CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-85219 json | Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause uncons... | |
| CVE-2026-81469 json | Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A low pr... | |
| CVE-2026-79320 json | Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downstream... | |
| CVE-2026-79319 json | Stencil core 4.43.5 is vulnerable to Incorrect Access Control. | |
| CVE-2026-79318 json | web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/wri... | |
| CVE-2026-73552 json | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and ... | |
| CVE-2026-73550 json | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and ... | |
| CVE-2026-73549 json | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and ... | |
| CVE-2026-73548 json | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and ... | |
| CVE-2026-73547 json | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and ... | |
| CVE-2026-73546 json | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and ... | |
| CVE-2026-73513 json | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and ... | |
| CVE-2026-73512 json | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and ... | |
| CVE-2026-62247 json | Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authorization... | |
| CVE-2026-94496 json | jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify ... | |
| CVE-2026-94494 json | jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' re... | |
| CVE-2026-91165 json | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO retu... | |
| CVE-2026-91164 json | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authenticati... | |
| CVE-2026-58271 json | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POS... | |
| CVE-2026-58269 json | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POS... | |
| CVE-2026-55897 json | luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an... | |
| CVE-2026-55159 json | luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or un... | |
| CVE-2026-54915 json | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /auth/red... | |
| CVE-2026-52835 json | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the import_config handler and... | |
| CVE-2026-50572 json | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and ... | |
| CVE-2026-49995 json | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the newsletter cron field sto... | |
| CVE-2026-49811 json | Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vul... | |
| CVE-2026-48521 json | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and ... | |
| CVE-2026-45381 json | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint inserts ... | |
| CVE-2026-94210 json | A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file... | |
| CVE-2026-94185 json | nvm resolves a requested version or alias by treating it as a filename under $NVM_DIR/alias. Before 0.40.8, nvm_alias() conca... | |
| CVE-2026-94148 json | A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR... | |
| CVE-2026-94142 json | A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerabili... | |
| CVE-2026-94128 json | A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the ... | |
| CVE-2026-94100 json | A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the fil... | |
| CVE-2026-94095 json | A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functional... | |
| CVE-2026-94090 json | A security flaw has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug of t... | |
| CVE-2026-94048 json | A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the fil... | |
| CVE-2026-94043 json | A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/f... | |
| CVE-2026-90860 json | The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a pr... | |
| CVE-2026-84285 json | An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to e... | |
| CVE-2026-77021 json | Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) a... | |
| CVE-2026-61746 json | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and PluginS... | |
| CVE-2026-94038 json | A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of the fil... | |
| CVE-2026-87205 json | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported v... | |
| CVE-2026-87200 json | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported v... | |
| CVE-2026-87197 json | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported v... | |
| CVE-2026-87196 json | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported v... | |
| CVE-2026-87161 json | Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations). Supported vers... | |
| CVE-2026-87160 json | Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations). Supported vers... | |
| CVE-2026-87149 json | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Aw... | |
| CVE-2026-87146 json | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security)... | |
| CVE-2026-87135 json | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security)... | |
| CVE-2026-87134 json | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security)... | |
| CVE-2026-87133 json | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security)... | |
| CVE-2026-87132 json | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security)... | |
| CVE-2026-87131 json | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security)... | |
| CVE-2026-76781 json | A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer... | |
| CVE-2026-87127 json | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions that ... | |
| CVE-2026-87126 json | Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Reports Security). Supported versi... | |
| CVE-2026-87124 json | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported vers... | |
| CVE-2026-83490 json | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported vers... | |
| CVE-2026-83488 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-microprofile-security). Supported versi... | |
| CVE-2026-83485 json | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions tha... | |
| CVE-2026-83484 json | Vulnerability in the Oracle US Federal Human Resources product of Oracle E-Business Suite (component: Internal Operations). ... | |
| CVE-2026-83465 json | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). S... | |
| CVE-2026-83461 json | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). S... | |
| CVE-2026-83457 json | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Su... | |
| CVE-2026-83449 json | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported... | |
| CVE-2026-83443 json | Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versions t... | |
| CVE-2026-83437 json | Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Change Management). Supported version... | |
| CVE-2026-83436 json | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Recall Management). Supported versio... | |
| CVE-2026-83431 json | Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: WebUI). Supported versions that... | |
| CVE-2026-83346 json | Vulnerability in the Oracle Fusion Middleware Control product of Oracle Fusion Middleware (component: Framework). Supported ... | |
| CVE-2026-83345 json | Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are... | |
| CVE-2026-83343 json | Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System W... | |
| CVE-2026-83341 json | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). ... | |
| CVE-2026-83334 json | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Sup... | |
| CVE-2026-83332 json | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supporte... | |
| CVE-2026-83326 json | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions t... | |
| CVE-2026-83324 json | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Secu... | |
| CVE-2026-83321 json | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Action... | |
| CVE-2026-83309 json | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are af... | |
| CVE-2026-83274 json | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported ... | |
| CVE-2026-83270 json | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Secu... | |
| CVE-2026-83267 json | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Publisher Security). Supported versions ... | |
| CVE-2026-83266 json | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supported... | |
| CVE-2026-76703 json | A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways th... | |
| CVE-2026-76702 json | A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local atta... | |
| CVE-2026-76701 json | A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attac... | |
| CVE-2026-76684 json | Vulnerabilities have been identified in the API of HPE Networking EdgeConnect SD-WAN Orchestrator that could potentially allo... | |
| CVE-2026-76683 json | Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways that could allow an u... | |
| CVE-2026-76682 json | A vulnerability in the network security monitoring component of intrusion detection systems could allow an unauthenticated re... | |
| CVE-2026-76681 json | A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privilege... | |
| CVE-2026-76680 json | Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges... | |
| CVE-2026-76679 json | Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct den... | |
| CVE-2026-76678 json | A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow a low-privilege authenticated r... | |
| CVE-2026-76677 json | A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could allow a ... | |
| CVE-2026-76676 json | Buffer overflow vulnerabilities exist in the underlying operating system of EdgeConnect SD-WAN Gateways that could allow an u... | |
| CVE-2026-76675 json | A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitatio... |