CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-43752 json | An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious fi... | Fri, 10 Jul 2026 10:35:55 |
| CVE-2026-59834 json | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/ful... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-58144 json | Cotonti Siena 0.9.26 and earlier contains a stored cross-site scripting vulnerability that allows authenticated users with PF... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-57020 json | An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networ... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-57019 json | An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-56690 json | Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Co... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-56689 json | Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Co... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-55615 json | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.5, Neo4jChatAgent passe... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-55605 json | DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hosted H... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-55207 json | Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker ... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-49256 json | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-33803 json | An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved all... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-33802 json | A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated atta... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-33801 json | An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Network... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-33800 json | An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX ... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-22660 json | FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated administrators ... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-22659 json | FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows authenticated mode... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-21056 json | Improper authorization in Samsung Health prior to version 7.00.0.107 allows local attackers to access connected device inform... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-21050 json | Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive informat... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-15299 json | The Animation Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'weather_style' ... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-15291 json | The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all ver... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-15271 json | A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to ... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-14461 json | mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT respo... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2025-12127 json | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All refere... | Fri, 10 Jul 2026 10:20:15 |
| CVE-2026-33799 json | An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an a... | Fri, 10 Jul 2026 10:20:14 |
| CVE-2026-11332 json | A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's m... | Fri, 10 Jul 2026 10:20:14 |
| CVE-2026-15165 json | TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service | Fri, 10 Jul 2026 10:05:14 |
| CVE-2026-42582 json | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the... | Fri, 10 Jul 2026 09:49:53 |
| CVE-2026-56813 json | Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject or ov... | Fri, 10 Jul 2026 09:19:15 |
| CVE-2026-54470 json | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Referenc... | Fri, 10 Jul 2026 09:19:14 |
| CVE-2026-54469 json | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A l... | Fri, 10 Jul 2026 09:19:14 |
| CVE-2026-33390 json | An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiv... | Fri, 10 Jul 2026 09:19:14 |
| CVE-2026-31984 json | A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, ... | Fri, 10 Jul 2026 09:19:14 |
| CVE-2026-31983 json | A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker c... | Fri, 10 Jul 2026 09:19:14 |
| CVE-2026-31982 json | An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a us... | Fri, 10 Jul 2026 09:19:14 |
| CVE-2026-31981 json | A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation funct... | Fri, 10 Jul 2026 09:19:14 |
| CVE-2026-21049 json | Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code. | Fri, 10 Jul 2026 09:19:14 |
| CVE-2026-21046 json | Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged ... | Fri, 10 Jul 2026 09:19:14 |
| CVE-2026-21043 json | Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with sy... | Fri, 10 Jul 2026 09:19:14 |
| CVE-2026-21042 json | Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code. | Fri, 10 Jul 2026 09:19:14 |
| CVE-2026-58225 json | SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject SQL ... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-56814 json | Plug.Parsers.MULTIPART, the multipart request-body parser used to handle file uploads and multipart forms, does not enforce i... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-56688 json | Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Com... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-54468 json | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attac... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-53363 json | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_consum... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-53354 json | In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Mitigate TLBI errata on various Arm CPUs ... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-53345 json | In the Linux kernel, the following vulnerability has been resolved: KVM: Don't WARN if memory is dirtied without a vCPU when... