CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-74988 json Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corr...
CVE-2026-74968 json Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Th...
CVE-2026-74247 json A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-...
CVE-2026-74245 json A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exp...
CVE-2026-74244 json A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to f...
CVE-2026-74989 json Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security...
CVE-2026-74979 json Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbi...
CVE-2026-74243 json A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated atta...
CVE-2026-74240 json A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) auth...
CVE-2026-76047 json Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the ...
CVE-2026-76038 json Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the ...
CVE-2026-76037 json Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to poten...
CVE-2026-76036 json Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary...
CVE-2026-76034 json Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside...
CVE-2026-76033 json Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised t...
CVE-2026-77148 json A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?m...
CVE-2026-75526 json django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 until ...
CVE-2026-75514 json BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and antibot ...
CVE-2026-72854 json msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes its ...
CVE-2026-72852 json hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a...
CVE-2026-66788 json A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the des...
CVE-2026-9033 json An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active capt...
CVE-2026-8717 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-6822 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-6260 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-66787 json A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems ...
CVE-2026-66785 json A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other ...
CVE-2026-66002 json Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and Persona...
CVE-2026-66001 json Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in frapp...
CVE-2026-64777 json A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever...
CVE-2026-63654 json Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_...
CVE-2026-63003 json django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, p...
CVE-2026-62315 json Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/client.py...
CVE-2026-61663 json django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, r...
CVE-2026-54624 json django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, r...
CVE-2026-54622 json django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, t...
CVE-2026-53993 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-77031 json A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the file /go...
CVE-2026-76641 json Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by proces...
CVE-2026-73258 json Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or ...
CVE-2026-73253 json Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard ce...
CVE-2026-63383 json Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer re...
CVE-2026-53587 json libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to b...
CVE-2026-53586 json libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to b...
CVE-2026-53585 json libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to b...
CVE-2026-53584 json libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to b...
CVE-2026-53583 json libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to b...
CVE-2026-53569 json Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_as_see...
CVE-2026-50190 json Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in `application/front/contro...
CVE-2026-49996 json SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureD...
CVE-2026-46537 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-46536 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-46535 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-46534 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-46533 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-43678 json An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byt...
CVE-2026-19683 json A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-p...
CVE-2026-19586 json A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an Ope...
CVE-2026-15743 json Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static meth...
CVE-2026-76583 json A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by this vulnerability is an unknown functionality o...
CVE-2026-74016 json Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
CVE-2026-66612 json Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
CVE-2026-61625 json VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.146.0...
CVE-2026-54623 json django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, t...
CVE-2026-53425 json Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticate...
CVE-2026-53424 json Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a...
CVE-2026-48711 json SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SSHFS accepts a bracketed m...
CVE-2026-47187 json SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return ab...
CVE-2026-23501 json Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS ...
CVE-2026-20315 json As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team h...
CVE-2026-20231 json As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team h...
CVE-2026-16855 json IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a heap buffer ...
CVE-2026-76221 json GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to ...
CVE-2026-76220 json GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by ...
CVE-2026-76218 json GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without ...
CVE-2026-70421 json Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileg...
CVE-2026-49427 json Pages belonging to largepage shared memory objects were not explicitly wired. When sendfile(2) transmitted such an object wi...
CVE-2026-49419 json When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller's current p...
CVE-2026-49418 json When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping range are m...
CVE-2026-49415 json During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are updated. Du...
CVE-2026-21584 json This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, an...
CVE-2026-73899 json Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ...
CVE-2026-73897 json Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ...
CVE-2026-73895 json Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ...
CVE-2026-73893 json Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ...
CVE-2026-73892 json Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ...
CVE-2026-73890 json Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ...
CVE-2026-73889 json Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ...
CVE-2026-73888 json Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ...
CVE-2026-73887 json Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ...
CVE-2026-73877 json Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ...
CVE-2026-73876 json Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ...
CVE-2026-73875 json Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ...
CVE-2026-73872 json Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ...
CVE-2026-73871 json Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ...
CVE-2026-73868 json Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ...
CVE-2026-21582 json This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in ...
CVE-2026-74012 json Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a...
CVE-2026-71153 json Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ...
CVE-2026-71130 json Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report