CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-96879 json | Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia Foundation's Mediawiki - Flag... | |
| CVE-2026-91769 json | PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, ... | |
| CVE-2026-91767 json | php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS serv... | |
| CVE-2026-91766 json | When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorizatio... | |
| CVE-2026-9313 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-100417 json | RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allo... | |
| CVE-2026-100391 json | MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and in... | |
| CVE-2026-100390 json | Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded head... | |
| CVE-2026-100389 json | GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handlin... | |
| CVE-2026-100388 json | RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the... | |
| CVE-2026-100387 json | pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that all... | |
| CVE-2026-100380 json | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Founda... | |
| CVE-2026-100379 json | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows... | |
| CVE-2026-100378 json | Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionality No... | |
| CVE-2026-100377 json | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Exten... | |
| CVE-2026-91765 json | cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacke... | |
| CVE-2026-57864 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-57443 json | SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1,... | |
| CVE-2026-17545 json | On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LP... | |
| CVE-2026-10758 json | Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap base... | |
| CVE-2026-6103 json | phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal d... | |
| CVE-2026-100376 json | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Founda... | |
| CVE-2026-100373 json | OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that... | |
| CVE-2026-100369 json | CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and ... | |
| CVE-2026-100208 json | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | |
| CVE-2026-96878 json | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo exten... | |
| CVE-2026-96877 json | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo exten... | |
| CVE-2026-96876 json | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo exten... | |
| CVE-2026-96875 json | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo exten... | |
| CVE-2026-93682 json | When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect ... | |
| CVE-2026-85511 json | A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-i... | |
| CVE-2026-5267 json | Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that doe... | |
| CVE-2025-14181 json | The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefine... | |
| CVE-2025-1218 json | The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes ... | |
| CVE-2026-93395 json | A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processin... | |
| CVE-2026-93394 json | A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and tran... | |
| CVE-2026-85892 json | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based... | |
| CVE-2026-77490 json | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allow... | |
| CVE-2026-68526 json | Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/con... | |
| CVE-2026-100372 json | ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticate... | |
| CVE-2026-100368 json | CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide speciali... | |
| CVE-2026-100310 json | GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment var... | |
| CVE-2026-63206 json | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sanitizer, which blocks rem... | |
| CVE-2026-57861 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-56731 json | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a low-privilege authenticated user may in... | |
| CVE-2026-56726 json | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, this vulnerability breaks normal ticket i... | |
| CVE-2026-53990 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-53629 json | GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right... | |
| CVE-2026-45801 json | GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without th... | |
| CVE-2026-88340 json | An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnera... | |
| CVE-2026-87902 json | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` fi... | |
| CVE-2026-71855 json | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior t... | |
| CVE-2026-71543 json | OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies coul... | |
| CVE-2026-70336 json | Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute co... | |
| CVE-2026-70335 json | Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studi... | |
| CVE-2026-68919 json | GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material m... | |
| CVE-2026-67421 json | RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ Manageme... | |
| CVE-2026-67415 json | RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, the Shovel parameter parser converted attacke... | |
| CVE-2026-67408 json | RabbitMQ is a messaging and streaming broker. From 4.1.0 until 4.3.3, 4.2.9, and 4.1.11, Stream Management Super-Stream Bindi... | |
| CVE-2026-67242 json | RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, OAuth2 isinteger(Exp) guard skips token-expir... | |
| CVE-2026-67234 json | RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, get_auth_mechanism/1 used term_to_binary/1 on... | |
| CVE-2026-67226 json | RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7, Admin-only atom exhaustion: PUT /... | |
| CVE-2026-57229 json | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.... | |
| CVE-2026-54584 json | mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when r... | |
| CVE-2026-52743 json | GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a reque... | |
| CVE-2026-69320 json | Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an un... | |
| CVE-2026-69306 json | Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over... | |
| CVE-2026-69278 json | Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| CVE-2026-62699 json | Null pointer dereference in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to execute ... | |
| CVE-2026-58650 json | Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security f... | |
| CVE-2026-47285 json | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthori... | |
| CVE-2026-83944 json | Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-77903 json | Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network... | |
| CVE-2026-70200 json | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized att... | |
| CVE-2026-69399 json | Azure Arc Elevation of Privilege Vulnerability | |
| CVE-2026-68791 json | Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network. | |
| CVE-1999-1598 json | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: ... | |
| CVE-1999-0199 json | manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value u... | |
| CVE-1999-1373 json | FORE PowerHub before 5.0.1 allows remote attackers to cause a denial of service (hang) via a TCP SYN scan with TCP/IP OS fing... | |
| CVE-1999-1263 json | Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded att... | |
| CVE-1999-1174 json | ZIP drive for Iomega ZIP-100 disks allows attackers with physical access to the drive to bypass password protection by insert... | |
| CVE-1999-1091 json | UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows atta... | |
| CVE-1999-1081 json | Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files. | |
| CVE-1999-1024 json | ip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length heade... | |
| CVE-2026-85917 json | Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-85885 json | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized atta... | |
| CVE-2026-83946 json | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized a... | |
| CVE-2026-69843 json | Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-85893 json | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-82355 json | When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow r... | |
| CVE-2026-69486 json | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |
| CVE-2026-87289 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported ve... | |
| CVE-2026-83488 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-microprofile-security). Supported versi... | |
| CVE-2026-97897 json | A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file... | |
| CVE-2026-97896 json | A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::... | |
| CVE-2026-97895 json | A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Ad... | |
| CVE-2026-97064 json | X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the databa... | |
| CVE-2026-97063 json | X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/co... | |
| CVE-2026-97060 json | X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify... | |
| CVE-2026-84465 json | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature ... |