CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-60152 json Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported ...
CVE-2026-47051 json Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported version...
CVE-2026-47049 json Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Suppor...
CVE-2026-66759 json A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin ...
CVE-2026-66758 json A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation ...
CVE-2026-66757 json A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for...
CVE-2026-66031 json Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticate...
CVE-2026-66030 json Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticate...
CVE-2026-66028 json Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authentica...
CVE-2026-64647 json Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through ...
CVE-2026-64646 json Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through ...
CVE-2026-64644 json Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through ...
CVE-2026-64643 json Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through ...
CVE-2026-64641 json Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through ...
CVE-2026-59239 json Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authentica...
CVE-2026-55579 json Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships ...
CVE-2026-54540 json Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated terminal ...
CVE-2026-51244 json schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in UnpackFrameHeader(). Multiple attacker-controlled in...
CVE-2026-51235 json LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch() function (src/libraw_cxx.cpp) and fuji_rotate() function (src/d...
CVE-2026-48052 json Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who is a m...
CVE-2026-48030 json Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command I...
CVE-2026-17612 json Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains an ...
CVE-2026-16481 json A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page...
CVE-2026-12383 json A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (pe...
CVE-2026-10683 json In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handler ga...
CVE-2026-10682 json The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a signed...
CVE-2026-66730 json facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthent...
CVE-2026-66474 json Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.
CVE-2026-66434 json Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.
CVE-2026-66397 json phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowin...
CVE-2026-66391 json Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache ...
CVE-2026-66390 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This is...
CVE-2026-59251 json Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated a...
CVE-2026-59250 json Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt th...
CVE-2026-55953 json The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in Serv...
CVE-2026-55737 json Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can suppl...
CVE-2026-54890 json Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) ...
CVE-2026-51303 json A use-after-free (UAF) vulnerability was discovered in the core parsing component of SQLite 3.41. The flaw occurs because the...
CVE-2026-51298 json sqlite 3.41 is vulnerable to use after free in the JSON extraction function. After releasing JsonParse object memory via json...
CVE-2026-51297 json sqlite 3.41 has a use-after-free vulnerability in the JSON parsing logic. Remote adversaries can craft malicious JSON payload...
CVE-2026-47078 json Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extraction ...
CVE-2026-17574 json HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invali...
CVE-2026-17572 json Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attacker...
CVE-2026-17570 json Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged us...
CVE-2026-17530 json A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _buil...
CVE-2026-65564 json Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
CVE-2026-65436 json Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.
CVE-2026-64796 json Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the ar...
CVE-2026-63685 json Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement req...
CVE-2026-63683 json Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP condi...
CVE-2026-63280 json Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - C...
CVE-2026-63265 json Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX...
CVE-2026-59558 json Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
CVE-2026-59550 json Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
CVE-2026-59537 json Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions.
CVE-2026-59531 json Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
CVE-2026-17527 json In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access t...
CVE-2026-65595 json n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of...
CVE-2026-65594 json n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was intr...
CVE-2026-65590 json n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/compu...
CVE-2026-60605 json Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Higher Ed Statistics A...
CVE-2026-60580 json Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The s...
CVE-2026-65015 json n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution too...
CVE-2026-65014 json n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint be...
CVE-2026-47632 json Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent...
CVE-2026-62464 json Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions ...
CVE-2026-61250 json Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll). Supported versions that are aff...
CVE-2026-61216 json Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll). Supported versions that are aff...
CVE-2026-61142 json Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions ...
CVE-2026-60750 json Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions ...
CVE-2026-66029 json Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticate...
CVE-2026-66731 json facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that...
CVE-2026-66729 json facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauth...
CVE-2026-64645 json Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through ...
CVE-2026-64642 json Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests t...
CVE-2026-55578 json Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the terminal fe...
CVE-2026-54272 json ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 ar...
CVE-2026-48051 json Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, Papra's webhook delivery system ...
CVE-2026-45623 json PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Synta...
CVE-2026-17569 json Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permissi...
CVE-2026-17568 json Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administ...
CVE-2026-17552 json Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation...
CVE-2026-66412 json Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone dat...
CVE-2026-66396 json SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover im...
CVE-2026-66394 json SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authe...
CVE-2026-63077 json In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling pro...
CVE-2026-58227 json The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS o...
CVE-2026-51304 json sqlite 3.41 has a use-after-free (UAF) vulnerability in the ORDER BY clause parsing routine. The affected code first releases...
CVE-2026-42792 json Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker...
CVE-2026-24252 json NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this...
CVE-2026-17573 json A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk ...
CVE-2026-17500 json A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file comm...
CVE-2026-17192 json A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated t...
CVE-2026-17191 json An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw...
CVE-2026-16812 json VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged i...
CVE-2026-14827 json The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside ...
CVE-2026-14820 json The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login au...
CVE-2026-14568 json The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPres...
CVE-2026-14289 json The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers,...
CVE-2026-14236 json The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as t...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report