CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-1579 json | The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signin... | |
| CVE-2026-67429 json | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-wr... | |
| CVE-2026-67428 json | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including sr... | |
| CVE-2026-67427 json | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resol... | |
| CVE-2026-67426 json | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification ... | |
| CVE-2026-67425 json | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such ... | |
| CVE-2026-67424 json | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, http.re... | |
| CVE-2026-67201 json | V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows atta... | |
| CVE-2026-66737 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-62995 json | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. i... | |
| CVE-2026-59919 json | Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Ne... | |
| CVE-2026-59901 json | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `... | |
| CVE-2026-59900 json | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty... | |
| CVE-2026-59898 json | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab a... | |
| CVE-2026-40272 json | Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel... | |
| CVE-2026-18236 json | A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is ... | |
| CVE-2026-16328 json | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a con... | |
| CVE-2026-16326 json | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow on... | |
| CVE-2026-14529 json | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 tradit... | |
| CVE-2026-14266 json | 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attac... | |
| CVE-2026-13346 json | pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locatio... | |
| CVE-2026-12935 json | The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer... | |
| CVE-2026-10684 json | In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used the 16-bit tgt_code field of a stored Zephyr coredump he... | |
| CVE-2026-8497 json | Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and ... | |
| CVE-2026-2482 json | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could ... | |
| CVE-2026-67194 json | Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via ... | |
| CVE-2026-54735 json | Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, cer... | |
| CVE-2026-54727 json | proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entri... | |
| CVE-2026-54078 json | veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF... | |
| CVE-2026-51992 json | SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via ... | |
| CVE-2026-48395 json | Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of ... | |
| CVE-2026-48390 json | Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could l... | |
| CVE-2026-18257 json | Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certifica... | |
| CVE-2026-18255 json | A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositor... | |
| CVE-2026-16729 json | undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.... | |
| CVE-2026-13723 json | A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary fil... | |
| CVE-2026-8338 json | A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. ... | |
| CVE-2025-60931 json | An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allo... | |
| CVE-2026-66758 json | A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation ... | |
| CVE-2026-60653 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Suppo... | |
| CVE-2026-60652 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Suppo... | |
| CVE-2026-60651 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Suppo... | |
| CVE-2026-60650 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Suppo... | |
| CVE-2026-60649 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Suppo... | |
| CVE-2026-60648 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Suppo... | |
| CVE-2026-60646 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Suppo... | |
| CVE-2026-35425 json | Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. | |
| CVE-2026-60645 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Suppo... | |
| CVE-2026-60644 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Suppo... | |
| CVE-2026-60643 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported ver... | |
| CVE-2026-60640 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported ver... | |
| CVE-2026-60639 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported ver... | |
| CVE-2026-60638 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported ver... | |
| CVE-2026-60637 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported ver... | |
| CVE-2026-60636 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported ver... | |
| CVE-2026-60635 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported ver... | |
| CVE-2026-60634 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported ver... | |
| CVE-2026-60633 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported ver... | |
| CVE-2026-62228 json | OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers... | |
| CVE-2026-62222 json | OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins.... | |
| CVE-2026-62207 json | OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach adm... | |
| CVE-2026-62203 json | OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly... | |
| CVE-2026-60632 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported ver... | |
| CVE-2026-60631 json | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported ver... | |
| CVE-2026-60627 json | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The su... | |
| CVE-2026-60623 json | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected... | |
| CVE-2026-60621 json | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). The sup... | |
| CVE-2026-60618 json | Vulnerability in the JD Edwards EnterpriseOne Procurement and Subcontract Management product of Oracle JD Edwards (component:... | |
| CVE-2026-60586 json | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected... | |
| CVE-2026-60569 json | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are a... | |
| CVE-2026-59866 json | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clie... | |
| CVE-2026-59865 json | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation... | |
| CVE-2026-59859 json | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.4, Kiota's PHP generator embedded OpenAPI description, de... | |
| CVE-2026-53633 json | Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a... | |
| CVE-2026-48358 json | Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code ex... | |
| CVE-2026-48324 json | ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerabili... | |
| CVE-2026-48321 json | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker cou... | |
| CVE-2026-48320 json | ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability ... | |
| CVE-2026-48319 json | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability tha... | |
| CVE-2026-46634 json | Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synth... | |
| CVE-2026-58629 json | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-50746 json | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Ap... | |
| CVE-2026-50426 json | Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network. | |
| CVE-2026-48356 json | Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary... | |
| CVE-2026-47995 json | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged att... | |
| CVE-2026-47994 json | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged atta... | |
| CVE-2026-43740 json | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, ma... | |
| CVE-2026-34693 json | Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (X... | |
| CVE-2026-34691 json | Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS)... | |
| CVE-2026-34632 json | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbit... | |
| CVE-2025-61140 json | The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution. | |
| CVE-2025-56499 json | Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files ... | |
| CVE-2026-20316 json | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated... | |
| CVE-2026-59920 json | Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Ne... | |
| CVE-2026-59899 json | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `Http... | |
| CVE-2026-54705 json | MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode content in ... | |
| CVE-2026-67193 json | Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obta... | |
| CVE-2026-62389 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as a duplicate of CVE-2026-48779. | |
| CVE-2026-60714 json | Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported ... | |
| CVE-2026-60112 json | AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticat... |