CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-18929 json Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The libra...
CVE-2026-15722 json A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in re...
CVE-2026-5674 json A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, su...
CVE-2025-6020 json A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allow...
CVE-2025-5318 json A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handl...
CVE-2026-43971 json Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescape...
CVE-2024-14045 json A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/contr...
CVE-2026-56211 json A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds valida...
CVE-2026-56210 json A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check...
CVE-2026-56209 json An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check ...
CVE-2026-56208 json A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's...
CVE-2026-34884 json SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue aff...
CVE-2026-12243 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-7195 json Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a ra...
CVE-2025-5914 json A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() fu...
CVE-2025-5278 json A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The prog...
CVE-2026-53511 json calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when its ...
CVE-2025-7425 json A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory manage...
CVE-2026-74505 json In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: Fix UAF at error handling during probe Alt...
CVE-2026-74449 json In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix divide-by-zero in calculate_mcache_...
CVE-2026-74448 json In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix QID bit leak in pqm_create_queue() When...
CVE-2026-74424 json In the Linux kernel, the following vulnerability has been resolved: fbcon: fix NULL pointer dereference for a console withou...
CVE-2026-72243 json In the Linux kernel, the following vulnerability has been resolved: selinux: check connect-related permissions on TCP Fast O...
CVE-2026-72211 json In the Linux kernel, the following vulnerability has been resolved: ntfs: grow index root value before reparent header updat...
CVE-2026-15371 json Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a U...
CVE-2026-72210 json In the Linux kernel, the following vulnerability has been resolved: ntfs: fix off-by-one in mapping pairs decoding bounds ch...
CVE-2026-72208 json In the Linux kernel, the following vulnerability has been resolved: ntfs: add bounds check before accessing EA entries in n...
CVE-2026-72207 json In the Linux kernel, the following vulnerability has been resolved: ntfs: not change 0-byte $DATA attribute to non-resident ...
CVE-2026-72206 json In the Linux kernel, the following vulnerability has been resolved: ntfs: validate index block header more strictly Modify ...
CVE-2026-72205 json In the Linux kernel, the following vulnerability has been resolved: ntfs: free volume-wide resources on fill_super failure ...
CVE-2026-72204 json In the Linux kernel, the following vulnerability has been resolved: ntfs: centalize $INDEX_ROOT header validation Add a ded...
CVE-2026-72203 json In the Linux kernel, the following vulnerability has been resolved: ntfs: skip extent mft records in writeback to prevent de...
CVE-2026-72202 json In the Linux kernel, the following vulnerability has been resolved: ntfs: avoid heap allocation for free-cluster readahead s...
CVE-2026-72201 json In the Linux kernel, the following vulnerability has been resolved: ntfs: validate index entries on reading Validate index ...
CVE-2026-72200 json In the Linux kernel, the following vulnerability has been resolved: ntfs: detect mapping-pairs LCN accumulator overflow The...
CVE-2026-72199 json In the Linux kernel, the following vulnerability has been resolved: ntfs: validate resident index root values on lookup Res...
CVE-2026-72198 json In the Linux kernel, the following vulnerability has been resolved: ntfs: reject non-resident records for resident-only attr...
CVE-2026-72162 json In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_...
CVE-2026-72150 json In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix uninitialized xprt_create_args structure Th...
CVE-2026-72106 json In the Linux kernel, the following vulnerability has been resolved: dm-ioctl: fix a possible overflow in list_version_get_in...
CVE-2026-72031 json In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD ...
CVE-2026-72025 json In the Linux kernel, the following vulnerability has been resolved: s390/monwriter: Reject buffer reuse with different data ...
CVE-2026-68460 json In the Linux kernel, the following vulnerability has been resolved: f2fs: fix potential deadlock in f2fs_balance_fs() When ...
CVE-2026-68457 json In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for FSCTL mutations SET_S...
CVE-2026-68447 json In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU control stack checkpoint copy ...
CVE-2026-68436 json In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: use kvzalloc to allocate struct dc str...
CVE-2026-68430 json In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx8: drop unecessary BUG_ON() There's no ne...
CVE-2026-68427 json In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix use-after-free in host1x_bo_clear_cache...
CVE-2026-68374 json In the Linux kernel, the following vulnerability has been resolved: usb: core: sysfs: add lock to bos_descriptors_read() Ad...
CVE-2026-68364 json In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix ISM dc_lock deadlock during suspend...
CVE-2026-68259 json In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds in allocate_event_notification_...
CVE-2026-68258 json In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds on CRIU restore queue type and ...
CVE-2026-68257 json In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix 32-bit overflow in CWSR total size calcu...
CVE-2026-68252 json In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() The...
CVE-2026-68251 json In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() The...
CVE-2026-68250 json In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() The...
CVE-2026-68480 json In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injecti...
CVE-2026-68249 json In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() The...
CVE-2026-68246 json In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() There...
CVE-2026-68245 json In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_inf...
CVE-2026-68235 json In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: dce100: skip non-DP stream encoders for...
CVE-2026-68234 json In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_rese...
CVE-2026-68185 json In the Linux kernel, the following vulnerability has been resolved: LoongArch: Move jump_label_init() before parse_early_par...
CVE-2026-68155 json In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors A mes...
CVE-2026-68115 json In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() There...
CVE-2026-68114 json In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON() The...
CVE-2026-68113 json In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() There...
CVE-2026-68112 json In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() Th...
CVE-2026-17107 json A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHA...
CVE-2026-16242 json A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was star...
CVE-2026-4740 json A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Impro...
CVE-2026-1784 json The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that...
CVE-2026-75091 json The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site ...
CVE-2026-15748 json The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1...
CVE-2026-75060 json In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
CVE-2026-75059 json In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
CVE-2026-75056 json In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
CVE-2026-75051 json In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
CVE-2026-75045 json In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database ...
CVE-2026-75007 json In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%...
CVE-2026-75003 json In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could eva...
CVE-2026-75002 json In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead t...
CVE-2026-75000 json In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute m...
CVE-2026-74254 json Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerabl...
CVE-2026-71947 json D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injectio...
CVE-2026-71571 json Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Back...
CVE-2026-69414 json Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly ref...
CVE-2026-50523 json Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authori...
CVE-2026-17184 json IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of fil...
CVE-2026-16139 json In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can explo...
CVE-2026-16138 json In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata ...
CVE-2026-16137 json In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traver...
CVE-2025-62593 json Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via ...
CVE-2026-75151 json A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnera...
CVE-2026-74243 json A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated atta...
CVE-2026-73683 json Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers t...
CVE-2026-73053 json SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to saniti...
CVE-2026-73045 json SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublis...
CVE-2026-72810 json SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows ano...
CVE-2026-19926 json A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown funct...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report