CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-82733 json | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenti... | |
| CVE-2026-82732 json | Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argument values outs... | |
| CVE-2026-82731 json | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who contro... | |
| CVE-2026-82730 json | Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute value... | |
| CVE-2026-77950 json | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenti... | |
| CVE-2026-77856 json | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated at... | |
| CVE-2026-75865 json | The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is v... | |
| CVE-2026-74837 json | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated at... | |
| CVE-2026-67395 json | A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation ... | |
| CVE-2026-82475 json | iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to vali... | |
| CVE-2026-82469 json | Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tok... | |
| CVE-2026-82464 json | pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefix... | |
| CVE-2026-82457 json | su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid... | |
| CVE-2026-82452 json | rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack aut... | |
| CVE-2026-82447 json | Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a ... | |
| CVE-2026-82423 json | A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order... | |
| CVE-2026-67394 json | A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affectin... | |
| CVE-2026-65643 json | Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root. | |
| CVE-2026-55858 json | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5,... | |
| CVE-2026-55841 json | Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog For... | |
| CVE-2026-55784 json | free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-... | |
| CVE-2026-48932 json | A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outboun... | |
| CVE-2026-18477 json | A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attack... | |
| CVE-2026-15369 json | The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up... | |
| CVE-2026-58015 json | A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not... | |
| CVE-2026-58014 json | A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c f... | |
| CVE-2026-58013 json | A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a cu... | |
| CVE-2026-58012 json | A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compi... | |
| CVE-2026-58011 json | A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gda... | |
| CVE-2026-58010 json | A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c... | |
| CVE-2026-54100 json | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH... | |
| CVE-2026-54099 json | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-ap... | |
| CVE-2026-18508 json | A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to... | |
| CVE-2026-15588 json | A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authen... | |
| CVE-2026-14164 json | A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the ... | |
| CVE-2026-5704 json | A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidde... | |
| CVE-2026-55678 json | Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering accepts ... | |
| CVE-2026-18899 json | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal. | |
| CVE-2026-18743 json | A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host,... | |
| CVE-2026-3627 json | IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements... | |
| CVE-2026-82020 json | Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influen... | |
| CVE-2026-55569 json | aqua is a declarative command-line version manager written in Go. Prior to 2.60.1, pkg/unarchive/archives.go in the handler.H... | |
| CVE-2026-55549 json | Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from GET /... | |
| CVE-2026-55511 json | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving t... | |
| CVE-2026-55378 json | JS Recon is a JavaScript enumeration and SAST tool. From 1.2.1-beta.1 until 1.3.1-beta.2, the PR Branch Checker workflow in .... | |
| CVE-2026-55215 json | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versi... | |
| CVE-2026-55065 json | Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/vie... | |
| CVE-2026-17203 json | IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due... | |
| CVE-2026-15310 json | When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled si... | |
| CVE-2026-19820 json | A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze... | |
| CVE-2026-12051 json | The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer derefere... | |
| CVE-2026-11985 json | On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to CONF... | |
| CVE-2026-11812 json | The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-sc... | |
| CVE-2026-11368 json | The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel vi... | |
| CVE-2026-10849 json | The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server i... | |
| CVE-2026-10848 json | The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) u... | |
| CVE-2026-10774 json | Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth... | |
| CVE-2026-10773 json | The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char *... | |
| CVE-2026-10685 json | The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the ... | |
| CVE-2026-2411 json | Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose perm... | |
| CVE-2026-10684 json | In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used the 16-bit tgt_code field of a stored Zephyr coredump he... | |
| CVE-2026-10683 json | In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handler ga... | |
| CVE-2026-10659 json | The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks so that, on a ... | |
| CVE-2026-7007 json | The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl.c) be... | |
| CVE-2026-13479 json | The LoRaWAN application-layer clock-synchronization service parses downlinks in clock_sync_package_callback() (subsys/lorawan... | |
| CVE-2026-83524 json | A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 202607... | |
| CVE-2026-82971 json | A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/ne... | |
| CVE-2026-22244 json | OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server... | |
| CVE-2026-4560 json | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All refere... | |
| CVE-2026-13480 json | The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package_callback() in subsys/lorawan/services/frag_t... | |
| CVE-2026-66324 json | External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing ... | |
| CVE-2026-13481 json | The IEEE 1588 PTP management-message parser in subsys/net/lib/ptp/tlv.c mishandles the PTP_MGMT_TIME management id. In tlv_mg... | |
| CVE-2026-82256 json | SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node p... | |
| CVE-2026-70309 json | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over ... | |
| CVE-2026-66798 json | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |
| CVE-2026-82957 json | A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of... | |
| CVE-2026-82954 json | A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file pa... | |
| CVE-2026-82922 json | A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_... | |
| CVE-2026-82921 json | A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.... | |
| CVE-2026-82882 json | Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing aut... | |
| CVE-2026-82398 json | pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtim... | |
| CVE-2026-82397 json | Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-... | |
| CVE-2026-82396 json | Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/... | |
| CVE-2026-82395 json | Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the ... | |
| CVE-2026-82394 json | Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the ... | |
| CVE-2026-82393 json | pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's packa... | |
| CVE-2026-77353 json | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated us... | |
| CVE-2026-77352 json | Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.0.0, any authen... | |
| CVE-2026-77351 json | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated ... | |
| CVE-2026-82919 json | A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the fi... | |
| CVE-2026-82905 json | A vulnerability was detected in sdcb chats up to 1.12.0. This affects the function McpController of the file src/BE/web/Contr... | |
| CVE-2026-82813 json | A vulnerability was detected in BEN Group TubeBuddy for YouTube Extension up to 5.8.4 on Chrome. This impacts the function TB... | |
| CVE-2026-82703 json | A security flaw has been discovered in Edimax BR-6214K 1.40. This vulnerability affects the function system of the file www/p... | |
| CVE-2026-82698 json | A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affe... | |
| CVE-2026-82693 json | A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /... | |
| CVE-2026-82671 json | A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminateProcess in the ... | |
| CVE-2026-82666 json | A flaw has been found in yaojingang GEOFlow up to 2.1.0. This issue affects the function preview of the file app/Http/Control... | |
| CVE-2026-82629 json | A vulnerability was determined in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This issue affects the... | |
| CVE-2026-82622 json | A security vulnerability has been detected in code-projects Employee Leave Managing System 1.0. Affected is an unknown functi... | |
| CVE-2026-77348 json | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GH... |