CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-61103 json | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supp... | |
| CVE-2026-60985 json | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). ... | |
| CVE-2026-60984 json | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). ... | |
| CVE-2026-60979 json | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported version... | |
| CVE-2026-60978 json | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported version... | |
| CVE-2026-60617 json | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supp... | |
| CVE-2026-46979 json | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Inter... | |
| CVE-2026-46851 json | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supp... | |
| CVE-2026-57232 json | Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end module p... | |
| CVE-2026-55824 json | Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credenti... | |
| CVE-2026-53505 json | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter ... | |
| CVE-2026-53504 json | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression per... | |
| CVE-2026-53503 json | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <colu... | |
| CVE-2026-53502 json | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segm... | |
| CVE-2026-53501 json | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed d... | |
| CVE-2026-67822 json | Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The functio... | |
| CVE-2026-56670 json | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint s... | |
| CVE-2026-54737 json | @phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5... | |
| CVE-2026-54725 json | vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1... | |
| CVE-2026-54706 json | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends us... | |
| CVE-2026-53500 json | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plai... | |
| CVE-2026-52856 json | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malfo... | |
| CVE-2026-34497 json | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Em... | |
| CVE-2026-34495 json | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Sys... | |
| CVE-2026-25552 json | Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-lim... | |
| CVE-2026-21662 json | Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious ... | |
| CVE-2026-18481 json | Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated rem... | |
| CVE-2026-18321 json | Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd | |
| CVE-2026-18141 json | A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated ... | |
| CVE-2026-17925 json | Inappropriate implementation in Cast in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass s... | |
| CVE-2026-17912 json | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to by... | |
| CVE-2026-17901 json | Insufficient validation of untrusted input in Sharing in Google Chrome on Android prior to 151.0.7922.72 allowed a remote att... | |
| CVE-2026-17883 json | Inappropriate implementation in Headless in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same ori... | |
| CVE-2026-17882 json | Policy bypass in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a mal... | |
| CVE-2026-17873 json | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to... | |
| CVE-2026-17869 json | Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds mem... | |
| CVE-2026-15978 json | SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoint... | |
| CVE-2025-69936 json | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1. | |
| CVE-2025-69935 json | CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fro... | |
| CVE-2025-69934 json | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. | |
| CVE-2025-69933 json | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. | |
| CVE-2025-69930 json | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. | |
| CVE-2025-65342 json | code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field. | |
| CVE-2025-65336 json | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php. | |
| CVE-2026-66731 json | facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that... | |
| CVE-2026-66730 json | facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthent... | |
| CVE-2026-66729 json | facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauth... | |
| CVE-2026-63359 json | The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker... | |
| CVE-2026-60987 json | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). ... | |
| CVE-2026-60986 json | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). ... | |
| CVE-2026-17865 json | Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compr... | |
| CVE-2026-17860 json | Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a local attac... | |
| CVE-2026-17856 json | Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had comp... | |
| CVE-2026-17855 json | Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer pr... | |
| CVE-2026-17854 json | Insufficient policy enforcement in WebMCP in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same or... | |
| CVE-2026-17853 json | Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromise... | |
| CVE-2026-17852 json | Inappropriate implementation in Media Router in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same... | |
| CVE-2026-17850 json | Inappropriate implementation in Permissions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same ... | |
| CVE-2026-17849 json | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to sp... | |
| CVE-2026-17848 json | Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox... | |
| CVE-2026-17847 json | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to pote... | |
| CVE-2026-17846 json | Inappropriate implementation in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had co... | |
| CVE-2026-6552 json | Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerabil... | |
| CVE-2021-35606 json | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Notification Framewor... | |
| CVE-2021-2421 json | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Inter... | |
| CVE-2020-2912 json | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Self-Service). The su... | |
| CVE-2017-3577 json | Vulnerability in the PeopleSoft Enterprise CS Campus Community component of Oracle PeopleSoft Products (subcomponent: Framewo... | |
| CVE-2026-60395 json | Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.... | |
| CVE-2026-60394 json | Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-21.21... | |
| CVE-2023-2208 json | A vulnerability, which was classified as critical, has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This ... | |
| CVE-2023-2207 json | A vulnerability classified as critical was found in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability aff... | |
| CVE-2023-2206 json | A vulnerability classified as critical has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an u... | |
| CVE-2023-2205 json | A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. It has been rated as critical. Affected by th... | |
| CVE-2023-2204 json | A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. It has been declared as critical. Affected by... | |
| CVE-2026-59232 json | Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the c... | |
| CVE-2026-59231 json | Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to caus... | |
| CVE-2026-58048 json | Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. | |
| CVE-2026-58047 json | HTTP Smuggling in cPanel allows potential leak of credentials. | |
| CVE-2026-56571 json | HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, sys... | |
| CVE-2026-56570 json | HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid u... | |
| CVE-2026-56569 json | HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configurati... | |
| CVE-2026-56568 json | HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves... | |
| CVE-2026-56567 json | HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal co... | |
| CVE-2026-55100 json | hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates un... | |
| CVE-2026-54729 json | DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_s... | |
| CVE-2026-34490 json | Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker o... | |
| CVE-2026-17566 json | pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a ... | |
| CVE-2026-52680 json | Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uplo... | |
| CVE-2026-44617 json | LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing... | |
| CVE-2026-44616 json | LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping u... | |
| CVE-2026-44613 json | Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state... | |
| CVE-2026-35847 json | An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils... | |
| CVE-2026-28814 json | Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensit... | |
| CVE-2026-18446 json | fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference ... | |
| CVE-2026-17351 json | The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query t... | |
| CVE-2026-17350 json | The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its ... | |
| CVE-2026-17349 json | /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an ex... | |
| CVE-2026-17348 json | In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_r... | |
| CVE-2026-17347 json | The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that retur... | |
| CVE-2026-17346 json | The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex t... |