CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-69292 json | Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-69277 json | Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate pr... | |
| CVE-2026-69276 json | Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute ... | |
| CVE-2026-69275 json | Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-95371 json | Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromise... | |
| CVE-2026-95311 json | Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineer... | |
| CVE-2026-95310 json | Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outsid... | |
| CVE-2026-19588 json | Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. | |
| CVE-2026-19587 json | Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation. | |
| CVE-2026-103548 json | Improperly stored passwords in the config file in Itron MV-90 xi 3.0 allows attackers to decode the passwords and password hi... | |
| CVE-2026-103547 json | In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only... | |
| CVE-2026-103387 json | A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the file src/schemes/m... | |
| CVE-2026-102994 json | pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifier... | |
| CVE-2026-102993 json | pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman pag... | |
| CVE-2026-102992 json | piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in ... | |
| CVE-2026-102991 json | Mako is a template library written in Python. Prior to 1.4.2, on Windows, TemplateLookup.get_template() in mako/lookup.py res... | |
| CVE-2026-102990 json | basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server ... | |
| CVE-2026-101885 json | ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation ... | |
| CVE-2026-101884 json | OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block... | |
| CVE-2026-101883 json | OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability ... | |
| CVE-2026-101882 json | OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accept... | |
| CVE-2026-101881 json | OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSock... | |
| CVE-2026-101880 json | OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval polic... | |
| CVE-2026-101879 json | OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that a... | |
| CVE-2026-103475 json | yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in it... | |
| CVE-2026-103471 json | restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated at... | |
| CVE-2026-103399 json | A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request bod... | |
| CVE-2026-62308 json | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an auth... | |
| CVE-2026-55181 json | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authent... | |
| CVE-2026-55177 json | CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to version 13.... | |
| CVE-2026-55107 json | Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby ... | |
| CVE-2026-55094 json | Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to ve... | |
| CVE-2026-103432 json | apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi,... | |
| CVE-2026-103395 json | LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserial... | |
| CVE-2026-103233 json | A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f914... | |
| CVE-2026-103230 json | A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c.... | |
| CVE-2026-102984 json | Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a request URL from th... | |
| CVE-2026-102717 json | MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash | |
| CVE-2026-55174 json | UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shim... | |
| CVE-2026-103111 json | PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bound... | |
| CVE-2026-103106 json | Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infi... | |
| CVE-2026-103101 json | Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicio... | |
| CVE-2026-94029 json | Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP ... | |
| CVE-2026-92870 json | A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnorma... | |
| CVE-2026-92869 json | An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process... | |
| CVE-2026-92868 json | An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass c... | |
| CVE-2026-92121 json | In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside sign... | |
| CVE-2026-89238 json | WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading... | |
| CVE-2026-88920 json | An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authe... | |
| CVE-2026-87830 json | In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into pa... | |
| CVE-2026-85532 json | Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptogr... | |
| CVE-2026-62146 json | A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own r... | |
| CVE-2026-103087 json | Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remot... | |
| CVE-2026-103043 json | anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to... | |
| CVE-2026-102938 json | virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt valu... | |
| CVE-2026-102925 json | virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zs... | |
| CVE-2026-102877 json | Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL valida... | |
| CVE-2026-102829 json | simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations ... | |
| CVE-2026-102825 json | Russh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTH_REQUEST path reached from server::run_stream in ... | |
| CVE-2026-102621 json | A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the f... | |
| CVE-2026-102253 json | iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to cras... | |
| CVE-2026-74225 json | U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and C... | |
| CVE-2026-71974 json | U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate im... | |
| CVE-2026-67993 json | basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the ... | |
| CVE-2026-61519 json | Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team inv... | |
| CVE-2026-102821 json | Russh is a Rust SSH client and server library. Prior to 0.63.2, an authenticated remote peer can send SSH_MSG_KEXINIT without... | |
| CVE-2026-95376 json | Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging s... | |
| CVE-2026-95375 json | Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised t... | |
| CVE-2026-95366 json | Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the re... | |
| CVE-2026-95362 json | Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social en... | |
| CVE-2026-95330 json | Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system acc... | |
| CVE-2026-95309 json | UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elemen... | |
| CVE-2026-95308 json | Integer overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the rendere... | |
| CVE-2026-95307 json | UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social en... | |
| CVE-2026-95306 json | Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the s... | |
| CVE-2026-102728 json | Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that t... | |
| CVE-2026-102558 json | A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming... | |
| CVE-2026-100758 json | Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderb... | |
| CVE-2026-100756 json | Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox ESR 153.4, Thun... | |
| CVE-2026-95301 json | Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the... | |
| CVE-2026-95297 json | Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web ori... | |
| CVE-2026-95281 json | Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary... | |
| CVE-2026-91096 json | In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in... | |
| CVE-2026-91095 json | In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWeb... | |
| CVE-2026-90979 json | LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and role lookup by textually substituting the pl... | |
| CVE-2026-90783 json | MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to intege... | |
| CVE-2026-88816 json | DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName. fetchrow_hashref uses th... | |
| CVE-2026-88815 json | DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv. When casting to SQL_NU... | |
| CVE-2026-85644 json | XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS::Par... | |
| CVE-2026-79683 json | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could po... | |
| CVE-2026-76111 json | Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potent... | |
| CVE-2026-58575 json | Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially expl... | |
| CVE-2026-12425 json | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Empl... | |
| CVE-2025-6170 json | A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an... | |
| CVE-2026-87004 json | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow... | |
| CVE-2026-55224 json | MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operation platforms, pe... | |
| CVE-2026-53605 json | Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireles... | |
| CVE-2026-102820 json | pageant provides a [PageantStream] type that implements [AsyncRead] and [AsyncWrite] traits and can be used to talk to a runn... | |
| CVE-2026-102490 json | All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root. | |
| CVE-2026-102489 json | Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zamma... |