CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-90467 json aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP pa...
CVE-2026-89268 json QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them ...
CVE-2026-89267 json starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty li...
CVE-2026-87910 json When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. I...
CVE-2026-89266 json stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size i...
CVE-2026-87875 json The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source...
CVE-2026-86169 json Axolotl before 0.19.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defa...
CVE-2026-90461 json OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configure...
CVE-2026-90460 json An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 creden...
CVE-2026-90457 json The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authent...
CVE-2026-90456 json An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known adm...
CVE-2026-90455 json A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, r...
CVE-2026-90454 json A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of wri...
CVE-2026-90453 json A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer h...
CVE-2026-90452 json Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange ...
CVE-2026-90451 json An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies...
CVE-2026-90450 json The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its t...
CVE-2026-90449 json When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administra...
CVE-2026-90448 json A deployment mode intended to expose only read access to stored data proxies a set of application programming interface route...
CVE-2026-90447 json A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of ...
CVE-2026-90446 json An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a b...
CVE-2026-90445 json An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating...
CVE-2026-90444 json A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell met...
CVE-2026-90443 json A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encodi...
CVE-2026-54258 json ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39...
CVE-2026-54248 json Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swar...
CVE-2026-54241 json libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to c...
CVE-2026-54240 json libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to c...
CVE-2026-50018 json Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` w...
CVE-2026-50013 json Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff(...
CVE-2026-49992 json Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery ...
CVE-2026-88924 json A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created priva...
CVE-2026-82001 json Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-ser...
CVE-2026-81982 json Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attac...
CVE-2026-81977 json Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensit...
CVE-2026-75740 json Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privi...
CVE-2026-75735 json Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privi...
CVE-2026-75729 json Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privi...
CVE-2026-49846 json libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request...
CVE-2026-48496 json OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Sta...
CVE-2026-45056 json matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients....
CVE-2026-44715 json OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated us...
CVE-2026-75722 json Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this ...
CVE-2026-75716 json Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this ...
CVE-2026-75706 json Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this ...
CVE-2026-75683 json Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this ...
CVE-2026-75677 json Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this ...
CVE-2026-75661 json Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this ...
CVE-2026-75642 json Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privi...
CVE-2026-75635 json Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this ...
CVE-2026-19713 json Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this ...
CVE-2025-64618 json Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privi...
CVE-2026-80057 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Us...
CVE-2026-80056 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an In...
CVE-2026-79645 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Mis...
CVE-2026-79644 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im...
CVE-2026-9216 json An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker hav...
CVE-2026-9215 json A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social e...
CVE-2026-80238 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Ex...
CVE-2026-80178 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im...
CVE-2026-80170 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Us...
CVE-2026-80135 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im...
CVE-2026-80134 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Us...
CVE-2026-78488 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im...
CVE-2026-78480 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Mis...
CVE-2026-80133 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Rel...
CVE-2026-80132 json ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Miss...
CVE-2026-61410 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Mis...
CVE-2026-81918 json Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A user wi...
CVE-2026-81917 json Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the Docum...
CVE-2026-81907 json Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST...
CVE-2026-68535 json Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate(...
CVE-2026-54174 json melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange...
CVE-2026-54166 json Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the `asset:import` permis...
CVE-2026-62140 json Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions.
CVE-2026-54165 json Dobase is an open-source, self-hosted workspace with installable tools. Versions prior to 2026.06.03 have a one-click stored ...
CVE-2026-50025 json Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mousehole...
CVE-2026-49865 json Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerabili...
CVE-2026-49464 json NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, ...
CVE-2026-49439 json OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint all...
CVE-2026-48490 json ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in versi...
CVE-2026-47773 json ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models. Versions prior to 2.0.2 contain a missing bou...
CVE-2026-45057 json matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk...
CVE-2026-62139 json Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.
CVE-2026-62138 json Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions.
CVE-2026-62137 json Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions.
CVE-2026-62136 json Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 version...
CVE-2026-62135 json Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions.
CVE-2026-62134 json Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions.
CVE-2026-62133 json Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions.
CVE-2026-62132 json Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.
CVE-2026-62114 json Unauthenticated Broken Access Control in Passster <= 4.3.13 versions.
CVE-2026-62113 json Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions.
CVE-2026-62112 json Editor SQL Injection in Amelia <= 2.4.9 versions.
CVE-2026-62111 json Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions.
CVE-2026-62110 json Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions.
CVE-2026-62109 json Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.
CVE-2026-62107 json Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.
CVE-2026-62106 json Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.
CVE-2026-62105 json Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report