CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-96589 json | When a private repository is transferred to a user who lacks access, Gitea grants that recipient temporary read access as a c... | |
| CVE-2026-96580 json | Gitea expanded a workflow's static `strategy.matrix` into its full Cartesian product without a size limit when creating a run... | |
| CVE-2026-96404 json | When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been... | |
| CVE-2026-96400 json | With `[migrations] ALLOWED_DOMAINS` set to a matching entry such as `*` or a hostname wildcard, Gitea's migration URL validat... | |
| CVE-2026-96399 json | A repository's external issue tracker regular expression containing alternating capture groups could produce invalid slice in... | |
| CVE-2026-95112 json | When processing issue and comment bodies, Gitea scanned the entire preceding text for action keywords such as "closes" or "fi... | |
| CVE-2026-95106 json | Gitea accepted pushed Git trees containing two entries with the same name, which Git's own consistency checks reject. Gitea's... | |
| CVE-2026-94205 json | Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the event rather than t... | |
| CVE-2026-94114 json | Symbolic name not mapping to correct object vulnerability in Apache Commons. BCEL caches attacker-controlled classes under... | |
| CVE-2026-89430 json | Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was crea... | |
| CVE-2026-79960 json | When a push was authenticated with a deploy key, Gitea recorded the repository owner as the pusher, so permission checks in t... | |
| CVE-2026-79818 json | A vulnerability in an API interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to circumvent ... | |
| CVE-2026-79817 json | A sensitive information disclosure vulnerability exists in the client software of HPE Networking ClearPass Policy Manager. Su... | |
| CVE-2026-79816 json | A vulnerability in a client interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attack... | |
| CVE-2026-79815 json | A command injection vulnerability in the OnGuard agent of ClearPass Policy Manager could allow an authenticated remote attack... | |
| CVE-2026-79814 json | An arbitrary file write vulnerability in the ClearPass Policy Manager OnGuard agent could allow malicious users on a local in... | |
| CVE-2026-79813 json | A local privilege escalation vulnerability exists in the ClearPass client software. Successful exploitation could allow a low... | |
| CVE-2026-79812 json | A denial of service vulnerability exists in the OnGuard agent of HPE Networking ClearPass Policy Manager. Successful exploita... | |
| CVE-2026-79811 json | A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authenticated attacker with adminis... | |
| CVE-2026-79810 json | Remote code execution vulnerabilities exist in the affected interface of HPE Networking ClearPass Policy Manager that could a... | |
| CVE-2026-79809 json | An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitatio... | |
| CVE-2026-79808 json | A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow ... | |
| CVE-2026-79807 json | A missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malici... | |
| CVE-2026-79806 json | A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Lin... | |
| CVE-2026-79805 json | An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an atta... | |
| CVE-2026-79803 json | A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authe... | |
| CVE-2026-79802 json | A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could al... | |
| CVE-2026-79801 json | A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could ... | |
| CVE-2026-79800 json | An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful ex... | |
| CVE-2026-79799 json | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attac... | |
| CVE-2026-79798 json | SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged ... | |
| CVE-2026-79797 json | An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager... | |
| CVE-2026-79796 json | Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an un... | |
| CVE-2026-79794 json | A SQL injection vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated ... | |
| CVE-2026-76754 json | A vulnerability in an affected interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduc... | |
| CVE-2026-76753 json | A format string vulnerability in an affected service interface of HPE Networking ClearPass Policy Manager could allow an unau... | |
| CVE-2026-76752 json | Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy... | |
| CVE-2026-76751 json | A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitati... | |
| CVE-2026-76750 json | Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Succ... | |
| CVE-2026-76749 json | A sensitive information disclosure vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated remo... | |
| CVE-2026-76748 json | A privilege escalation vulnerability exists in the API of AOS-S. Successful exploitation could allow an authenticated read-on... | |
| CVE-2026-106454 json | Twisted is an event-based framework for internet applications, supporting Python 3.6+. In 25.5.0 and earlier, wildcardToRegex... | |
| CVE-2026-106453 json | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to t... | |
| CVE-2026-106452 json | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates th... | |
| CVE-2026-106451 json | yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTe... | |
| CVE-2026-106450 json | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocate... | |
| CVE-2026-106449 json | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopO... | |
| CVE-2026-106448 json | StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor CBOR map decoding... | |
| CVE-2026-106447 json | StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor decoder recursive... | |
| CVE-2026-106446 json | Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() ... | |
