CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-103105 json | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which ... | |
| CVE-2026-103104 json | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation wh... | |
| CVE-2026-103102 json | Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote att... | |
| CVE-2026-103101 json | Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicio... | |
| CVE-2026-103100 json | Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious a... | |
| CVE-2026-105767 json | Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of C... | |
| CVE-2026-105766 json | Use of the backend-facing $scheme variable in the trailing-slash directory redirect in nginx.conf of Chainguard Academy (edu)... | |
| CVE-2026-105696 json | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-page RPC accepts a share-link permission o... | |
| CVE-2026-105695 json | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using ... | |
| CVE-2026-105694 json | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, authenticated users with file-edit permission can ... | |
| CVE-2026-105693 json | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC retur... | |
| CVE-2026-105692 json | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selec... | |
| CVE-2026-105691 json | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled tex... | |
| CVE-2026-105690 json | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie with... | |
| CVE-2026-105689 json | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, app.util.ssrf/blocked-address? relies on Java Inet... | |
| CVE-2026-105688 json | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation accepta... | |
| CVE-2026-105687 json | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administr... | |
| CVE-2026-105686 json | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the chunked media upload RPC validates that a chun... | |
| CVE-2026-105684 json | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-comment-threads, get-comment-thread, and g... | |
| CVE-2026-105683 json | Ghost is a Node.js content management system. From 6.14.0 until 6.27.0, an input validation issue may have allowed staff user... | |
| CVE-2026-105682 json | Ghost is a Node.js content management system. From 1.18.0 until 6.27.0, an SSRF vulnerability in the webhooks feature allowed... | |
| CVE-2026-105681 json | Ghost is a Node.js content management system. From 5.9.0 until 6.44.1, an input validation issue allowed members to access co... | |
| CVE-2026-105680 json | Ghost is a Node.js content management system. From 5.81.0 until 6.60.0, staff with the Author role could delete posts and pag... | |
| CVE-2026-105679 json | Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploa... | |
| CVE-2026-105678 json | Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were ... | |
| CVE-2026-105677 json | Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation ... | |
| CVE-2026-105676 json | Ghost is a Node.js content management system. From 1.20.0 until 6.64.0, a vulnerability in how Ghost loads theme translation ... | |
| CVE-2026-105675 json | Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites wer... | |
| CVE-2026-105652 json | Ghost is a Node.js content management system. From 0.7.2 until 6.64.0, any staff-level user was able to determine the relativ... | |
| CVE-2026-105651 json | Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark card, Ghost could store non-... | |
| CVE-2026-105650 json | Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website co... | |
| CVE-2026-105649 json | Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a n... | |
| CVE-2026-105648 json | Ghost is a Node.js content management system. From 6.0.9 until 6.65.0, a validation issue allowed some functionality, such as... | |
| CVE-2026-97257 json | Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Inject... | |
| CVE-2026-95265 json | Feehi CMS 2.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the UEditor catchimage endpoint. The private-I... | |
| CVE-2026-95264 json | Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backend user with article edit permission can delete a... | |
| CVE-2026-95263 json | Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update pe... | |
| CVE-2026-94201 json | Ash stores :atom-typed attributes as strings and compares them as strings. When such an attribute is referenced in a filter, ... | |
| CVE-2026-93617 json | Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injectio... | |
| CVE-2026-78862 json | An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the UART serial interface on the printed c... | |
| CVE-2026-78861 json | An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via a hardcoded 512-bit RSA Private Key | |
| CVE-2026-78860 json | An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the storage of information in plaintext | |
| CVE-2026-71299 json | A flaw was found in Maestro. Its REST API write endpoints were registered without proper authentication middleware. This allo... | |
| CVE-2026-71298 json | A flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the `orderBy` query parameter o... | |
| CVE-2026-71297 json | A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to... | |
| CVE-2026-105712 json | gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive w... | |
| CVE-2026-105647 json | Ghost is a Node.js content management system. From 6.54.1 until 6.65.0, a validation issue allowed some functionality, such a... | |
| CVE-2026-105645 json | Ghost is a Node.js content management system. From 5.37.0 until 6.67.0, a crafted request to the external media inliner could... | |
| CVE-2026-105642 json | Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contai... | |
| CVE-2026-105637 json | Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/as... | |