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-53330 json | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-53166 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-21057 json | Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds ... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-21055 json | Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitr... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-21054 json | Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to access ... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-21053 json | Improper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files within ... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-21052 json | Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with ... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-21051 json | Incorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure TencentWif... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-15028 json | A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a special... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-14475 json | The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via the... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-12276 json | The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enabled on ... | Fri, 10 Jul 2026 08:18:15 |
| CVE-2026-44172 json | MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking no... | Fri, 10 Jul 2026 08:18:14 |
| CVE-2026-12329 json | Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12. | Fri, 10 Jul 2026 08:18:14 |
| CVE-2026-12298 json | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and... | Fri, 10 Jul 2026 08:18:14 |
| CVE-2026-12296 json | Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12... | Fri, 10 Jul 2026 08:18:14 |
| CVE-2026-12292 json | Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Th... | Fri, 10 Jul 2026 08:18:14 |
| CVE-2026-12143 json | form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to ... | Fri, 10 Jul 2026 08:18:14 |
| CVE-2026-44495 json | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains pro... | Fri, 10 Jul 2026 08:18:13 |
| CVE-2026-44494 json | Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerabl... | Fri, 10 Jul 2026 08:18:13 |
| CVE-2026-53435 json | In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary typ... | Fri, 10 Jul 2026 08:18:12 |
| CVE-2026-48710 json | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated b... | Fri, 10 Jul 2026 08:18:12 |
| CVE-2026-48526 json | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while sup... | Fri, 10 Jul 2026 08:18:12 |
| CVE-2026-45700 json | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-... | Fri, 10 Jul 2026 08:18:12 |
| CVE-2026-44488 json | Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configu... | Fri, 10 Jul 2026 08:18:12 |
| CVE-2026-42570 json | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. ... | Fri, 10 Jul 2026 08:18:12 |
| CVE-2026-41567 json | Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a c... | Fri, 10 Jul 2026 08:18:12 |
| CVE-2026-40984 json | In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) ... | Fri, 10 Jul 2026 08:18:12 |
| CVE-2026-39821 json | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For exampl... | Fri, 10 Jul 2026 08:18:12 |
| CVE-2026-34993 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.lo... | Fri, 10 Jul 2026 08:18:12 |
| CVE-2026-9277 json | shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op`... | Fri, 10 Jul 2026 08:18:12 |
| CVE-2026-8643 json | pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path ... | Fri, 10 Jul 2026 08:18:12 |
| CVE-2026-5241 json | A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled m... | Fri, 10 Jul 2026 08:18:12 |
| CVE-2025-71319 json | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Nod... | Fri, 10 Jul 2026 08:18:12 |
| CVE-2026-46595 json | Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback... | Fri, 10 Jul 2026 08:18:11 |
| CVE-2026-45736 json | ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulner... | Fri, 10 Jul 2026 08:18:11 |
| CVE-2026-42561 json | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulner... | Fri, 10 Jul 2026 08:18:11 |
| CVE-2026-42508 json | Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key... | Fri, 10 Jul 2026 08:18:11 |
| CVE-2026-39835 json | SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused... | Fri, 10 Jul 2026 08:18:11 |
| CVE-2026-39832 json | When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in... | Fri, 10 Jul 2026 08:18:11 |
| CVE-2026-39830 json | A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's re... | Fri, 10 Jul 2026 08:18:11 |
| CVE-2026-39829 json | The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively la... | Fri, 10 Jul 2026 08:18:11 |
| CVE-2026-39828 json | When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were sile... | Fri, 10 Jul 2026 08:18:11 |
| CVE-2026-44432 json | urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead... | Fri, 10 Jul 2026 08:18:10 |
| CVE-2026-42264 json | Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config p... | Fri, 10 Jul 2026 08:18:10 |
| CVE-2026-42006 json | An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, o... | Fri, 10 Jul 2026 08:18:10 |
| CVE-2026-27851 json | When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as s... | Fri, 10 Jul 2026 08:18:10 |
| CVE-2026-6322 json | fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw d... | Fri, 10 Jul 2026 08:18:10 |
| CVE-2026-6321 json | fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and ... | Fri, 10 Jul 2026 08:18:10 |
| CVE-2026-2614 json | A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and e... | Fri, 10 Jul 2026 08:18:10 |
| CVE-2026-42198 json | pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a cli... | Fri, 10 Jul 2026 08:18:09 |
| CVE-2026-42044 json | Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable... | Fri, 10 Jul 2026 08:18:09 |
| CVE-2026-41316 json | ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` insta... | Fri, 10 Jul 2026 08:18:09 |
| CVE-2026-41242 json | protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can ... | Fri, 10 Jul 2026 08:18:09 |