CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-65904 json | DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a different ... | |
| CVE-2026-65689 json | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database d... | |
| CVE-2026-65593 json | n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-para... | |
| CVE-2026-61884 json | The web management interface of Tycon Systems TPDIN-Monitor-WEB2 does not perform server-side validation of credentials d... | |
| CVE-2026-55985 json | The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a ... | |
| CVE-2026-11354 json | The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc... | |
| CVE-2025-71408 json | NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module... | |
| CVE-2026-34596 json | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of-Chec... | |
| CVE-2026-34527 json | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniServer:... | |
| CVE-2026-34464 json | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServe... | |
| CVE-2026-34462 json | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several Proces... | |
| CVE-2026-34461 json | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieIniSer... | |
| CVE-2026-34459 json | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc pr... | |
| CVE-2026-34458 json | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injecti... | |
| CVE-2026-34457 json | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a confi... | |
| CVE-2026-34454 json | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 preven... | |
| CVE-2026-33975 json | Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-serve... | |
| CVE-2026-33489 json | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza... | |
| CVE-2026-33467 json | Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to ... | |
| CVE-2026-33420 json | Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details ... | |
| CVE-2026-33414 json | Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability... | |
| CVE-2026-33324 json | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2S... | |
| CVE-2026-33190 json | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-DNS tr... | |
| CVE-2026-34619 json | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Director... | |
| CVE-2026-34602 json | Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users endpoint... | |
| CVE-2026-34370 json | Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains an In... | |
| CVE-2026-34213 json | Docmost is open-source collaborative wiki and documentation software. Starting in version 0.3.0 and prior to version 0.71.0, ... | |
| CVE-2026-34212 json | Docmost is open-source collaborative wiki and documentation software. In versions prior to 0.71.0, improper neutralization of... | |
| CVE-2026-34161 json | Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, a Stored Cross-Site Scripting (XSS... | |
| CVE-2026-34160 json | Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange Notific... | |
| CVE-2026-33715 json | Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.ajax.php... | |
| CVE-2026-33714 json | Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in the ... | |
| CVE-2026-33193 json | Docmost is open-source collaborative wiki and documentation software. Versions prior to 0.70.0 are vulnerable to a stored cro... | |
| CVE-2026-33146 json | Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions 0.70.... | |
| CVE-2026-34625 json | Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabi... | |
| CVE-2026-34624 json | Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabi... | |
| CVE-2026-34623 json | Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabi... | |
| CVE-2026-34617 json | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result... | |
| CVE-2026-34615 json | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could... | |
| CVE-2026-34614 json | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an ... | |
| CVE-2026-33829 json | Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perfor... | |
| CVE-2026-34837 json | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, he REST endpoint POST /api/v1/ai_assistan... | |
| CVE-2026-34782 json | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the REST endpoint POST /api/v1/... | |
| CVE-2026-34724 json | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerab... | |
| CVE-2026-34723 json | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, unauthenticated remote attacker... | |
| CVE-2026-34722 json | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the used endpoint for ticket cr... | |
| CVE-2026-33827 json | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unaut... | |
| CVE-2026-33826 json | Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network. | |
| CVE-2026-33825 json | Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-33824 json | Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. | |
| CVE-2026-33822 json | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| CVE-2026-3438 json | A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows ... | |
| CVE-2026-34721 json | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoints fo... | |
| CVE-2026-34720 json | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the SSO mechanism in Zammad was... | |
| CVE-2026-34719 json | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the webhook model was missing a... | |
| CVE-2026-34718 json | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for ticket a... | |
| CVE-2026-34392 json | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-mana... | |
| CVE-2026-34248 json | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means ... | |
| CVE-2026-34166 json | LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter in L... | |
| CVE-2026-33458 json | Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with w... | |
| CVE-2026-33350 json | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-mana... | |
| CVE-2026-33810 json | When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildca... | |
| CVE-2026-33753 json | rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Autho... | |
| CVE-2026-33273 json | Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is ex... | |
| CVE-2026-3480 json | The WP Blockade plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 0.9.14. The p... | |
| CVE-2026-3477 json | The PZ Frontend Manager plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.6... | |
| CVE-2026-34781 json | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8... | |
| CVE-2026-34765 json | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8... | |
| CVE-2026-34582 json | Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to b... | |
| CVE-2026-34580 json | Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it w... | |
| CVE-2026-34371 json | LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the execut... | |
| CVE-2026-34080 json | xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eav... | |
| CVE-2026-34079 json | Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated... | |
| CVE-2026-34078 json | Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in th... | |
| CVE-2026-34045 json | Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP serv... | |
| CVE-2026-33439 json | Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable ... | |
| CVE-2026-3357 json | IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, ... | |
| CVE-2025-69515 json | An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into acc... | |
| CVE-2025-14859 json | The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware. H... | |
| CVE-2025-14858 json | The Semtech LR11xx LoRa transceivers running early versions of firmware contains an information disclosure vulnerability in i... | |
| CVE-2026-22675 json | OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthentica... | |
| CVE-2026-20432 json | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of priv... | |
| CVE-2026-20431 json | In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has con... | |
| CVE-2026-0049 json | In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. T... | |
| CVE-2025-71058 json | Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originates fro... | |
| CVE-2025-58349 json | An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 12... | |
| CVE-2025-54602 json | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1... | |
| CVE-2025-54601 json | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor amd Wearable Processor Exynos 980, 850, 1080, 1280, 1... | |
| CVE-2025-54328 json | An issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1... | |
| CVE-2025-13044 json | IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitra... | |
| CVE-2019-25704 json | Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting ... | |
| CVE-2019-25702 json | Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting ... | |
| CVE-2019-25700 json | Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting ... | |
| CVE-2019-25698 json | Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting ... | |
| CVE-2019-25696 json | Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting ... | |
| CVE-2019-25694 json | Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queri... | |
| CVE-2019-25692 json | Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting ... | |
| CVE-2019-25690 json | Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting ... | |
| CVE-2019-25688 json | Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queri... | |
| CVE-2019-25687 json | Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated att... |