CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-85402 json A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the f...
CVE-2026-85401 json A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality o...
CVE-2026-85399 json A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the f...
CVE-2026-85398 json A vulnerability was identified in code-projects Hospital Information System 1.0. Affected is the function viewReq of the file...
CVE-2026-85149 json SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote atta...
CVE-2026-85148 json SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote atta...
CVE-2026-85147 json SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote atta...
CVE-2026-85146 json SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote atta...
CVE-2026-84809 json Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__...
CVE-2026-84376 json Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from req...
CVE-2026-79755 json Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Doc...
CVE-2026-75754 json Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS C...
CVE-2026-55421 json Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 00b7c3c, the endpoint a...
CVE-2026-53649 json Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090...
CVE-2026-84804 json Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and customers v...
CVE-2026-84799 json Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors,...
CVE-2026-84794 json Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authe...
CVE-2026-84780 json Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.
CVE-2026-84764 json Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
CVE-2026-84698 json PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into...
CVE-2026-84484 json ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthentica...
CVE-2026-84483 json WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthen...
CVE-2026-84478 json WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attack...
CVE-2026-84441 json A security vulnerability has been detected in Piwigo up to 16.3.0. Affected by this issue is some unknown functionality of th...
CVE-2026-84427 json A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash...
CVE-2026-81775 json Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions.
CVE-2026-81769 json Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Boo...
CVE-2026-81286 json Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.
CVE-2026-78408 json The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later...
CVE-2026-14982 json The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i...
CVE-2026-3850 json The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_cont...
CVE-2026-84374 json Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the ...
CVE-2026-84370 json SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0...
CVE-2026-84365 json Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix rele...
CVE-2026-84310 json pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_...
CVE-2026-84306 json Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.6 and 5.7.6, pac...
CVE-2026-84287 json A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file g...
CVE-2026-84269 json A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to pro...
CVE-2026-84206 json Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing ...
CVE-2026-84201 json appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, all...
CVE-2026-84189 json LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxid...
CVE-2026-73524 json Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote attackers to exec...
CVE-2026-16493 json A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py ...
CVE-2026-11332 json A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's m...
CVE-2026-85397 json A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the function findBySearch of th...
CVE-2026-85383 json A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file...
CVE-2026-85382 json A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b389...
CVE-2026-45200 json Software installed and run as a non-privileged user may conduct improper GPU driver IOCTL calls to create an allocation scena...
CVE-2026-84233 json A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When ...
CVE-2026-84194 json LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an authenticated OS command injection vulnerability in li...
CVE-2026-84110 json A vulnerability was detected in Releasit Releasit COD Form & Upsells v1. This vulnerability affects unknown code of the compo...
CVE-2026-83618 json xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.10 until 0...
CVE-2026-83613 json xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xm...
CVE-2026-83608 json xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xm...
CVE-2026-45197 json Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/...
CVE-2025-5459 json A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands...
CVE-2023-54356 json Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_...
CVE-2026-85381 json A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c381...
CVE-2026-85380 json A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b3...
CVE-2026-85379 json A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61...
CVE-2026-15310 json When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled si...
CVE-2026-67402 json An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 H...
CVE-2026-67398 json Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from...
CVE-2026-67397 json Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as r...
CVE-2026-49509 json Out-of-bounds read vulnerability in Samsung Opensource Escargot allows Overread Buffers. This issue affects Escargot: 25648a...
CVE-2026-85456 json MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowing att...
CVE-2026-85455 json MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out...
CVE-2026-85454 json MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL te...
CVE-2026-85453 json MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to injec...
CVE-2026-85452 json MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and ...
CVE-2026-85451 json MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses ...
CVE-2026-85450 json MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded con...
CVE-2026-85449 json MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowin...
CVE-2026-85448 json MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed communities stored in parallel vectors within Sh...
CVE-2026-85447 json MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCAST_REQ subscriptions without validating duration or variable ...
CVE-2026-85446 json MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity c...
CVE-2026-85445 json MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the Demuxer::addMuxPacket() function that trusts the pa...
CVE-2026-85444 json MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that...
CVE-2026-85443 json MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thr...
CVE-2026-85442 json MOOS core-moos through 10.4.0 fails to validate packet length declarations in CMOOSCommPkt::OnBytesWritten(), allowing unauth...
CVE-2026-85441 json MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-negative in CMOOSMsg::operator>>. Unau...
CVE-2026-85440 json MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that a...
CVE-2026-85439 json MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() ...
CVE-2026-85438 json MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree ...
CVE-2026-85437 json MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker...
CVE-2026-85436 json MOOS essential-moos through 10.0.1 contains a buffer overflow vulnerability in CMOOSUDPLink::ReadPktFromArray() that allows r...
CVE-2026-85435 json MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing a...
CVE-2026-85434 json MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attack...
CVE-2026-85433 json MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfig...
CVE-2026-85432 json MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attacker...
CVE-2026-85431 json MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when...
CVE-2026-85430 json MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from ...
CVE-2026-85429 json MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from th...
CVE-2026-85428 json MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows ...
CVE-2026-85427 json MOOS essential-moos pAntler through 10.0.1 contains a remote code execution vulnerability that allows unauthenticated attacke...
CVE-2026-85426 json MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Atta...
CVE-2026-85425 json MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsa...
CVE-2026-85424 json MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with ful...
CVE-2026-85378 json A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b3...
CVE-2026-85241 json A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the fil...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report