CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-90615 json A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown p...
CVE-2026-90614 json A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of ...
CVE-2026-90613 json A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfo...
CVE-2026-90612 json A vulnerability was identified in GPAC up to f1219cde. Affected is the function gf_sm_dump_command_list of the file scene_man...
CVE-2026-90611 json A vulnerability was determined in GPAC up to f1219cde. This impacts the function xmt_parse_element of the file scene_manager/...
CVE-2026-90610 json A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg...
CVE-2026-33964 json An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs w...
CVE-2026-33963 json An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A st...
CVE-2026-33962 json An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malf...
CVE-2026-33960 json An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, a...
CVE-2026-33957 json An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the...
CVE-2026-33956 json An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a malfor...
CVE-2026-31278 json An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 al...
CVE-2026-23793 json An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, and 2400. An out-of-bounds memory access vulnera...
CVE-2026-23792 json An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400...
CVE-2026-23791 json An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A...
CVE-2026-23790 json An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A...
CVE-2026-23789 json An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1...
CVE-2026-23788 json An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR...
CVE-2026-23787 json An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A...
CVE-2026-23786 json An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A...
CVE-2026-90609 json A vulnerability has been found in GPAC up to f1219cde. The impacted element is an unknown function of the file scenegraph/vrm...
CVE-2026-90608 json A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boa...
CVE-2026-90607 json A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boa...
CVE-2025-68624 json N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to se...
CVE-2025-64031 json libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to a...
CVE-2026-90606 json A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Set...
CVE-2026-90605 json A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of t...
CVE-2026-90604 json A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anch...
CVE-2025-63842 json A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authe...
CVE-2024-53922 json An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack o...
CVE-2022-42917 json In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configurati...
CVE-2026-90603 json A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown f...
CVE-2026-90602 json A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the fu...
CVE-2026-90601 json A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/m...
CVE-2026-90600 json A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /...
CVE-2026-15892 json The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in ...
CVE-2026-15891 json The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PING...
CVE-2026-90599 json A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an...
CVE-2026-90598 json A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The...
CVE-2026-90597 json A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown...
CVE-2026-90596 json A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_r...
CVE-2026-52297 json FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_r...
CVE-2026-52296 json FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcod...
CVE-2026-52295 json FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based a...
CVE-2026-49030 json Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Furt...
CVE-2026-35867 json A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK ro...
CVE-2026-90595 json A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineContr...
CVE-2026-90594 json A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function Permissi...
CVE-2026-90593 json A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the fi...
CVE-2026-90584 json A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameCo...
CVE-2026-89050 json The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured...
CVE-2026-88802 json The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do n...
CVE-2026-88793 json The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, rel...
CVE-2026-85129 json The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, ...
CVE-2026-81648 json The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpo...
CVE-2026-74933 json The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX act...
CVE-2026-38332 json TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea len...
CVE-2026-37008 json CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnera...
CVE-2026-36989 json A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php.
CVE-2026-36453 json Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra varia...
CVE-2026-90583 json A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected eleme...
CVE-2026-90582 json A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/in...
CVE-2026-90581 json A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate o...
CVE-2026-90580 json A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file pa...
CVE-2026-29812 json CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.
CVE-2026-29811 json CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary...
CVE-2026-29810 json CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.
CVE-2025-70820 json Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.
CVE-2025-70819 json Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volum...
CVE-2026-90579 json A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key ...
CVE-2026-90578 json A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c o...
CVE-2026-90577 json A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the ...
CVE-2026-90576 json A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of the fil...
CVE-2025-64059 json Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is dispu...
CVE-2025-45480 json Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.
CVE-2020-15875 json An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the informat...
CVE-2026-90575 json A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php ...
CVE-2026-90574 json A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the f...
CVE-2026-90573 json A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scene...
CVE-2026-90572 json A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient::opU...
CVE-2026-90571 json A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of ...
CVE-2026-90570 json A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoo...
CVE-2026-90569 json A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicContr...
CVE-2026-90568 json A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of ...
CVE-2026-90567 json A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highl...
CVE-2026-90566 json A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affect...
CVE-2026-90565 json A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. A...
CVE-2026-90564 json A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMsgLis...
CVE-2026-90563 json A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the file Art...
CVE-2026-90529 json A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the ...
CVE-2026-90528 json A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the...
CVE-2026-90527 json A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src...
CVE-2026-90526 json A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown ...
CVE-2026-90525 json A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /...
CVE-2026-90524 json A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af0...
CVE-2026-90523 json A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. Th...
CVE-2026-90783 json MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to intege...
CVE-2026-90782 json S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() wh...
CVE-2026-90781 json alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one by...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report