CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-86284 json A security vulnerability has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a...
CVE-2026-86282 json A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Af...
CVE-2026-86281 json A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This imp...
CVE-2026-86280 json A vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects ...
CVE-2026-84256 json An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authentica...
CVE-2026-84226 json OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a bi...
CVE-2026-82312 json OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of se...
CVE-2026-81830 json The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted config...
CVE-2026-81738 json OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via c...
CVE-2026-78254 json The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths th...
CVE-2026-78221 json An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local auth...
CVE-2026-78043 json The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted co...
CVE-2026-14296 json When using the Direct XIP update strategy, the main application image starts other cores (i.e. radio core), based on the curr...
CVE-2026-86279 json A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted ...
CVE-2026-86278 json A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected eleme...
CVE-2026-86277 json A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is a...
CVE-2026-79698 json A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-E...
CVE-2026-79697 json A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-E...
CVE-2026-86276 json A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects som...
CVE-2026-86275 json A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerabil...
CVE-2026-86274 json A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects the function E...
CVE-2026-86273 json A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getU...
CVE-2026-81302 json PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute ar...
CVE-2026-2670 json A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-E...
CVE-2026-86272 json A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000. This impacts...
CVE-2026-86271 json A vulnerability was found in FluentCMS up to 0.0.5. This affects the function GetAccessible of the file src/Backend/FluentCMS...
CVE-2026-86270 json A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of...
CVE-2026-86315 json An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can ...
CVE-2026-86269 json A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file...
CVE-2026-86268 json A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_L...
CVE-2026-86267 json A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affec...
CVE-2026-86265 json A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown f...
CVE-2026-86314 json Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms all...
CVE-2026-86313 json Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665e...
CVE-2026-86264 json A flaw has been found in sfturing ssm_pro up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of ...
CVE-2026-86263 json A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function...
CVE-2026-86262 json A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affect...
CVE-2026-86261 json A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is...
CVE-2026-86260 json A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected eleme...
CVE-2026-86245 json A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown fun...
CVE-2026-86244 json A security vulnerability has been detected in FastAdmin up to 1.2.0.20210401_beta. Affected is the function register/login of...
CVE-2026-86241 json A weakness has been identified in liufee FeehiCMS up to 2.1.1. This impacts an unknown function of the file environments/prod...
CVE-2026-86240 json A security flaw has been discovered in liufee FeehiCMS up to 2.1.1. This affects the function catchImage of the file backend/...
CVE-2026-86239 json A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of th...
CVE-2026-20518 json In geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information ...
CVE-2026-20517 json In geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privi...
CVE-2026-20516 json In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of ...
CVE-2026-20515 json In gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User exe...
CVE-2026-20514 json In Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to local informat...
CVE-2026-20513 json In Audio HAL, there is a possible information disclosure due to improper input validation. This could lead to local informati...
CVE-2026-20512 json In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalati...
CVE-2026-20511 json In SurfaceFlinger, there is a possible memory corruption due to use after free. This could lead to local escalation of privil...
CVE-2026-20510 json In camera middleware, there is a possible escalation of privilege due to double free. This could lead to local escalation of ...
CVE-2026-20509 json In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p...
CVE-2026-20508 json In Power HAL, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privi...
CVE-2026-20507 json In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privi...
CVE-2026-20506 json In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privi...
CVE-2026-20504 json In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a U...
CVE-2026-20503 json In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a U...
CVE-2026-20502 json In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privil...
CVE-2026-20501 json In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privil...
CVE-2026-20500 json In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with ...
CVE-2026-16876 json An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication ...
CVE-2026-86238 json A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of...
CVE-2026-86237 json A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model...
CVE-2026-86236 json A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of ...
CVE-2026-86235 json A flaw has been found in itsourcecode Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pa...
CVE-2026-86234 json A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/...
CVE-2026-86233 json A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unk...
CVE-2026-86304 json MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAM...
CVE-2026-86232 json A weakness has been identified in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown f...
CVE-2026-86231 json A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main...
CVE-2026-86228 json A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the...
CVE-2026-86227 json A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the fi...
CVE-2026-86226 json A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown func...
CVE-2026-86225 json A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the...
CVE-2026-49509 json Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 25648aef...
CVE-2025-5278 json A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The prog...
CVE-2025-2842 json A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed b...
CVE-2025-2786 json A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploy...
CVE-2024-11831 json A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not prope...
CVE-2026-86224 json A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query...
CVE-2025-5318 json A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handl...
CVE-2026-86223 json A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of ...
CVE-2026-86222 json A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_quer...
CVE-2026-54100 json A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH...
CVE-2026-54099 json A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-ap...
CVE-2026-4878 json A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in t...
CVE-2025-6020 json A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allow...
CVE-2025-4373 json A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the posi...
CVE-2026-86221 json A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_qu...
CVE-2026-75569 json A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without perf...
CVE-2026-86220 json A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function my...
CVE-2026-86219 json Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce ...
CVE-2026-82209 json When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie`...
CVE-2026-82208 json With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, lib...
CVE-2026-80255 json A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secu...
CVE-2026-80231 json A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different ...
CVE-2026-80230 json When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPE...
CVE-2026-80229 json When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles....

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report