CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-70328 json Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-70327 json Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-70318 json Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-68817 json Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68816 json Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68815 json Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68814 json Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68813 json Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-68812 json Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-33167 json Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1...
CVE-2026-2072 json Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Cente...
CVE-2026-1166 json Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops Center Administrator: from 10....
CVE-2026-68795 json Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68794 json Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68793 json Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-65807 json Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to ex...
CVE-2026-6245 json A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM pas...
CVE-2026-2336 json A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-d...
CVE-2025-9497 json Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issu...
CVE-2026-73325 json Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to exe...
CVE-2026-73294 json Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling pas...
CVE-2026-73293 json Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, Proje...
CVE-2026-73292 json Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a ...
CVE-2026-70547 json An authenticated user without repository read permission may access package metadata under specific conditions.
CVE-2026-69107 json An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
CVE-2026-69105 json An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting...
CVE-2026-68971 json Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `...
CVE-2026-68970 json Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape...
CVE-2026-68969 json Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted t...
CVE-2026-68968 json Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path se...
CVE-2026-68759 json A holder of a valid integration credential may impersonate other users under specific conditions.
CVE-2026-68758 json A low-privileged authenticated user may access restricted support information under specific conditions.
CVE-2026-68076 json Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's sco...
CVE-2026-67587 json Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the m...
CVE-2026-67260 json Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the sched...
CVE-2026-66384 json An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CVE-2026-66016 json Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible t...
CVE-2026-65941 json In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected se...
CVE-2026-65940 json In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible locati...
CVE-2026-65939 json In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitra...
CVE-2026-65938 json In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API all...
CVE-2026-65937 json In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persiste...
CVE-2026-65926 json An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle...
CVE-2026-65017 json Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an admini...
CVE-2026-64639 json Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (custome...
CVE-2026-59244 json
CVE-2026-59242 json Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through...
CVE-2026-58076 json Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from th...
CVE-2026-73290 json RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request ...
CVE-2026-54183 json Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's...
CVE-2026-19548 json Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld),...
CVE-2026-15803 json In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing unt...
CVE-2025-35988 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2025-35977 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2025-32737 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2025-32087 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2025-32084 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2025-31943 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2025-30178 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2025-27570 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2025-27245 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2025-25275 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2025-24837 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2025-24488 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2025-20020 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2026-73286 json RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attack...
CVE-2026-73264 json Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access co...
CVE-2026-73263 json Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content co...
CVE-2026-71845 json A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, inc...
CVE-2026-70345 json Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-70336 json Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute co...
CVE-2026-70322 json Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70317 json Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-68756 json A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
CVE-2026-67558 json The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against ...
CVE-2026-53996 json NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivile...
CVE-2026-49262 json In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulne...
CVE-2026-47231 json Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-changi...
CVE-2026-47227 json Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`...
CVE-2026-14479 json A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an...
CVE-2026-14478 json A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject ...
CVE-2026-70312 json Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70304 json Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-68821 json Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-68801 json Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68800 json Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68799 json Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-68797 json Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-68796 json Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-66804 json Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
CVE-2026-65806 json Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
CVE-2026-65783 json Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
CVE-2026-65672 json Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
CVE-2026-65671 json Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
CVE-2026-64922 json Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an...
CVE-2026-63521 json Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-62901 json Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-62793 json Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-62786 json Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-62781 json Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report