CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-107396 json | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3... | |
| CVE-2026-107395 json | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3... | |
| CVE-2026-84275 json | IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated at... | |
| CVE-2026-84274 json | IBM Guardium Data Protection 12.2.2 is affected by a sensitive information exposure vulnerability. During SECRET and API_KEY ... | |
| CVE-2026-84272 json | IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-controller component. An un... | |
| CVE-2026-84271 json | IBM Guardium Data Protection 12.2 is vulnerable to a signature verification bypass in the patch installer. An attacker with l... | |
| CVE-2026-84250 json | IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkc... | |
| CVE-2026-84245 json | IBM Guardium Data Protection 12.2 is vulnerable to a local privilege escalation in the cp_wrapper component. A low-privileged... | |
| CVE-2026-84244 json | IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in... | |
| CVE-2026-82344 json | IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reas... | |
| CVE-2026-82335 json | IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based buffer overflow in the MongoDB protocol parser. A... | |
| CVE-2026-82334 json | IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based out-of-bounds read in the TDS7 LOGIN7 protocol p... | |
| CVE-2026-107394 json | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3... | |
| CVE-2026-107392 json | music-metadata is a metadata parser for audio and video media files. Prior to 11.15.0, the DSF parser handles an unrecognized... | |
| CVE-2026-107391 json | music-metadata is a metadata parser for audio and video media files. In the public development revision introduced after 11.1... | |
| CVE-2026-107390 json | music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the MP4 parser accepts an attacker-con... | |
| CVE-2026-107389 json | music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the Matroska and WebM EBML parser deco... | |
| CVE-2026-107388 json | music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the ID3v2 parser trusts the syncsafe t... | |
| CVE-2026-107387 json | music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the APEv2 parser reads an attacker-con... | |
| CVE-2026-107325 json | Improper validation of a BSON array length in the MongoDB Go Driver can cause an out-of-bounds index and runtime panic when a... | |
| CVE-2026-106436 json | The BSON encoder in the MongoDB PHP Driver does not check some return values after a document exceeds libbson's size limit. T... | |
| CVE-2026-106432 json | The BSON encoder in the MongoDB PHP Driver converts a string length to a 32-bit value without validation. When an affected ap... | |
| CVE-2026-84290 json | IBM Guardium Data Protection 12.0, 12.1, 12.2 is affected by an improper validation of user-supplied pointers in the WfpMonit... | |
| CVE-2026-84278 json | IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the SUID-root ssh_config_wrapper compon... | |
| CVE-2026-84276 json | IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticat... | |
| CVE-2026-107324 json | An integer overflow in BSON value-length handling in the MongoDB Go Driver can cause a runtime panic when an application vali... | |
| CVE-2026-106438 json | An incorrect calculation in Decimal128 string parsing in the MongoDB C Driver can accept certain over-precision inputs contai... | |
| CVE-2026-106437 json | The BSON buffer-reservation API in the MongoDB C Driver can record a length smaller than the five-byte BSON minimum. Later ap... | |
| CVE-2026-106434 json | The explicit decryption component of MongoDB libmongocrypt can return an unrecognized encrypted payload unchanged instead of ... | |
| CVE-2026-106433 json | Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type whe... | |
| CVE-2026-106431 json | An off-by-one error in the BSON bulk document writer in the MongoDB C Driver can write one zero byte immediately past a heap ... | |
| CVE-2026-106430 json | The MongoDB C++ Driver discards content after an embedded NUL byte in certain field and collection names accepted by the coll... | |
| CVE-2026-106429 json | An integer underflow in the KMS endpoint-parsing logic of MongoDB libmongocrypt can cause an allocation failure that terminat... | |
| CVE-2026-107302 json | msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length o... | |
| CVE-2026-107301 json | msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or p... | |
| CVE-2026-107300 json | msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invoke... | |
| CVE-2026-106428 json | An out-of-bounds read in SCRAM authentication response parsing in the MongoDB C Driver can read one byte beyond a fixed-size ... | |
| CVE-2026-105570 json | Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential re... | |
| CVE-2026-105452 json | Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The pro... | |
| CVE-2026-101998 json | Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned d... | |
| CVE-2026-50055 json | A policy-enforcement flaw in Zimbra Collaboration Suite allows an authenticated user to bypass disabled mail forwarding by us... | |
| CVE-2026-50054 json | An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated... | |
| CVE-2026-10631 json | An authorization bypass in the EWS FindItem handler of Zimbra Collaboration Suite 10.1.0 through 10.1.19 allows an authentica... | |
| CVE-2026-107299 json | msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserve... | |
| CVE-2026-107298 json | msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no... | |
| CVE-2026-107297 json | msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomp... | |
| CVE-2026-107296 json | msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit intege... | |
| CVE-2026-93017 json | The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group... | |
| CVE-2026-14999 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-14992 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-14988 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-14905 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-14888 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-14509 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-14508 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-14507 json | IBM DataPower Gateway 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to cause a denial of service due ... | |
| CVE-2026-14502 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-14497 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-14496 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-14273 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-107623 json | A flaw was found in the OIDC Dynamic Client Registration (DCR) component of Keycloak. A bug in the response serialization cau... | |
| CVE-2026-107604 json | A flaw was found in the installation provider and client registration endpoints of the Keycloak identity management service. ... | |
| CVE-2026-107565 json | A flaw was found in luksmeta. A local attacker with administrative privileges can cause data corruption when saving metadata ... | |
| CVE-2026-105827 json | ImageMagick before 7.1.2-30 and 6.9.13-55 contains an uncontrolled recursion vulnerability in the CALS decoder due to a missi... | |
| CVE-2026-105826 json | ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a security policy bypass in the MAT decoder, which does not enf... | |
| CVE-2026-105825 json | ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a denial of service vulnerability in its handling of XMP profil... | |
| CVE-2026-105824 json | ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a use-after-free vulnerability in the RSVG decoder when built w... | |
| CVE-2026-14269 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-13258 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-13257 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-105823 json | ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 lacks a security policy check in the CUT encoder, allowing configured se... | |
| CVE-2026-105405 json | ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains an invalid memory free vulnerability in the MVG decoder. Attack... | |
| CVE-2026-105404 json | ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a code injection vulnerability in its PostScript coders, becaus... | |
| CVE-2026-105403 json | ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 allows a security policy bypass when a policy uses coder, rather than mo... | |
| CVE-2026-105402 json | ImageMagick before 7.1.2-31 contains a denial of service vulnerability that allows attackers to disrupt processing by supplyi... | |
| CVE-2026-105401 json | ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability in the distributed pixel cache server that allows c... | |
| CVE-2026-105400 json | ImageMagick before 7.1.2-31 contains a resource leak vulnerability that allows attackers to leave file pointers open by suppl... | |
| CVE-2026-105399 json | ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a denial of service vulnerability in the MVG decoder caused by ... | |
| CVE-2026-105398 json | ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability that allows attackers to overwrite heap memory by m... | |
| CVE-2026-104634 json | Incorrect Type Conversion or Cast vulnerability in BeamMCP.Server in ScriptKittyOS beam_mcp allows an MCP client's JSON true,... | |
| CVE-2026-88257 json | Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's di... | |
| CVE-2026-16340 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-16182 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.... | |
| CVE-2026-16181 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-16179 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-16178 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-16177 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-16167 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-16165 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-16164 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-16163 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-16161 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-16159 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-16111 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-15824 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-15822 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-15819 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-15784 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-15781 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... | |
| CVE-2026-15762 json | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.... |