CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2025-13845 json CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project ...
CVE-2025-13822 json MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication m...
CVE-2025-13818 json Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent
CVE-2025-13879 json Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with administra...
CVE-2025-13877 json A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the file ...
CVE-2025-13875 json A weakness has been identified in Yohann0617 oci-helper up to 3.2.4. This issue affects the function addCfg of the file src/m...
CVE-2025-13873 json Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allo...
CVE-2025-13872 json Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-bas...
CVE-2025-13844 json CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious proje...
CVE-2025-13828 json SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if t...
CVE-2025-13824 json A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault ...
CVE-2025-13823 json A security issue was found in the IPv6 stack in the Micro850 and Micro870 controllers when the controllers received multiple ...
CVE-2025-13829 json Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private info...
CVE-2025-13816 json A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2. The impacted element is the function FileOpe...
CVE-2025-13815 json A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file ...
CVE-2025-13814 json A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploa...
CVE-2025-13813 json A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /...
CVE-2025-13811 json A vulnerability was determined in jsnjfz WebStack-Guns 1.0. This vulnerability affects unknown code of the file src/main/java...
CVE-2025-13810 json A vulnerability was found in jsnjfz WebStack-Guns 1.0. This affects the function renderPicture of the file src/main/java/com/...
CVE-2025-13809 json A vulnerability has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this issue i...
CVE-2025-13808 json A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerability is...
CVE-2025-13807 json A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected is the function M...
CVE-2025-13805 json A weakness has been identified in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This affects the function getInputStream of the file ...
CVE-2025-13804 json A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT. The impacted element is an unknown function of t...
CVE-2025-13803 json A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /mediacrush...
CVE-2025-29923 json go-redis is the official Redis client library for the Go programming language. Prior to 9.5.5, 9.6.3, and 9.7.2, go-redis pot...
CVE-2025-13802 json A vulnerability was determined in jairiidriss RestaurantWebsite up to e7911f12d035e8e2f9a75e7a28b59e4ef5c1d654. Impacted is a...
CVE-2025-13800 json A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue affects the function set_mesh_disconnect of the file...
CVE-2025-13799 json A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This vulnerability affects the function ap_macfilter_del o...
CVE-2025-13797 json A vulnerability was detected in ADSLR B-QE2W401 250814-r037c. Affected by this issue is the function parameterdel_swifimac of...
CVE-2025-13796 json A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this vulnerability is the function Anal...
CVE-2025-13795 json A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c01. Af...
CVE-2025-13793 json A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected b...
CVE-2025-13790 json A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-s...
CVE-2025-13789 json A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php....
CVE-2025-13788 json A vulnerability has been found in Chanjet CRM up to 20251106. The impacted element is an unknown function of the file /tools/...
CVE-2025-13787 json A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/...
CVE-2025-13786 json A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch o...
CVE-2025-13785 json A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects some un...
CVE-2025-13784 json A weakness has been identified in yungifez Skuul School Management System up to 2.6.5. This vulnerability affects unknown cod...
CVE-2025-13762 json Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of S...
CVE-2024-7806 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-7314 json Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insuffi...
CVE-2023-7313 json Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modifications tool. Insufficien...
CVE-2023-7309 json A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua S...
CVE-2023-7305 json SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under ce...
CVE-2023-7303 json A vulnerability, which was classified as problematic, was found in q2apro q2apro-on-site-notifications up to 1.4.6. This affe...
CVE-2023-7299 json A vulnerability was found in DataGear up to 4.60. It has been declared as critical. This vulnerability affects unknown code o...
CVE-2023-7279 json A vulnerability has been found in Secure Systems Engineering Connaisseur up to 3.3.0 and classified as problematic. This vuln...
CVE-2023-7260 json Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4. The vulnerability co...
CVE-2023-7259 json ** DISPUTED ** A vulnerability was found in zzdevelop lenosp up to 20230831. It has been classified as problematic. This affe...
CVE-2023-7249 json Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory S...
CVE-2022-34821 json A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK610...
CVE-2026-64057 json In the Linux kernel, the following vulnerability has been resolved: afs: Fix the locking used by afs_get_link() The afs fil...
CVE-2026-9586 json An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint proces...
CVE-2026-84857 json A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the file src/serve.rs of the compon...
CVE-2026-84856 json A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The impacted element is the function request.text/req.json o...
CVE-2026-84852 json A security vulnerability has been detected in Reader Tools PDF Reader App 98.8 on Android. The affected element is the functi...
CVE-2026-84452 json Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to ...
CVE-2026-84292 json fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host ...
CVE-2026-82524 json UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload ar...
CVE-2026-78662 json Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood...
CVE-2026-75137 json UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cl...
CVE-2026-75136 json UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to retri...
CVE-2026-75135 json UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover th...
CVE-2026-75134 json SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated...
CVE-2026-56855 json Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire...
CVE-2026-84642 json The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escapin...
CVE-2026-84372 json Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeli...
CVE-2026-84361 json Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from ...
CVE-2026-81928 json Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message...
CVE-2026-81205 json Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Di...
CVE-2026-81164 json Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: fr...
CVE-2026-49249 json Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity ...
CVE-2023-20577 json A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, ...
CVE-2023-20576 json Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting...
CVE-2026-84303 json gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/...
CVE-2026-59822 json LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamab...
CVE-2026-15809 json A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An...
CVE-2026-7680 json A weakness has been identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file backend/we...
CVE-2023-20579 json Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypa...
CVE-2026-68752 json A Project Resource Manager may gain broader administrative privileges under specific conditions.
CVE-2026-76221 json GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to ...
CVE-2026-73783 json Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malic...
CVE-2026-73782 json A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code e...
CVE-2026-73781 json A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a sto...
CVE-2026-73780 json A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Reques...
CVE-2026-73779 json Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticat...
CVE-2026-73778 json A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthen...
CVE-2026-73777 json Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated r...
CVE-2026-73776 json A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could a...
CVE-2026-73775 json Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensi...
CVE-2026-73774 json A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclo...
CVE-2026-73773 json An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of thi...
CVE-2026-73772 json Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-serv...
CVE-2026-73771 json An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication proc...
CVE-2026-73770 json An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated ma...
CVE-2026-73768 json A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Suc...
CVE-2026-73767 json Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of the...
CVE-2026-73766 json Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrat...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report