CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-80138 json ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell ...
CVE-2026-79912 json A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of...
CVE-2026-79911 json A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function set...
CVE-2026-70665 json Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. P...
CVE-2026-55805 json Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allo...
CVE-2026-54757 json Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions befor...
CVE-2026-44476 json Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered cl...
CVE-2026-41707 json Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing J...
CVE-2026-18985 json Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-plac...
CVE-2026-18261 json Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.
CVE-2026-18260 json Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*.
CVE-2026-18259 json Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Conte...
CVE-2026-16646 json Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.
CVE-2026-16645 json Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing...
CVE-2026-16644 json Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versio...
CVE-2026-16643 json Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.
CVE-2026-16642 json Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.
CVE-2026-16641 json Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
CVE-2026-16640 json Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autoc...
CVE-2026-16639 json Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows A...
CVE-2026-16638 json Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders al...
CVE-2026-15917 json Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allo...
CVE-2026-15916 json Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: ...
CVE-2026-78655 json Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier se...
CVE-2026-78619 json Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because t...
CVE-2026-19582 json In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could execute arbitrary code unkno...
CVE-2026-15089 json Vulnerability in Drupal Commerce guest registration. This issue affects Commerce guest registration versions: *.*.
CVE-2026-15088 json Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.
CVE-2026-80186 json A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetoo...
CVE-2026-80185 json BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceR...
CVE-2026-80184 json In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, applicati...
CVE-2026-80182 json In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authent...
CVE-2026-79845 json A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of the f...
CVE-2026-79804 json A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected b...
CVE-2026-73180 json Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session...
CVE-2026-68763 json Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when ...
CVE-2026-68569 json Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a use...
CVE-2026-68525 json Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security const...
CVE-2026-66422 json Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role a...
CVE-2026-65927 json Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to res...
CVE-2026-65905 json Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests...
CVE-2026-65637 json Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apac...
CVE-2026-65183 json Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an ...
CVE-2026-65182 json Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a cons...
CVE-2026-63404 json Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnera...
CVE-2026-63403 json Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the server is vulnerable to an unauthentic...
CVE-2026-62865 json Typebot is an open-source chatbot builder. In self-hosted versions prior to 3.18.0, the server-side Send Email integration bl...
CVE-2026-62862 json Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless email...
CVE-2026-62861 json TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenticated non-guest workspace member can remove another workspace...
CVE-2026-38474 json GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 suffers from a Broken access control vulnerabil...
CVE-2026-38473 json A Stored XSS vulnerability in the subtitle deletion flow in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864...
CVE-2026-38472 json A Stored XSS vulnerability in forum reward comments in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d1...
CVE-2026-38470 json A Broken access control vulnerability in the API user endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af4...
CVE-2026-38469 json A Stored XSS vulnerability in the custom bonus title feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a...
CVE-2026-38468 json A SQL injection vulnerability in the country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97...
CVE-2026-38467 json A SQL injection vulnerability in the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d184...
CVE-2026-38466 json A Stored XSS vulnerability in the torrent remaster custom title feature in GazellePW (GazellePosterWall) commit 86c4bedf72769...
CVE-2026-38465 json A Stored XSS vulnerability in the donor avatar mouse-over text feature in GazellePW (GazellePosterWall) commit 86c4bedf727691...
CVE-2026-32637 json Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. P...
CVE-2026-75569 json A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without perf...
CVE-2026-80104 json DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload di...
CVE-2026-80101 json A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validates the...
CVE-2026-79793 json A vulnerability has been found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown func...
CVE-2026-79792 json A flaw has been found in zackees transcribe-anything up to 4.1.0. Affected is the function ytdlp_download of the file src/tra...
CVE-2026-79293 json Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive informati...
CVE-2026-79292 json Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rend...
CVE-2026-79291 json Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via...
CVE-2026-79290 json Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside th...
CVE-2026-79289 json Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attac...
CVE-2026-79288 json Improper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to obta...
CVE-2026-79287 json Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive informa...
CVE-2026-79286 json Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potenti...
CVE-2026-79285 json Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtain cro...
CVE-2026-79284 json UI misrepresentation in Core in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised ...
CVE-2026-79283 json UI misrepresentation in Geometry in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a...
CVE-2026-79282 json Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary ...
CVE-2026-79276 json Improper privilege management in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging soci...
CVE-2026-79275 json Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside t...
CVE-2026-79274 json Information leak in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a c...
CVE-2026-79273 json Incorrect reference resolution in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to ...
CVE-2026-79272 json Improper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised...
CVE-2026-79271 json Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to ob...
CVE-2026-79270 json Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside the ...
CVE-2026-79269 json Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web o...
CVE-2026-79267 json Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer ...
CVE-2026-79266 json Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to...
CVE-2026-79265 json Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the ...
CVE-2026-79264 json Incorrect reference resolution in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web ori...
CVE-2026-79263 json Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code insi...
CVE-2026-79262 json Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin pol...
CVE-2026-79261 json Incorrect authorization in Controls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin po...
CVE-2026-79260 json Improper input validation in Cookies in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised th...
CVE-2026-79259 json Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system ...
CVE-2026-79258 json Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineer...
CVE-2026-79257 json Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside t...
CVE-2026-79256 json Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker wh...
CVE-2026-79255 json Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the...
CVE-2026-79254 json Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker ...
CVE-2026-79253 json Improper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveragi...
CVE-2026-79252 json Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin da...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report