CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-100876 json | A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected... | |
| CVE-2026-96279 json | A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Fl... | |
| CVE-2026-96276 json | If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build... | |
| CVE-2026-88772 json | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-6... | |
| CVE-2026-88771 json | Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before... | |
| CVE-2026-100875 json | A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Thi... | |
| CVE-2026-100874 json | A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects... | |
| CVE-2026-100873 json | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The i... | |
| CVE-2026-101061 json | utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete a... | |
| CVE-2026-101060 json | python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool ... | |
| CVE-2026-101059 json | utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to ... | |
| CVE-2026-101058 json | python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual po... | |
| CVE-2026-101057 json | utcp-mcp (the MCP plugin of python-utcp) through 1.1.2 connects to the HTTP and WebSocket MCP server URLs given in a call tem... | |
| CVE-2026-101056 json | Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Atta... | |
| CVE-2026-101051 json | Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated users to... | |
| CVE-2026-101048 json | Cloudreve before 4.17.0 registers the administrative node test endpoints (POST /api/v4/admin/node/test and POST /api/v4/admin... | |
| CVE-2026-101047 json | Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise... | |
| CVE-2026-101046 json | Fleet before 4.89.0 contains an SQL injection vulnerability in the activity list endpoints (GET /api/v1/fleet/activities and ... | |
| CVE-2026-101045 json | Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generate... | |
| CVE-2026-101044 json | pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha.5, do... | |
| CVE-2026-101043 json | pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProx... | |
| CVE-2026-101050 json | Heym before 0.0.53 fails to verify the X-Telegram-Bot-Api-Secret-Token header on Telegram webhook endpoints when credential_i... | |
| CVE-2026-101049 json | Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing secr... | |
| CVE-2026-101042 json | Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-based a... | |
| CVE-2026-100865 json | Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflo... | |
| CVE-2026-100852 json | AzuraCast before 0.23.8 contains a command injection vulnerability in the Liquidsoap config generation for live recording tha... | |
| CVE-2026-88778 json | Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue ... | |
| CVE-2026-88777 json | Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: be... | |
| CVE-2026-88776 json | Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: bef... | |
| CVE-2026-88775 json | Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.3... | |
| CVE-2026-88774 json | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-6... | |
| CVE-2026-88773 json | Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Ci... | |
| CVE-2026-100841 json | In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_onl... | |
| CVE-2026-100673 json | The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the... | |
| CVE-2026-100672 json | The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that return... | |
| CVE-2026-100666 json | Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to and in... | |
| CVE-2026-100665 json | Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate ... | |
| CVE-2026-100664 json | Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority pseu... | |
| CVE-2026-100663 json | Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT ... | |
| CVE-2026-100662 json | Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource ... | |
| CVE-2026-100661 json | Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulne... | |
| CVE-2026-100660 json | Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK en... | |
| CVE-2026-100659 json | Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC 9114 ... | |
| CVE-2026-100658 json | Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue in WebSocketServerExtensionHandler. The handler ... | |
| CVE-2026-100657 json | Netty's STOMP codec (io.netty:netty-codec-stomp) contains a ByteBuf leak in StompSubframeDecoder. Once a frame's declared con... | |
| CVE-2026-100656 json | Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServerCodec. The codec tracks... | |
| CVE-2026-100655 json | Netty (io.netty:netty-codec-http) versions up to and including 4.1.137.Final and from 4.2.0.Final through 4.2.17.Final accept... | |
| CVE-2026-101041 json | The account recovery (password reset) functionality in the vulnerability-lookup web application contains a time-of-check-to-t... | |
| CVE-2026-101033 json | KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operations. ... | |
| CVE-2026-101032 json | navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Attackers... | |
| CVE-2026-100872 json | Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated ... | |
| CVE-2026-100871 json | Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens iss... | |
| CVE-2026-100870 json | Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the reques... | |
| CVE-2026-100869 json | Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers... | |
| CVE-2026-100868 json | Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-... | |
| CVE-2026-100867 json | spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before rendering th... | |
| CVE-2026-100866 json | onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allow... | |
| CVE-2026-100749 json | Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned file en... | |
| CVE-2026-100748 json | Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0 | |
| CVE-2026-100747 json | Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token che... | |
| CVE-2026-97165 json | Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” para... | |
| CVE-2026-97164 json | Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6... | |
| CVE-2026-94417 json | When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips th... | |
| CVE-2026-93304 json | A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been... | |
| CVE-2026-93302 json | MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that ... | |
| CVE-2026-89136 json | When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited server... | |
| CVE-2026-89135 json | A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certificate ... | |
| CVE-2026-89134 json | A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN dNSNa... | |
| CVE-2026-89133 json | wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforc... | |
| CVE-2026-89102 json | In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapli... | |
| CVE-2026-15442 json | In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutd... | |
| CVE-2026-94419 json | Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the for... | |
| CVE-2026-94418 json | Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to kee... | |
| CVE-2026-100741 json | Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on... | |
| CVE-2026-13742 json | Honeywell IQ MultiAccess, all versions prior to and including version 28, contain an improper digital signature verification ... | |
| CVE-2026-97319 json | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute be... | |
| CVE-2026-97227 json | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on... | |
| CVE-2026-96899 json | The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its... | |
| CVE-2026-96897 json | The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that... | |
| CVE-2026-96896 json | The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation chec... | |
| CVE-2026-96895 json | The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting ... | |
| CVE-2026-92995 json | The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, al... | |
| CVE-2026-92436 json | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading ... | |
| CVE-2026-89006 json | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as po... | |
| CVE-2026-89003 json | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supp... | |
| CVE-2026-89001 json | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitte... | |
| CVE-2026-89000 json | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination... | |
| CVE-2026-86841 json | The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrus... | |
| CVE-2026-86839 json | The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payme... | |
| CVE-2026-86609 json | The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked downl... | |
| CVE-2026-85002 json | The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML... | |
| CVE-2026-84069 json | The WebFacing™ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate a ... | |
| CVE-2026-82841 json | The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordP... | |
| CVE-2026-81655 json | The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it re... | |
| CVE-2026-0014 json | In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input valida... | |
| CVE-2025-47828 json | Lumi H5P-Nodejs-library before 9.3.3 omits a sanitizeHtml call for plain text strings. | |
| CVE-2026-100746 json | A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks... | |
| CVE-2026-85542 json | IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An... | |
| CVE-2026-100864 json | heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolve... | |
| CVE-2026-100863 json | Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/services/... |