CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-84442 json | A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android. This vulnerability affects the function get... | |
| CVE-2026-84441 json | A security vulnerability has been detected in Piwigo up to 16.3.0. Affected by this issue is some unknown functionality of th... | |
| CVE-2026-72693 json | `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged conte... | |
| CVE-2026-14982 json | The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i... | |
| CVE-2026-14957 json | In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. ... | |
| CVE-2026-84715 json | FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing a... | |
| CVE-2026-84485 json | APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unaut... | |
| CVE-2026-84484 json | ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthentica... | |
| CVE-2026-84438 json | A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/a... | |
| CVE-2026-84437 json | A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/contro... | |
| CVE-2026-84431 json | A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.u... | |
| CVE-2026-82968 json | A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social ident... | |
| CVE-2026-15816 json | A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emer... | |
| CVE-2025-26465 json | A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be perfo... | |
| CVE-2026-84702 json | facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside t... | |
| CVE-2026-84701 json | NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malic... | |
| CVE-2026-84700 json | PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g.... | |
| CVE-2026-84699 json | Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow... | |
| CVE-2026-84698 json | PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into... | |
| CVE-2026-84697 json | Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv... | |
| CVE-2026-84696 json | Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interfa... | |
| CVE-2026-84695 json | BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unv... | |
| CVE-2026-84694 json | Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed ... | |
| CVE-2026-84430 json | A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of t... | |
| CVE-2026-84427 json | A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash... | |
| CVE-2026-84425 json | A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/bro... | |
| CVE-2026-17084 json | The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint at... | |
| CVE-2026-15806 json | The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPas... | |
| CVE-2026-15310 json | When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled si... | |
| CVE-2026-84359 json | Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer p... | |
| CVE-2026-84358 json | Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromi... | |
| CVE-2026-84357 json | Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engi... | |
| CVE-2026-84356 json | UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via... | |
| CVE-2026-84355 json | Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised t... | |
| CVE-2026-84354 json | Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social eng... | |
| CVE-2026-84353 json | Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveragin... | |
| CVE-2026-84352 json | Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary ... | |
| CVE-2026-84351 json | Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised th... | |
| CVE-2026-84350 json | Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to... | |
| CVE-2026-84349 json | Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer ... | |
| CVE-2026-84348 json | Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensit... | |
| CVE-2026-84347 json | Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside t... | |
| CVE-2026-84335 json | Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the... | |
| CVE-2026-84334 json | Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execu... | |
| CVE-2026-84333 json | Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary c... | |
| CVE-2026-84332 json | Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system ac... | |
| CVE-2026-84331 json | Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the re... | |
| CVE-2026-84330 json | UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof a... | |
| CVE-2026-84329 json | Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had... | |
| CVE-2026-84328 json | Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the... | |
| CVE-2026-84327 json | Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveragin... | |
| CVE-2026-84326 json | Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code insi... | |
| CVE-2026-84325 json | Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social... | |
| CVE-2026-84324 json | Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside t... | |
| CVE-2026-84323 json | Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the... | |
| CVE-2026-81928 json | Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message... | |
| CVE-2026-78957 json | Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive inf... | |
| CVE-2026-79720 json | Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide cer... | |
| CVE-2026-76195 json | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command... | |
| CVE-2026-65091 json | NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A suc... | |
| CVE-2026-76193 json | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary... | |
| CVE-2026-72984 json | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attac... | |
| CVE-2026-70331 json | Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform ... | |
| CVE-2026-84483 json | WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthen... | |
| CVE-2026-84482 json | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain(... | |
| CVE-2026-84481 json | WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoi... | |
| CVE-2026-84480 json | WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use e... | |
| CVE-2026-84479 json | WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied Use... | |
| CVE-2026-84478 json | WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attack... | |
| CVE-2026-84477 json | AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming pe... | |
| CVE-2026-84476 json | WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to s... | |
| CVE-2026-84423 json | A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go o... | |
| CVE-2026-84208 json | AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.jso... | |
| CVE-2026-80205 json | NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.... | |
| CVE-2026-84642 json | The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escapin... | |
| CVE-2026-84641 json | A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents... | |
| CVE-2026-84640 json | A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in... | |
| CVE-2026-84639 json | Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixe... | |
| CVE-2026-84637 json | Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypas... | |
| CVE-2026-84375 json | js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js... | |
| CVE-2026-84374 json | Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the ... | |
| CVE-2026-84373 json | Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone... | |
| CVE-2026-84372 json | Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeli... | |
| CVE-2026-84289 json | A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of th... | |
| CVE-2026-84288 json | A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of ... | |
| CVE-2026-84145 json | Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed... | |
| CVE-2026-84144 json | Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corr... | |
| CVE-2026-84143 json | Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed... | |
| CVE-2026-84142 json | Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security... | |
| CVE-2026-84141 json | Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunder... | |
| CVE-2026-83549 json | Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability ... | |
| CVE-2026-83548 json | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate a... | |
| CVE-2026-76851 json | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execut... | |
| CVE-2026-75604 json | Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applicat... | |
| CVE-2026-19118 json | A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code ... | |
| CVE-2026-18730 json | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated... | |
| CVE-2023-54391 json | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control bef... | |
| CVE-2026-84140 json | Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunde... | |
| CVE-2026-84139 json | Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird ... | |
| CVE-2026-84138 json | Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. |