CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-64619 json | FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attack... | |
| CVE-2026-64194 json | Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainNam... | |
| CVE-2026-64193 json | Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDE... | |
| CVE-2026-63771 json | Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injec... | |
| CVE-2026-63770 json | Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthenticated ... | |
| CVE-2026-63769 json | Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that... | |
| CVE-2026-63768 json | cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attacke... | |
| CVE-2026-63731 json | HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct t... | |
| CVE-2026-63730 json | HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct t... | |
| CVE-2026-63108 json | Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers ... | |
| CVE-2026-63107 json | LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template end... | |
| CVE-2026-62414 json | The Joomla extension Page Builder CK does not properly apply access control to frontend page list views. | |
| CVE-2026-61901 json | The Joomla extension Hikashop is vulnerable to an open redirect. | |
| CVE-2026-61900 json | The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE. | |
| CVE-2026-64612 json | A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installin... | |
| CVE-2026-61425 json | The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access. | |
| CVE-2026-61424 json | The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE. | |
| CVE-2026-60034 json | The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, lead... | |
| CVE-2026-60033 json | The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target internal/reserved addres... | |
| CVE-2026-60032 json | The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/write... | |
| CVE-2026-60031 json | The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handl... | |
| CVE-2026-60030 json | The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload medi... | |
| CVE-2026-60029 json | The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder ... | |
| CVE-2026-60028 json | The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder ... | |
| CVE-2026-60027 json | The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticat... | |
| CVE-2026-60026 json | The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (... | |
| CVE-2026-55639 json | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Securit... | |
| CVE-2026-55626 json | xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the ... | |
| CVE-2026-48812 json | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's atta... | |
| CVE-2026-48389 json | DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbi... | |
| CVE-2026-12341 json | This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected... | |
| CVE-2026-8170 json | The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths an... | |
| CVE-2026-8169 json | ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challeng... | |
| CVE-2026-58484 json | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` read... | |
| CVE-2026-58414 json | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursive... | |
| CVE-2026-55238 json | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm... | |
| CVE-2026-54538 json | xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to properl... | |
| CVE-2026-50743 json | A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campa... | |
| CVE-2026-47275 json | In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `nni_mqttv5_msg_decode_connect()` allows a malicious MQ... | |
| CVE-2026-46715 json | Flask-Security-Too allows users to add security features to their Flask applicationa. Version 5.8.0's OAuth reauthentication ... | |
| CVE-2026-46701 json | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an empty ... | |
| CVE-2026-44227 json | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a r... | |
| CVE-2026-44178 json | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the vi... | |
| CVE-2026-41521 json | xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen... | |
| CVE-2026-41252 json | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-base... | |
| CVE-2026-39878 json | Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form th... | |
| CVE-2026-39385 json | Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validatio... | |
| CVE-2026-35590 json | libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and includi... | |
| CVE-2026-35217 json | NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the final 1... | |
| CVE-2026-34239 json | Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php ... | |
| CVE-2026-33327 json | libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8... | |
| CVE-2026-32825 json | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycl... | |
| CVE-2026-26483 json | Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management fun... | |
| CVE-2026-63071 json | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for ... | |
| CVE-2026-62418 json | Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources... | |
| CVE-2026-62183 json | Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or... | |
| CVE-2026-57308 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An adm... | |
| CVE-2026-53421 json | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements ca... | |
| CVE-2026-53405 json | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can ... | |
| CVE-2026-51027 json | An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component. | |
| CVE-2026-51026 json | Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a craft... | |
| CVE-2026-48824 json | Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-4... | |
| CVE-2026-46516 json | Frogman provides headless FreePBX control. Prior to version 1.6.6, Frogman's chat-console markdown formatter (`assets/js/chat... | |
| CVE-2026-45797 json | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated file u... | |
| CVE-2026-45709 json | Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Reques... | |
| CVE-2026-44359 json | Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's ma... | |
| CVE-2026-35198 json | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the... | |
| CVE-2026-32823 json | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycl... | |
| CVE-2026-32819 json | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycl... | |
| CVE-2026-32806 json | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycl... | |
| CVE-2026-26199 json | HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is i... | |
| CVE-2026-26081 json | HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ... | |
| CVE-2026-26080 json | HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy En... | |
| CVE-2026-16244 json | A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is ... | |
| CVE-2026-16235 json | Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in ra... | |
| CVE-2026-16224 json | A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jx... | |
| CVE-2026-16217 json | A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown fun... | |
| CVE-2026-16211 json | A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impacts the function AssetLast... | |
| CVE-2026-16205 json | A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decode of ... | |
| CVE-2026-12080 json | A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-au... | |
| CVE-2026-6793 json | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consu... | |
| CVE-2026-6656 json | Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-i... | |
| CVE-2026-55254 json | NCalc is a fast, lightweight expression evaluator for .NET. Prior to 6.1.1, the factorial operator implementation in src/NCal... | |
| CVE-2026-54466 json | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of th... | |
| CVE-2026-54244 json | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endpoint ... | |
| CVE-2026-52203 json | An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter. | |
| CVE-2026-52199 json | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd ... | |
| CVE-2026-51833 json | Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enume... | |
| CVE-2026-50162 json | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a lexical... | |
| CVE-2026-49977 json | tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on any ... | |
| CVE-2026-48022 json | @hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and ... | |
| CVE-2026-46420 json | setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.25.0 p... | |
| CVE-2026-42168 json | django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model... | |
| CVE-2026-36669 json | An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attac... | |
| CVE-2026-16199 json | A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file ... | |
| CVE-2026-16197 json | A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessage... | |
| CVE-2026-16133 json | A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spawn of ... | |
| CVE-2026-16126 json | A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of the ... | |
| CVE-2026-16120 json | A vulnerability was determined in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This impacts the function matchesAllowlist/ext... | |
| CVE-2026-16085 json | A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function NewContextBuilder of the ... |