CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-70328 json | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | |
| CVE-2026-70327 json | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | |
| CVE-2026-70318 json | Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| CVE-2026-68817 json | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| CVE-2026-68816 json | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| CVE-2026-68815 json | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| CVE-2026-68814 json | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| CVE-2026-68813 json | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| CVE-2026-68812 json | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| CVE-2026-33167 json | Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1... | |
| CVE-2026-2072 json | Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Cente... | |
| CVE-2026-1166 json | Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops Center Administrator: from 10.... | |
| CVE-2026-68795 json | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| CVE-2026-68794 json | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| CVE-2026-68793 json | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| CVE-2026-65807 json | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to ex... | |
| CVE-2026-6245 json | A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM pas... | |
| CVE-2026-2336 json | A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-d... | |
| CVE-2025-9497 json | Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issu... | |
| CVE-2026-73325 json | Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to exe... | |
| CVE-2026-73294 json | Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling pas... | |
| CVE-2026-73293 json | Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, Proje... | |
| CVE-2026-73292 json | Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a ... | |
| CVE-2026-70547 json | An authenticated user without repository read permission may access package metadata under specific conditions. | |
| CVE-2026-69107 json | An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. | |
| CVE-2026-69105 json | An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting... | |
| CVE-2026-68971 json | Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `... | |
| CVE-2026-68970 json | Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape... | |
| CVE-2026-68969 json | Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted t... | |
| CVE-2026-68968 json | Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path se... | |
| CVE-2026-68759 json | A holder of a valid integration credential may impersonate other users under specific conditions. | |
| CVE-2026-68758 json | A low-privileged authenticated user may access restricted support information under specific conditions. | |
| CVE-2026-68076 json | Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's sco... | |
| CVE-2026-67587 json | Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the m... | |
| CVE-2026-67260 json | Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the sched... | |
| CVE-2026-66384 json | An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. | |
| CVE-2026-66016 json | Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible t... | |
| CVE-2026-65941 json | In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected se... | |
| CVE-2026-65940 json | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible locati... | |
| CVE-2026-65939 json | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitra... | |
| CVE-2026-65938 json | In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API all... | |
| CVE-2026-65937 json | In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persiste... | |
| CVE-2026-65926 json | An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle... | |
| CVE-2026-65017 json | Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an admini... | |
| CVE-2026-64639 json | Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (custome... | |
| CVE-2026-59244 json | ||
| CVE-2026-59242 json | Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through... | |
| CVE-2026-58076 json | Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from th... | |
| CVE-2026-73290 json | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request ... | |
| CVE-2026-54183 json | Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's... | |
| CVE-2026-19548 json | Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld),... | |
| CVE-2026-15803 json | In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing unt... | |
| CVE-2025-35988 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-35977 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-32737 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-32087 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-32084 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-31943 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-30178 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-27570 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-27245 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-25275 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-24837 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-24488 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-20020 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2026-73286 json | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attack... | |
| CVE-2026-73264 json | Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access co... | |
| CVE-2026-73263 json | Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content co... | |
| CVE-2026-71845 json | A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, inc... | |
| CVE-2026-70345 json | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-70336 json | Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute co... | |
| CVE-2026-70322 json | Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | |
| CVE-2026-70317 json | Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| CVE-2026-68756 json | A party with write access to stored session data may affect JFrog Artifactory under specific conditions. | |
| CVE-2026-67558 json | The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against ... | |
| CVE-2026-53996 json | NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivile... | |
| CVE-2026-49262 json | In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulne... | |
| CVE-2026-47231 json | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-changi... | |
| CVE-2026-47227 json | Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`... | |
| CVE-2026-14479 json | A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an... | |
| CVE-2026-14478 json | A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject ... | |
| CVE-2026-70312 json | Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | |
| CVE-2026-70304 json | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-68821 json | Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-68801 json | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| CVE-2026-68800 json | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| CVE-2026-68799 json | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| CVE-2026-68797 json | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| CVE-2026-68796 json | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| CVE-2026-66804 json | Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-65806 json | Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. | |
| CVE-2026-65783 json | Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-65672 json | Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-65671 json | Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-64922 json | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an... | |
| CVE-2026-63521 json | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| CVE-2026-62901 json | Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-62793 json | Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | |
| CVE-2026-62786 json | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | |
| CVE-2026-62781 json | Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network. |