CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-82722 json Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_admin lets any client that can reach th...
CVE-2026-82681 json Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a record's strin...
CVE-2026-82673 json Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in ash-project ash_admin allows wr...
CVE-2026-82608 json A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/im...
CVE-2026-82607 json A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the functio...
CVE-2026-82605 json A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component...
CVE-2026-81853 json Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_admin turns a record-lookup URL into an equ...
CVE-2026-81852 json Use of Insufficiently Random Values vulnerability in ash-project ash_admin ships a hardcoded, publicly known CSP nonce, defea...
CVE-2026-77850 json Stored Cross-site Scripting vulnerability in ash-project ash_admin executes attacker-supplied record content as script in an ...
CVE-2026-75757 json Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who con...
CVE-2026-16313 json A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data ...
CVE-2026-14476 json A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. ...
CVE-2026-14474 json A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searc...
CVE-2026-4408 json A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controll...
CVE-2026-2340 json A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by ...
CVE-2026-1933 json A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing...
CVE-2026-48864 json A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data...
CVE-2026-42013 json A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validat...
CVE-2026-42011 json A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previo...
CVE-2026-42010 json A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched...
CVE-2026-33846 json A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in me...
CVE-2026-5260 json A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange t...
CVE-2026-3012 json A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled,...
CVE-2026-33845 json A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an intege...
CVE-2025-5222 json A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag'...
CVE-2026-82604 json A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module...
CVE-2026-82603 json A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=...
CVE-2026-82602 json A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php...
CVE-2026-82601 json A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulat...
CVE-2026-82600 json A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /z...
CVE-2026-82580 json Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error tex...
CVE-2026-82579 json Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence...
CVE-2026-82564 json Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configure...
CVE-2026-75760 json Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request s...
CVE-2026-82599 json A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /membe...
CVE-2026-82598 json A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component...
CVE-2026-82597 json A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file /cgi-...
CVE-2026-81315 json Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebind...
CVE-2026-77956 json Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated ...
CVE-2026-76131 json Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate a legitimate VOCALOID6 E...
CVE-2025-10939 json A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation...
CVE-2025-8419 json A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection...
CVE-2025-7365 json A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during ...
CVE-2025-0604 json A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing a...
CVE-2024-11736 json A vulnerability was found in Keycloak. Admin users may have to access sensitive server environment variables and system prope...
CVE-2024-11734 json A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change real...
CVE-2024-10451 json A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during t...
CVE-2024-10270 json A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it co...
CVE-2024-9666 json A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due t...
CVE-2026-82596 json A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDetecte...
CVE-2026-82595 json A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /bo...
CVE-2026-82594 json A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the compone...
CVE-2026-82593 json A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFi...
CVE-2026-82592 json A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskForma...
CVE-2026-82591 json A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the funct...
CVE-2026-82590 json A weakness has been identified in Open5GS up to 2.7.7. The affected element is the function smf_nudm_sdm_handle_get of the fi...
CVE-2026-82589 json A security flaw has been discovered in Open5GS up to 2.7.7. Impacted is the function amf_namf_comm_handle_n1_n2_message_trans...
CVE-2026-82588 json A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/namf-ha...
CVE-2026-56718 json AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service ...
CVE-2026-64194 json Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainNam...
CVE-2026-64844 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-64843 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-64842 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-64841 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-64840 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-64839 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-56716 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-82587 json A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function amf_namf_comm_decode_ue_mm_con...
CVE-2026-82367 json Exposure of Data Element to Wrong Session vulnerability in ash-project ash_graphql can deliver one subscription's resolved re...
CVE-2026-81643 json Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a subscri...
CVE-2026-81636 json Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated clien...
CVE-2026-81633 json Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a relay node(id:...
CVE-2026-80223 json Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive ...
CVE-2026-78693 json Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_graphql allows a remote client ...
CVE-2026-56715 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-56713 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-82556 json A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migratio...
CVE-2026-82555 json A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of...
CVE-2026-82554 json A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_custom...
CVE-2026-81322 json Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access t...
CVE-2026-81319 json Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an...
CVE-2026-82553 json A vulnerability was detected in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected ...
CVE-2026-82552 json A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown func...
CVE-2026-82551 json A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers...
CVE-2026-82550 json A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetu...
CVE-2026-82549 json A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityMod...
CVE-2026-78699 json Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that c...
CVE-2026-82658 json Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticate...
CVE-2026-82657 json Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modul...
CVE-2026-82656 json Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users wit...
CVE-2026-82655 json Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that...
CVE-2026-82654 json SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering ...
CVE-2026-82653 json SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names an...
CVE-2026-82652 json SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view ba...
CVE-2026-82651 json SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path an...
CVE-2026-82650 json SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/t...
CVE-2026-82649 json SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vuln...
CVE-2026-82648 json WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to no...
CVE-2026-82647 json WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrator...
CVE-2026-82646 json WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that ...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report