CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-104286 json | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 t... | |
| CVE-2026-102671 json | The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default. | |
| CVE-2026-102670 json | Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it. | |
| CVE-2026-102669 json | Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages. | |
| CVE-2026-102668 json | The Joyland AI app accepts any TLS certificates from any server without validation. | |
| CVE-2026-102667 json | Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without use... | |
| CVE-2026-102666 json | The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access th... | |
| CVE-2026-102628 json | The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a pu... | |
| CVE-2026-100251 json | Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peer... | |
| CVE-2026-84682 json | A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent... | |
| CVE-2026-82358 json | RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/co_s... | |
| CVE-2026-82357 json | RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object ... | |
| CVE-2026-8618 json | A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient ... | |
| CVE-2026-104056 json | Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer... | |
| CVE-2026-103884 json | A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, ... | |
| CVE-2026-102369 json | Tapo C120 v1 and C200 V5 do not adequately protect login challenge data or sanitize attacker-controlled input processed by th... | |
| CVE-2026-102294 json | TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 ... | |
| CVE-2026-97662 json | An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow cont... | |
| CVE-2026-78578 json | Tapo C120 v1 and C200 v5 do not enforce authentication for do method HTTPS onboarding connect actions after initial setup. ... | |
| CVE-2026-78577 json | Tapo C120 v1 and C200 V5 contain a vulnerability in the HTTPS onboarding scan function due to missing authentication. After i... | |
| CVE-2026-56098 json | A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability ... | |
| CVE-2026-56097 json | A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. T... | |
| CVE-2026-15911 json | Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information... | |
| CVE-2026-12545 json | A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rail... | |
| CVE-2026-12542 json | A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval... | |
| CVE-2026-9032 json | Tapo C120 v1 and C200 v5 contain a NULL pointer dereference in the HTTPS onboarding connect request parser. The interface i... | |
| CVE-2026-96659 json | A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unaut... | |
| CVE-2026-96658 json | A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by ... | |
| CVE-2026-93546 json | Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access t... | |
| CVE-2026-79768 json | ||
| CVE-2026-73637 json | Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an u... | |
| CVE-2026-73636 json | Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all plat... | |
| CVE-2026-67172 json | HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive inform... | |
| CVE-2026-67171 json | HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes ... | |
| CVE-2026-63718 json | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache H... | |
| CVE-2026-63686 json | A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms all... | |
| CVE-2026-63292 json | Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platfor... | |
| CVE-2026-63045 json | Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.6... | |
| CVE-2026-59797 json | Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. T... | |
| CVE-2026-59685 json | Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when e... | |
| CVE-2026-58415 json | Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4... | |
| CVE-2026-57941 json | Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects A... | |
| CVE-2026-56449 json | Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue aff... | |
| CVE-2026-56154 json | Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affect... | |
| CVE-2026-56153 json | Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.... | |
| CVE-2026-48005 json | Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platfo... | |
| CVE-2026-14316 json | The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is... | |
| CVE-2026-12544 json | A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulner... | |
| CVE-2026-12541 json | A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks.... | |
| CVE-2026-12540 json | A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_... | |
| CVE-2026-12423 json | A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypa... | |
| CVE-2026-12405 json | A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (... | |
| CVE-2025-31980 json | HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inj... | |
| CVE-2026-103690 json | A flaw has been found in itsourcecode Leave Management System 1.0. This vulnerability affects unknown code of the file /modul... | |
| CVE-2026-103505 json | Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3... | |
| CVE-2026-101322 json | In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the sel... | |
| CVE-2026-79900 json | boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases veri... | |
| CVE-2026-79899 json | Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temp... | |
| CVE-2026-79898 json | Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs... | |
| CVE-2026-79896 json | Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A... | |
| CVE-2026-67106 json | HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return... | |
| CVE-2026-47360 json | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. ... | |
| CVE-2026-46729 json | NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects A... | |
| CVE-2026-42528 json | A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV lo... | |
| CVE-2026-42356 json | Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI program... | |
| CVE-2026-12627 json | Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A ... | |
| CVE-2026-9864 json | Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account pass... | |
| CVE-2026-103752 json | Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions. | |
| CVE-2026-103687 json | A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file s... | |
| CVE-2026-103347 json | Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions. | |
| CVE-2026-103068 json | Subscriber Privilege Escalation in ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 versions. | |
| CVE-2026-102378 json | Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions. | |
| CVE-2026-100517 json | Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions. | |
| CVE-2026-100514 json | Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions. | |
| CVE-2026-67105 json | HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with inte... | |
| CVE-2026-67104 json | HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated at... | |
| CVE-2026-62073 json | Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions. | |
| CVE-2026-62071 json | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions. | |
| CVE-2026-56599 json | HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an a... | |
| CVE-2026-56589 json | HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker... | |
| CVE-2026-93832 json | A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtim... | |
| CVE-2026-71542 json | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.... | |
| CVE-2026-71426 json | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.... | |
| CVE-2026-70650 json | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.... | |
| CVE-2026-103484 json | IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary ... | |
| CVE-2026-56662 json | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to versi... | |
| CVE-2026-56661 json | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to versi... | |
| CVE-2026-56660 json | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to versi... | |
| CVE-2026-55252 json | OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Pri... | |
| CVE-2026-55251 json | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to comm... | |
| CVE-2026-54049 json | Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3,... | |
| CVE-2026-53964 json | Document Merge Service is a document template merge service providing an API to manage templates and merge them with given da... | |
| CVE-2026-53953 json | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3... | |
| CVE-2026-14984 json | Cleartext transmission in the primary control endpoints of Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauth... | |
| CVE-2026-14983 json | Missing authentication in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated at... | |
| CVE-2026-104057 json | Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps... | |
| CVE-2026-55231 json | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.... | |
| CVE-2026-55230 json | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.... | |
| CVE-2026-27872 json | - Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy I... | |
| CVE-2026-97297 json | Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions. |