| CVE-2026-106445 json | Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProp... | |
| CVE-2026-76747 json | Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthentica... | |
| CVE-2026-76746 json | An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated adja... | |
| CVE-2026-76745 json | Memory corruption vulnerabilities exist in AOS-S that are reachable by an unauthenticated adjacent attacker. Successful explo... | |
| CVE-2026-76744 json | Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthentica... | |
| CVE-2026-76743 json | A vulnerability have been identified in the management interface of AOS-S that could potentially allow an unauthenticated rem... | |
| CVE-2026-76742 json | Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an ... | |
| CVE-2026-76741 json | Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an authenticate... | |
| CVE-2026-76061 json | A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious c... | |
| CVE-2026-73278 json | Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only confi... | |
| CVE-2026-70357 json | Gitea validates a repository migration hostname against its network allow and block lists before invoking Git, but the Git su... | |
| CVE-2026-106444 json | Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile... | |
| CVE-2026-106063 json | A heap-based buffer overflow was found in GIMP’s DICOM export plug-in. When exporting an image with extremely large width a... | |
| CVE-2026-105244 json | Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net. Every character outside... | |
| CVE-2026-105243 json | Insufficient Logging vulnerability in the EventLogAppender of Apache log4net. Long messages were truncated to a fixed size t... | |
| CVE-2026-105242 json | Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading... | |
| CVE-2026-105241 json | Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net. Content that the mail fi... | |
| CVE-2026-105240 json | Improper Neutralization of Null Byte or NUL Character vulnerability in the OutputDebugStringAppender of Apache log4net. A NU... | |
| CVE-2026-105239 json | Improper Neutralization of Null Byte or NUL Character vulnerability in the EventLogAppender of Apache log4net. A NUL charact... | |
| CVE-2026-105111 json | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL. ... | |
| CVE-2026-104636 json | Gitea validated the initial remote URL for push mirrors, wiki remote checks, and fetches of migrated pull request heads, but ... | |
| CVE-2026-104632 json | Gitea Actions blocks the jobs of workflow runs from first-time fork pull request contributors until a maintainer approves the... | |
| CVE-2026-104626 json | A user who can open a fork pull request can place workflow content with a shared run-level concurrency group into a Gitea Act... | |
| CVE-2026-104048 json | A flaw was found in SSSD. In trust-enabled identity management environments, SSSD evaluates Host-Based Access Control (HBAC) ... | |
| CVE-2026-104047 json | A flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly sanitized before being in... | |
| CVE-2026-103670 json | When a Gitea Actions run was inserted, older runs in the same workflow-level concurrency group were cancelled without checkin... | |
| CVE-2026-103667 json | Gitea's container registry served blob downloads with a `Content-Type` taken from the media type declared in pushed image man... | |
| CVE-2026-103504 json | Changing an organization team's permission through the API with only the `permission` field did not rebuild the team's per-un... | |
| CVE-2026-103059 json | When Gitea's built-in SSH server is enabled (`START_SSH_SERVER = true`), the presented public key was looked up with an SQL `... | |
| CVE-2026-103009 json | Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a speciall... | |
| CVE-2026-103008 json | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted request that causes t... | |
| CVE-2026-103007 json | Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege ... | |
| CVE-2026-103006 json | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested reques... | |
| CVE-2026-103005 json | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation... | |
| CVE-2026-102413 json | Uncaught Exception (CWE-248) in Elastic Endpoint can lead to denial of service via a specially crafted file name. When Elasti... | |
| CVE-2026-102412 json | Incorrect Authorization (CWE-863) in Kibana can lead to sensitive information disclosure via Accessing Functionality Not Prop... | |
| CVE-2026-102411 json | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to Denial of Service via Excessive A... | |
| CVE-2026-102410 json | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constra... | |
| CVE-2026-102409 json | Uncontrolled Recursion (CWE-674) in Elasticsearch can allow an authenticated user with low privileges to terminate an Elastic... | |
| CVE-2026-102408 json | Inefficient Regular Expression Complexity (CWE-1333) in Elasticsearch can lead to denial of service via Regular Expression Ex... | |
| CVE-2026-102407 json | Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized data stream modification via Accessing Functional... | |
| CVE-2026-102406 json | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In this co... | |
| CVE-2026-102404 json | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-13... | |
| CVE-2026-102169 json | On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive... | |
| CVE-2026-102168 json | On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive... | |
| CVE-2026-102167 json | On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpo... | |
| CVE-2026-102165 json | On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a cra... | |
| CVE-2026-102164 json | On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA ... | |
| CVE-2026-102163 json | On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within ... | |
| CVE-2026-102162 json | On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerabi... |