP3 and 2010 SP1 allows remote attackers to execute arbitrary code or cause a denial of service...
CVE-2011-3389 json The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Go...
CVE-2006-0987 json The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and...
CVE-2004-0230 json TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of ser...
CVE-2002-0510 json The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, which co...
CVE-2002-0478 json The default configuration of Foundry Networks EdgeIron 4802F allows remote attackers to modify sensitive information via arbi...
CVE-2001-1210 json Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must ship ...
CVE-2001-0514 json SNMP service in Atmel 802.11b VNET-B Access Point 1.3 and earlier, as used in Netgear ME102 and Linksys WAP11, accepts arbitr...
CVE-2001-0380 json Crosscom/Olicom XLT-F running XL 80 IM Version 5.5 Build Level 2 allows a remote attacker SNMP read and write access via a de...
CVE-2000-0515 json The snmpd.conf configuration file for the SNMP daemon (snmpd) in HP-UX 11.0 is world writable, which allows local users to mo...
CVE-2026-73665 json FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/...
CVE-2026-73662 json FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line o...
CVE-2026-107841 json pacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0,...
CVE-2026-107835 json OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.8.1, internal/cookies.ParseC...
CVE-2026-107389 json music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the Matroska and WebM EBML parser deco...
CVE-2026-107384 json MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 unt...
CVE-2026-78835 json Rocket Software Rocket Remote Desktop 18.0.8583.1 is vulnerable to Insufficiently Protected Credentials.
CVE-2026-75353 json OpENer v2.3/ commit 76b95cf, contains an out-of-bounds read in the server-side EtherNet/IP ForwardOpen connection-path parser...
CVE-2026-75352 json OpENer v2.3/commit 76b95cf, contains an integer underflow in the server-side EtherNet/IP ForwardOpen connection-path parser. ...
CVE-2026-75351 json OpENer v2.3/commit 76b95cf, contains an out-of-bounds read in the server-side EtherNet/IP ForwardOpen connection-path parser....
CVE-2015-2467 json Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Mem...
CVE-2015-2466 json Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafte...
CVE-2013-4786 json The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote atta...
CVE-2002-1117 json Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be se...
CVE-2002-0109 json Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensiti...
CVE-2001-1184 json wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consump...
CVE-2000-1200 json Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPoli...
CVE-2000-0147 json snmpd in SCO OpenServer has an SNMP community string that is writable by default, which allows local attackers to modify the ...
CVE-1999-0792 json ROUTERmate has a default SNMP community name which allows remote attackers to modify its configuration.
CVE-1999-0516 json An SNMP community name is guessable.
CVE-1999-0472 json The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to...
CVE-1999-0024 json DNS cache poisoning via BIND, by predictable query IDs.
CVE-2026-84276 json IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticat...
CVE-2026-84278 json IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the SUID-root ssh_config_wrapper compon...
CVE-2026-108096 json Improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer in AWS Amplify API Category...
CVE-2026-107839 json ageLANServer provides a cross-platform web server and launcher for offline multiplayer in several Age of Empires and Age of M...
CVE-2026-107838 json RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. F...
CVE-2026-107837 json RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. I...
CVE-2026-107836 json RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. I...
CVE-2026-107834 json OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart l...
CVE-2026-107833 json OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessResponse...
CVE-2026-75350 json EIPStackGroup OpENer v2.3 / master commit 76b95cf contains a buffer overflow in the GetAttributeList() implementation for the...
CVE-2026-108157 json Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticate...
CVE-2026-108111 json ruoyi-ai 3.0.0 through 3.1.0 contains a missing authorization vulnerability in the GET /workflow/search endpoint that exposes...
CVE-2026-107826 json OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in int...
CVE-2026-107825 json OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessURI in i...
CVE-2026-107824 json x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality o...
CVE-2026-107823 json MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, a...
CVE-2026-107822 json MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, a...
CVE-2026-107821 json MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, a...
CVE-2026-107820 json x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality o...
CVE-2026-107819 json MariaDB Connector/C is a C and C++ client library for connecting applications to MariaDB and MySQL databases. From 3.4.1 unti...
CVE-2026-107818 json MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, a...
CVE-2026-107817 json MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, a...
CVE-2026-107816 json MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, a...
CVE-2026-90983 json Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. (Hayat Hospital) Hayat Mobile allows Authenti...
CVE-2026-75597 json pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the `/web/<path:filename>` rout...
CVE-2026-75348 json An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master up to commit 76b95cf in the EtherNet/IP TC...
CVE-2026-55797 json Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-...
CVE-2026-108125 json Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in wp-post-author. This i...
CVE-2026-108124 json Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in wp-post-author. This i...
CVE-2026-108109 json PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/control...
CVE-2026-108105 json Open5GS through 2.8.0 contains a reachable assertion vulnerability in mme_gn_handle_sgsn_context_request() that allows remote...
CVE-2026-107813 json Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster router exposes node and na...
CVE-2026-107808 json Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does...
CVE-2026-107807 json Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master cr...
CVE-2026-107803 json ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in P...
CVE-2026-107783 json Insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to recove...
CVE-2026-105877 json Insertion of Sensitive Information Into Sent Data vulnerability in QuarkA QA Analytics qa-heatmap-analytics allows Retrieve E...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report