CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-105786 json Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, pa...
CVE-2026-105785 json Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Ser...
CVE-2026-82989 json There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated at...
CVE-2026-82988 json There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unaut...
CVE-2026-105784 json Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, se...
CVE-2026-105783 json Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, wh...
CVE-2026-105782 json Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, RefererMiddleware in scrapy/s...
CVE-2026-105764 json Immich is a high-performance self-hosted photo and video management solution. Prior to 3.2.4, an authenticated non-admin user...
CVE-2026-105763 json Twenty is an open-source CRM (customer relationship management) platform. From 1.20.10 until 2.7.0, the /metadata GraphQL con...
CVE-2026-105762 json Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/co...
CVE-2026-105471 json A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c9...
CVE-2026-103592 json simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that all...
CVE-2026-103588 json QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Tran...
CVE-2026-103001 json PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() meth...
CVE-2026-15563 json A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an a...
CVE-2026-7507 json A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit t...
CVE-2026-7307 json A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Asser...
CVE-2026-4634 json A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST ...
CVE-2026-0603 json A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability...
CVE-2025-9784 json A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse c...
CVE-2026-105761 json Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/<app_id>/server endpoin...
CVE-2026-105760 json vLLM is an inference and serving engine for large language models. Prior to 0.30.0, a caller can use the request-level media_...
CVE-2026-105759 json vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the Rust frontend's track_http_metrics mi...
CVE-2026-105758 json vLLM is an inference and serving engine for large language models. From 0.24.0 until 0.30.0, the Qwen2VLVideoBackend and Qwen...
CVE-2026-105757 json vLLM is an inference and serving engine for large language models. Prior to 0.30.0, structured-output request failures can es...
CVE-2026-105756 json vLLM is an inference and serving engine for large language models. Prior to 0.30.0, OpenAI-compatible request models accept a...
CVE-2026-105755 json vLLM is an inference and serving engine for large language models. Prior to 0.30.0, flash late-interaction scoring at the /sc...
CVE-2026-105754 json vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the /inference/v1/generate endpoint in th...
CVE-2026-105753 json vLLM is an inference and serving engine for large language models. Prior to 0.28.0, the default mirrored multimodal LRU cache...
CVE-2026-105752 json vLLM is an inference and serving engine for large language models. Prior to 0.30.0, Harmony tool continuations submitted thro...
CVE-2026-105470 json A vulnerability was identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d...
CVE-2026-105469 json A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d...
CVE-2026-104852 json GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 12.0.1, the GraphQL Tools uti...
CVE-2026-105751 json Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem...
CVE-2026-105750 json Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem...
CVE-2026-105749 json Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem...
CVE-2026-105748 json Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem...
CVE-2026-105747 json Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem...
CVE-2026-105746 json Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem...
CVE-2026-105745 json Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem...
CVE-2026-105744 json Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem...
CVE-2026-105743 json Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem...
CVE-2026-93321 json A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds runni...
CVE-2026-93315 json When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup t...
CVE-2026-91107 json openSIS Classic 9.3 allows an authenticated user with the built-in teacher role can select an arbitrary staff record through ...
CVE-2026-21589 json h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, J...
CVE-2026-105742 json Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem...
CVE-2026-105468 json A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. Th...
CVE-2026-103546 json In MongoDB Controllers for Kubernetes, insufficient validation of Ops Manager backup configuration may allow a user who can m...
CVE-2026-103433 json Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition...
CVE-2026-0482 json In AMD Versal™ Adaptive SoC devices, insufficient boundary checks in USB boot mode—when enabled through board modificatio...
CVE-2026-0461 json Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could...
CVE-2026-105773 json Canimaan Software ClamXAV versions 3.3 - 3.11 contains a local privilege escalation vulnerability in the Privileged Helper To...
CVE-2026-105768 json apko allows users to build and publish OCI container images built from apk packages. From version 0.2.0 to before version 1.4...
CVE-2026-105741 json Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulner...
CVE-2026-105740 json Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow use...
CVE-2026-105699 json Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.6.8 until 1.9.1, Langflow authenticated...
CVE-2026-105698 json Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did not veri...
CVE-2026-105697 json Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transpor...
CVE-2026-105447 json A flaw was found in Quay. When handling build trigger requests, the application incorrectly exposes trigger configuration det...
CVE-2026-105444 json A security flaw has been discovered in dotnet eShop .NET 8. The impacted element is the function GetOrderAsync of the file sr...
CVE-2026-105438 json A flaw has been found in O2OA up to 10.0.1-ce. This affects the function ActionUploadExcelWithUrl of the file /x_general_asse...
CVE-2026-102262 json Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker c...
CVE-2026-93326 json A build step for a Git source, crafted in a specific way, can bypass some policy validation rules. A malicious build definiti...
CVE-2026-84900 json Previous versions of HP ThinPro (prior to HP ThinPro 8.1 SP10) could potentially contain security vulnerabilities. HP has rel...
CVE-2026-77226 json Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setu...
CVE-2026-105695 json Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using ...
CVE-2026-105690 json Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie with...
CVE-2026-105684 json Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-comment-threads, get-comment-thread, and g...
CVE-2026-105294 json Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write ...
CVE-2026-105221 json The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to inte...
CVE-2026-105216 json go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate ...
CVE-2026-105214 json Zitadel before 4.16.2 contains a server-side request forgery vulnerability that allows attackers to make the server request i...
CVE-2026-105209 json ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or pas...
CVE-2026-101893 json Newell Brands DYMO ID 1.5.1.71 parses job files using XmlDocument.Load() without disabling DTD processing. The PC Job Files v...
CVE-2026-55270 json In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to loc...
CVE-2026-45524 json In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lea...
CVE-2026-28667 json In multiple functions of rw_t5t.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to ...
CVE-2026-105131 json ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to ...
CVE-2026-105126 json LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to e...
CVE-2026-105121 json OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy session...
CVE-2026-105116 json OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL u...
CVE-2026-105083 json ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips secur...
CVE-2026-104859 json Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @...
CVE-2026-104846 json Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 un...
CVE-2026-104477 json Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to...
CVE-2026-104182 json stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3...
CVE-2026-94544 json Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for ...
CVE-2026-82045 json UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity ...
CVE-2026-82040 json UTMStack before 11.2.16 contains a server-side request forgery vulnerability in IdentityProviderService.validateMetadataUrl()...
CVE-2026-70650 json GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3....
CVE-2026-93354 json Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to reg...
CVE-2026-76782 json Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
CVE-2026-55251 json NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to comm...
CVE-2026-53953 json GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3...
CVE-2026-103105 json Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which ...
CVE-2026-103104 json Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation wh...
CVE-2026-103102 json Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote att...
CVE-2026-103101 json Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicio...
CVE-2026-103100 json Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious a...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report