CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-62546 json Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported ...
CVE-2026-62534 json Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported ...
CVE-2026-17633 json IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injec...
CVE-2026-17632 json IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper v...
CVE-2026-17630 json IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of c...
CVE-2026-17626 json IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive hos...
CVE-2026-17624 json IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3...
CVE-2026-17623 json IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improp...
CVE-2026-10547 json IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/ver...
CVE-2026-7646 json IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users'...
CVE-2026-17625 json IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3...
CVE-2026-10128 json IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary ...
CVE-2026-9077 json IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions an...
CVE-2026-8446 json IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) comp...
CVE-2026-8182 json IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server with...
CVE-2026-7869 json IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bas...
CVE-2026-7658 json IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traver...
CVE-2026-9130 json IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authen...
CVE-2026-8478 json IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improp...
CVE-2026-8470 json IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-...
CVE-2026-8183 json IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3...
CVE-2026-68080 json It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker ...
CVE-2026-68078 json It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker...
CVE-2026-68077 json An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive...
CVE-2026-68075 json An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. Th...
CVE-2026-68073 json A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of serv...
CVE-2026-64640 json Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated...
CVE-2026-61486 json ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: al...
CVE-2026-61485 json ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects...
CVE-2026-61484 json ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lu...
CVE-2026-61483 json ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all ver...
CVE-2026-60023 json Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer:...
CVE-2026-50749 json Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated u...
CVE-2026-48912 json Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing owner...
CVE-2026-48911 json Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0...
CVE-2026-48834 json Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: throug...
CVE-2026-25292 json Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
CVE-2026-9205 json IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
CVE-2026-9201 json IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic ...
CVE-2026-9196 json IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assista...
CVE-2026-25289 json Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid ...
CVE-2026-25288 json Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
CVE-2026-24084 json Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabili...
CVE-2026-24083 json Memory Corruption while processing IOCTL device driver requests with invalid arguments.
CVE-2026-24080 json Memory Corruption when handling malformed request parameters in the fingerprint TA.
CVE-2026-24079 json Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
CVE-2026-24078 json Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVE-2026-24077 json Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
CVE-2026-24076 json Memory Corruption when processing registry values with incorrect types using a direct query method.
CVE-2026-21366 json Memory corruption while processing a packet with a size close to the maximum allowed value.
CVE-2026-48782 json Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 throug...
CVE-2026-18108 json Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an Encrypted...
CVE-2026-18092 json Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml rea...
CVE-2026-18089 json Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedde...
CVE-2026-15429 json A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of u...
CVE-2026-15428 json An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name pa...
CVE-2026-15427 json An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficie...
CVE-2026-9726 json Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeComm...
CVE-2026-5040 json TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password ha...
CVE-2026-60180 json Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++). Supported versions that are affect...
CVE-2026-60179 json Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++). Supported versions that are affect...
CVE-2026-13183 json In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic va...
CVE-2026-13182 json In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt fail...
CVE-2026-13181 json In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing...
CVE-2026-9081 json IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability i...
CVE-2026-7657 json IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffecti...
CVE-2026-60062 json The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outsid...
CVE-2026-48801 json linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's...
CVE-2026-48125 json UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1...
CVE-2026-13230 json An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, ...
CVE-2026-9770 json Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared...
CVE-2026-13188 json In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially ...
CVE-2026-13187 json In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially...
CVE-2026-13186 json In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storag...
CVE-2026-13185 json In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or...
CVE-2026-13184 json In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey i...
CVE-2026-12482 json A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `fil...
CVE-2026-10670 json The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_name_copy() in kernel/thr...
CVE-2026-10669 json On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/mpu.c — the ar...
CVE-2026-14932 json In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnera...
CVE-2026-14865 json In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML witho...
CVE-2026-13192 json In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF e...
CVE-2026-14902 json An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users...
CVE-2026-13190 json In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows...
CVE-2026-13189 json In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell chec...
CVE-2026-10672 json subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, siz...
CVE-2026-10671 json In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_pipe_init() in kernel/pipe.c used K_SYSCALL_O...
CVE-2026-58659 json PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state f...
CVE-2026-14903 json Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary f...
CVE-2026-12523 json Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of...
CVE-2026-66326 json Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-66325 json Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing ove...
CVE-2026-62241 json clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in a...
CVE-2026-66322 json Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network...
CVE-2026-66321 json Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attac...
CVE-2026-66318 json Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a net...
CVE-2026-66317 json Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a networ...
CVE-2026-66316 json Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network...
CVE-2026-66315 json Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-66314 json Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to discl...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report