| CVE-2026-105632 json | Plane is an open-source project management tool. Prior to 1.4.0, the GraphQL joinProject mutation lets any workspace member a... | |
| CVE-2026-105392 json | A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the f... | |
| CVE-2026-105389 json | A security vulnerability has been detected in feelec-yishu feelcrm-os 1.0.0. This issue affects some unknown processing of th... | |
| CVE-2026-105388 json | A weakness has been identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function index of the file Ap... | |
| CVE-2026-104979 json | Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes descr... | |
| CVE-2026-104974 json | Plane is an open-source project management tool. Prior to 1.4.0, a user whose account has been deactivated by setting is_acti... | |
| CVE-2026-104968 json | Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/entity-search/?query_type=user_me... | |
| CVE-2026-104964 json | Plane is an open-source project management tool. Prior to 1.4.0, Plane's project update endpoint authorizes the caller agains... | |
| CVE-2026-104956 json | Plane is an open-source project management tool. Prior to 1.4.0, the unauthenticated public issues endpoint accepts group_by ... | |
| CVE-2026-104891 json | mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition... | |
| CVE-2026-104714 json | Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. W... | |
| CVE-2026-104713 json | Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin. A request body is read i... | |
| CVE-2026-104712 json | Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbit... | |
| CVE-2026-104711 json | Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulner... | |
| CVE-2026-104030 json | A flaw was found in sssd. This vulnerability allows a local user to cause a Denial of Service (DoS) by submitting a specially... | |
| CVE-2026-104029 json | A flaw was found in SSSD. A local attacker can exploit this vulnerability by sending a specially crafted request to the autof... | |
| CVE-2026-103348 json | Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object I... | |
| CVE-2026-103337 json | Missing Authorization vulnerability in Kirillbdev WC Ukraine Shipping wc-ukr-shipping allows Exploiting Incorrectly Configure... | |
| CVE-2026-103066 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking... | |
| CVE-2026-102779 json | Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automation tasks in TF Content 2.9.0 - 2.9.4... | |
| CVE-2026-102777 json | Joomla Extension - svenbluege.de - Server-side request forgery in the Google Photos picker in Event Gallery extension < 6.6.0... | |
| CVE-2026-100511 json | Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager al... | |
| CVE-2026-100506 json | Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This ... | |
| CVE-2026-93319 json | A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race th... | |
| CVE-2026-93318 json | A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, B... | |
| CVE-2026-93317 json | An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match t... | |
| CVE-2026-93316 json | If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can ha... | |
| CVE-2026-86671 json | In Eclipse Che versions 7.29.0 and later, the GET `/api/scm/resolve` and `POST /api/factory/resolver` endpoints pass an attac... | |
| CVE-2026-78413 json | Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anyth... | |
| CVE-2026-78412 json | Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks t... | |
| CVE-2026-78411 json | Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a use... | |
| CVE-2026-58880 json | In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition. This cou... | |
| CVE-2026-58859 json | In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation ... | |
| CVE-2026-58856 json | In returnOutputBufferLocked of DeprecatedCamera3StreamSplitter.cpp, there is a possible out-of-bounds read due to a missing b... | |
| CVE-2026-58854 json | In multiple locations, there is a possible memory corruption due to type confusion. This could lead to local escalation of pr... | |
| CVE-2026-58841 json | In multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due to a logic error in the c... | |
| CVE-2026-58835 json | In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to rem... | |
| CVE-2026-58834 json | In setPermissionGrantState of DevicePolicyManagerService.java, there is a possible persistent denial of service due to improp... | |
| CVE-2026-58815 json | In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local esc... | |
| CVE-2026-55286 json | In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could le... | |
| CVE-2026-55280 json | In multiple locations, there is a possible out-of-bounds write due to uninitialized data. This could lead to remote escalatio... | |
| CVE-2026-55270 json | In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to loc... | |
| CVE-2026-55269 json | In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety issue due to improper input validation. This co... | |
| CVE-2026-55266 json | In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write due to resource exhaustion. This could lead to ... | |
| CVE-2026-55265 json | In multiple functions of PduParser.java, there is a possible out of bounds read due to a missing bounds check. This could lea... | |
| CVE-2026-49937 json | In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This co... | |
| CVE-2026-49933 json | In handle_le_monitor_device_event of msft.cc, there is a possible control-flow hijack in the privileged bluetooth process due... | |
| CVE-2026-49885 json | In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to lo... | |
| CVE-2026-49878 json | In wpas_handle_robust_av_scs_recv_action of robust_av.c, there is a possible out-of-bounds write due to a logic error in the ... | |
| CVE-2026-12171 json | auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-cha... |