CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-82901 json | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type... | |
| CVE-2026-85984 json | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via ... | |
| CVE-2026-77203 json | The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up t... | |
| CVE-2026-95811 json | Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allo... | |
| CVE-2026-97163 json | Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 | |
| CVE-2026-97162 json | Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 | |
| CVE-2026-97161 json | Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 | |
| CVE-2026-97160 json | Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.... | |
| CVE-2026-94132 json | Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise ex... | |
| CVE-2026-94131 json | Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A s... | |
| CVE-2026-100720 json | Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticat... | |
| CVE-2026-94130 json | Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vul... | |
| CVE-2026-100719 json | Froxlor versions before 2.3.12 contain a credential disclosure vulnerability in the DirProtections.listing API command that r... | |
| CVE-2026-100718 json | Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When an ad... | |
| CVE-2026-100717 json | froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and l... | |
| CVE-2026-100716 json | Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to v... | |
| CVE-2026-100715 json | Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cro... | |
| CVE-2026-100714 json | Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings harden... | |
| CVE-2026-100713 json | Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (l... | |
| CVE-2026-100712 json | froxlor through 2.3.10 disables a user's two-factor authentication immediately upon an unauthenticated-triggerable GET reques... | |
| CVE-2026-100711 json | froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user passwo... | |
| CVE-2026-100710 json | Froxlor through 2.3.10 does not filter sensitive columns from API responses: Domains::get(), Domains::listing(), SubDomains::... | |
| CVE-2026-100709 json | Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the accoun... | |
| CVE-2026-100708 json | Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in th... | |
| CVE-2026-100707 json | Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources due t... | |
| CVE-2026-100706 json | kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tena... | |
| CVE-2026-100705 json | Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.254.16... | |
| CVE-2026-100704 json | Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, the ImageValidatingPolicy (policies.kyverno.io/... | |
| CVE-2026-100703 json | Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to t... | |
| CVE-2026-100702 json | Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing... | |
| CVE-2026-100701 json | Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each cache ... | |
| CVE-2026-100700 json | nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern tha... | |
| CVE-2026-100699 json | Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser) mish... | |
| CVE-2026-100698 json | Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/functi... | |
| CVE-2026-100697 json | Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) ... | |
| CVE-2026-100696 json | Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the optional El... | |
| CVE-2026-100695 json | Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpolated ... | |
| CVE-2026-100694 json | Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type a... | |
| CVE-2026-100693 json | Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal den... | |
| CVE-2026-100692 json | Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at... | |
| CVE-2026-100691 json | Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not esc... | |
| CVE-2026-100690 json | Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js per... | |
| CVE-2026-100689 json | GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules. ... | |
| CVE-2026-100688 json | Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/:appI... | |
| CVE-2026-100687 json | Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to ... | |
| CVE-2026-100686 json | Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint,... | |
| CVE-2026-100685 json | Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate ... | |
| CVE-2026-100684 json | Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In ss... | |
| CVE-2026-100683 json | Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.... | |
| CVE-2026-100682 json | Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts us... | |
| CVE-2026-100681 json | Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability in t... | |
| CVE-2026-100680 json | Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, a... | |
| CVE-2026-100679 json | stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA... | |
| CVE-2026-100678 json | stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a ... | |
| CVE-2026-100677 json | stoatchat before 0.15.5 contains an account enumeration vulnerability in the login endpoint that exposes source file location... | |
| CVE-2026-100676 json | January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG <ima... | |
| CVE-2026-100675 json | stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes mass ... | |
| CVE-2026-100674 json | stoatchat before 0.15.5 fails to revalidate usernames after Unicode sanitization, allowing attackers to create usernames with... | |
| CVE-2026-100673 json | The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the... | |
| CVE-2026-100672 json | The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that return... | |
| CVE-2026-100671 json | Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig ... | |
| CVE-2026-100670 json | Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access ... | |
| CVE-2026-100669 json | Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In we... | |
| CVE-2026-100668 json | Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) is on t... | |
| CVE-2026-100667 json | grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and < 3.9.7 allow the two-factor authentication challenge to ... | |
| CVE-2026-100666 json | Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to and in... | |
| CVE-2026-100665 json | Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate ... | |
| CVE-2026-100664 json | Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority pseu... | |
| CVE-2026-100663 json | Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT ... | |
| CVE-2026-100662 json | Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource ... | |
| CVE-2026-100661 json | Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulne... | |
| CVE-2026-100660 json | Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK en... | |
| CVE-2026-100659 json | Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC 9114 ... | |
| CVE-2026-100658 json | Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue in WebSocketServerExtensionHandler. The handler ... | |
| CVE-2026-100657 json | Netty's STOMP codec (io.netty:netty-codec-stomp) contains a ByteBuf leak in StompSubframeDecoder. Once a frame's declared con... | |
| CVE-2026-100656 json | Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServerCodec. The codec tracks... | |
| CVE-2026-100655 json | Netty (io.netty:netty-codec-http) versions up to and including 4.1.137.Final and from 4.2.0.Final through 4.2.17.Final accept... | |
| CVE-2026-100654 json | vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/chat/com... | |
| CVE-2026-100653 json | vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-suppl... | |
| CVE-2026-100652 json | vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC frontends... | |
| CVE-2026-100651 json | vLLM before 0.29.0 fails to enforce decoder prompt-length validation on the disaggregated serving endpoint /inference/v1/gene... | |
| CVE-2026-100650 json | vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls (the... | |
| CVE-2026-100649 json | vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler subclass... | |
| CVE-2026-100648 json | vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing unauthe... | |
| CVE-2026-100647 json | vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-compatib... | |
| CVE-2026-100646 json | SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authenticat... | |
| CVE-2026-100645 json | SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database rendere... | |
| CVE-2026-100644 json | SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath parameter... | |
| CVE-2026-100643 json | SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authen... | |
| CVE-2026-100642 json | SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pas... | |
| CVE-2026-100641 json | SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list m... | |
| CVE-2026-100640 json | SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows remote-kernel renderers to ... | |
| CVE-2026-100639 json | SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutter/bu... | |
| CVE-2026-100638 json | SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticate... | |
| CVE-2026-100637 json | SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated a... | |
| CVE-2026-100636 json | SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authentica... | |
| CVE-2026-100635 json | SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are issued ... | |
| CVE-2026-100634 json | SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the Elec... | |
| CVE-2026-100633 json | SiYuan is a self-hosted personal knowledge management system. In versions 3.8.0 through 3.8.3, the MCP file tool's sensitive-... | |
| CVE-2026-100632 json | Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery... |