CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-73161 json | Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feature. ... | |
| CVE-2026-73160 json | Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. ... | |
| CVE-2026-73159 json | Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's v-htm... | |
| CVE-2026-73158 json | Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can contain s... | |
| CVE-2026-73157 json | Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface using HT... | |
| CVE-2026-72694 json | A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-priv... | |
| CVE-2026-72693 json | `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged conte... | |
| CVE-2026-71218 json | A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, whic... | |
| CVE-2026-71217 json | A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with ove... | |
| CVE-2026-49332 json | A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forw... | |
| CVE-2026-19418 json | The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYP... | |
| CVE-2026-19411 json | A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow a... | |
| CVE-2026-15567 json | A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder ... | |
| CVE-2026-15565 json | A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any ... | |
| CVE-2026-15563 json | A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an a... | |
| CVE-2026-15562 json | A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and comp... | |
| CVE-2026-15561 json | A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacke... | |
| CVE-2026-15560 json | when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalli... | |
| CVE-2026-15556 json | A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the sig... | |
| CVE-2026-15555 json | A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the J... | |
| CVE-2026-15554 json | the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authenticatio... | |
| CVE-2026-10579 json | A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verifi... | |
| CVE-2026-73156 json | Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap toolti... | |
| CVE-2026-73155 json | Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first check... | |
| CVE-2026-73140 json | Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports... | |
| CVE-2026-19519 json | A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked type... | |
| CVE-2026-19429 json | Jenkins FilePath.untarFrom() does not validate symlink targets in extracted TAR archives, even in versions patched for CVE-20... | |
| CVE-2026-19518 json | Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulatio... | |
| CVE-2026-19517 json | Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in ... | |
| CVE-2026-19391 json | A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the liter... | |
| CVE-2026-16053 json | Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Trave... | |
| CVE-2026-68480 json | In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injecti... | |
| CVE-2026-40127 json | OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID paramete... | |
| CVE-2026-19516 json | A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_a... | |
| CVE-2026-18348 json | Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role... | |
| CVE-2026-14549 json | The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its A... | |
| CVE-2026-14548 json | The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its A... | |
| CVE-2026-13716 json | Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload... | |
| CVE-2026-12052 json | The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.c bui... | |
| CVE-2026-12051 json | The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer derefere... | |
| CVE-2026-11894 json | The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_h... | |
| CVE-2026-8158 json | The Signed Video Framework contained a buffer overflow issue which could lead the application using this framework to cras... | |
| CVE-2026-6505 json | The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege... | |
| CVE-2026-6181 json | The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after aut... | |
| CVE-2026-5304 json | An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability c... | |
| CVE-2026-5303 json | The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege... | |
| CVE-2026-4757 json | A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege esca... | |
| CVE-2026-19425 json | Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote ... | |
| CVE-2026-16974 json | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scr... | |
| CVE-2026-11985 json | On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to CONF... | |
| CVE-2026-11893 json | The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetooth/hc... | |
| CVE-2026-19195 json | A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the lib... | |
| CVE-2026-19193 json | A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of t... | |
| CVE-2026-18982 json | A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Ku... | |
| CVE-2026-18951 json | A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggrega... | |
| CVE-2026-18950 json | A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBind... | |
| CVE-2026-18949 json | A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account... | |
| CVE-2026-18948 json | A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are... | |
| CVE-2026-18947 json | A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endp... | |
| CVE-2026-18941 json | A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_... | |
| CVE-2026-18621 json | A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening ... | |
| CVE-2026-18620 json | A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability... | |
| CVE-2026-18618 json | A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known H... | |
| CVE-2026-18617 json | A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.da... | |
| CVE-2026-18611 json | A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sens... | |
| CVE-2026-18608 json | A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, in... | |
| CVE-2026-16456 json | A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit... | |
| CVE-2026-15581 json | A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass... | |
| CVE-2026-15467 json | A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploi... | |
| CVE-2026-18772 json | Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expan... | |
| CVE-2026-16745 json | A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network bindin... | |
| CVE-2026-15154 json | A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Express... | |
| CVE-2026-72899 json | Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a fi... | |
| CVE-2026-72898 json | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and ga... | |
| CVE-2026-59091 json | A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these ... | |
| CVE-2026-59090 json | A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` varia... | |
| CVE-2026-21074 json | Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bi... | |
| CVE-2026-21068 json | Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arb... | |
| CVE-2026-16626 json | Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. Th... | |
| CVE-2026-65667 json | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2025-42999 json | SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious conten... | |
| CVE-2024-23692 json | Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnera... | |
| CVE-2026-72734 json | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutation in ... | |
| CVE-2026-24330 json | A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious... | |
| CVE-2026-24329 json | A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload into t... | |
| CVE-2026-19424 json | Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote a... | |
| CVE-2026-8917 json | Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local... | |
| CVE-2026-72729 json | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dat... | |
| CVE-2026-72724 json | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/chat/o... | |
| CVE-2026-71577 json | A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs... | |
| CVE-2026-70622 json | tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that a... | |
| CVE-2026-68171 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-59088 json | A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI image f... | |
| CVE-2026-48159 json | use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the default ... | |
| CVE-2026-48158 json | use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the ... | |
| CVE-2026-19384 json | A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown fu... | |
| CVE-2026-19379 json | A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the co... | |
| CVE-2026-19373 json | A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeReque... | |
| CVE-2026-19368 json | A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src... | |
| CVE-2026-19363 json | A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs... |