CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-62913 json Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-62893 json Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
CVE-2026-66272 json Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerab...
CVE-2026-66271 json Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vuln...
CVE-2026-66270 json Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vuln...
CVE-2026-63702 json Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low pr...
CVE-2026-63701 json Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerabi...
CVE-2026-63700 json Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low pr...
CVE-2026-57472 json Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vuln...
CVE-2026-57471 json Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vuln...
CVE-2026-57469 json Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration bac...
CVE-2026-53970 json ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that ...
CVE-2026-19884 json In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring th...
CVE-2026-19837 json A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/searc...
CVE-2026-19836 json A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of th...
CVE-2026-73673 json Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated ...
CVE-2026-72822 json The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the di...
CVE-2026-19835 json A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of t...
CVE-2026-19834 json A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/lo...
CVE-2026-19830 json A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the fil...
CVE-2026-19829 json A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4-20260107. This vulnerability affects unknown code of t...
CVE-2026-19824 json A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindL...
CVE-2026-16772 json In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the a...
CVE-2026-13198 json Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Co...
CVE-2026-13197 json Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Co...
CVE-2026-13196 json Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of...
CVE-2026-13002 json A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any D...
CVE-2026-73420 json NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defa...
CVE-2026-73304 json Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id retur...
CVE-2026-72816 json go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() ...
CVE-2026-72811 json SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.g...
CVE-2026-56865 json A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the G...
CVE-2026-19814 json A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bi...
CVE-2026-19791 json A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /g...
CVE-2026-19789 json A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_i...
CVE-2026-19762 json A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file FileChu...
CVE-2026-19757 json A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAnyoneC...
CVE-2026-19753 json A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the fi...
CVE-2026-18039 json The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from ove...
CVE-2026-16739 json The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request origi...
CVE-2026-15205 json The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using...
CVE-2026-14290 json The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it...
CVE-2026-12949 json The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity...
CVE-2026-73555 json vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/...
CVE-2026-73506 json Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in ...
CVE-2026-70464 json rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to e...
CVE-2026-70460 json rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by...
CVE-2026-56862 json Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been c...
CVE-2026-56859 json Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
CVE-2026-56858 json Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary c...
CVE-2026-56853 json When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they conta...
CVE-2026-33818 json Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
CVE-2026-19752 json A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. This affects the...
CVE-2026-19747 json A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260...
CVE-2026-19483 json IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage S...
CVE-2026-18715 json IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper proc...
CVE-2026-18509 json IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i ...
CVE-2026-18249 json IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validati...
CVE-2026-70456 json rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious s...
CVE-2026-70452 json rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts den...
CVE-2026-62814 json Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an...
CVE-2026-62803 json Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevat...
CVE-2026-62745 json Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an...
CVE-2026-53801 json rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows atta...
CVE-2026-53800 json rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows attacker...
CVE-2026-53796 json rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver'...
CVE-2026-53793 json rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-...
CVE-2026-53792 json rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malic...
CVE-2026-53788 json rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows lo...
CVE-2026-53783 json rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted sh...
CVE-2026-49820 json Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `s...
CVE-2026-28154 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean,...
CVE-2026-19345 json A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateT...
CVE-2026-19330 json A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_system...
CVE-2026-58046 json Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection a...
CVE-2026-46600 json Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
CVE-2026-44962 json Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied inpu...
CVE-2026-19325 json A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983...
CVE-2026-19285 json A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnera...
CVE-2026-19270 json A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_journey...
CVE-2026-19246 json A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the file n...
CVE-2026-62742 json Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an...
CVE-2026-62720 json Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an...
CVE-2026-62718 json Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an...
CVE-2026-62716 json Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an...
CVE-2026-62715 json Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an...
CVE-2026-62714 json Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an...
CVE-2026-70315 json Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70314 json Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-62908 json Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows a...
CVE-2026-71390 json CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature byp...
CVE-2026-71389 json CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an applic...
CVE-2026-70329 json Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-65661 json Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-65657 json Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64911 json Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63518 json Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-63513 json Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-62882 json Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a n...
CVE-2026-48446 json CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vuln...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report