CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-18556 json Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. Thi...
CVE-2026-9198 json IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to...
CVE-2026-70474 json Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise h...
CVE-2026-70473 json Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise G...
CVE-2026-70472 json Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assis...
CVE-2026-70471 json Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise i...
CVE-2026-69704 json Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitize...
CVE-2026-69703 json Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that al...
CVE-2026-69702 json SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attack...
CVE-2026-69264 json Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python s...
CVE-2026-68743 json A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length fiel...
CVE-2026-66300 json SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An at...
CVE-2026-49435 json Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker...
CVE-2026-47781 json PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local...
CVE-2026-47764 json pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable t...
CVE-2026-47623 json NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successfu...
CVE-2026-47622 json NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain ...
CVE-2026-47621 json NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton...
CVE-2026-47620 json NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton...
CVE-2026-13229 json Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint...
CVE-2026-0163 json In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote e...
CVE-2017-20242 json Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can sen...
CVE-2017-20241 json Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send...
CVE-2026-69259 json Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Ma...
CVE-2026-69254 json Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCod...
CVE-2026-47619 json NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A succes...
CVE-2026-47618 json NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-si...
CVE-2026-47617 json NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side requ...
CVE-2026-47616 json NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side requ...
CVE-2026-47615 json NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a craft...
CVE-2026-47614 json NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploi...
CVE-2026-47613 json NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricte...
CVE-2026-47612 json NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitati...
CVE-2026-47487 json NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository...
CVE-2026-24255 json NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash coll...
CVE-2026-24254 json NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-...
CVE-2026-24253 json NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit o...
CVE-2026-18830 json Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configu...
CVE-2026-68494 json The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass i...
CVE-2026-48818 json Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSR...
CVE-2026-18801 json OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution value...
CVE-2026-18401 json The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in Stream...
CVE-2026-18141 json A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated ...
CVE-2026-16060 json The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of...
CVE-2026-14818 json A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions f...
CVE-2026-14337 json Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user int...
CVE-2026-12586 json The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset acti...
CVE-2026-12383 json A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (pe...
CVE-2026-11368 json The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel vi...
CVE-2026-10032 json The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI sc...
CVE-2026-8508 json An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.1...
CVE-2026-6837 json A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions thro...
CVE-2026-34486 json Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of...
CVE-2026-11332 json A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's m...
CVE-2026-47763 json pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes s...
CVE-2026-69263 json Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for C...
CVE-2026-64634 json A vulnerability allowing local privilege escalation to the Reporter service context.
CVE-2026-64633 json A vulnerability allowing remote unauthenticated code execution on the agent host.
CVE-2026-64631 json A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
CVE-2026-64630 json A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.
CVE-2026-18790 json A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMonitor...
CVE-2026-18788 json A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function...
CVE-2026-70373 json Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatena...
CVE-2026-70372 json Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request paramet...
CVE-2026-63456 json Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remot...
CVE-2026-63455 json Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remot...
CVE-2026-58075 json A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged to...
CVE-2026-58074 json A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
CVE-2026-58073 json A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobta...
CVE-2026-58072 json A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to r...
CVE-2026-58071 json A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API as...
CVE-2026-58067 json A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adeni...
CVE-2026-56848 json A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_re...
CVE-2026-18787 json A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /u...
CVE-2026-18785 json A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_g...
CVE-2026-15920 json An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` re...
CVE-2026-15830 json An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` ...
CVE-2026-15337 json An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is ...
CVE-2026-15314 json Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP re...
CVE-2026-15307 json An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the ...
CVE-2026-70371 json Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request param...
CVE-2026-70370 json Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column re...
CVE-2026-70369 json Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controll...
CVE-2026-18809 json Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3.
CVE-2026-16623 json The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a genera...
CVE-2026-16618 json The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content typ...
CVE-2026-16068 json The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not ...
CVE-2026-16056 json The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, al...
CVE-2026-16035 json The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send,...
CVE-2026-15958 json The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-...
CVE-2026-15233 json The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attribu...
CVE-2026-14939 json The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it...
CVE-2026-14872 json The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape...
CVE-2026-69198 json ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every s...
CVE-2026-67599 json ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to...
CVE-2026-62870 json Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
CVE-2026-49132 json OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arb...
CVE-2026-48113 json Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can...
CVE-2026-18645 json A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /system/a...
CVE-2026-18616 json A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the ...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report