CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-107914 json Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a c...
CVE-2026-107911 json A type confusion vulnerability in the _read_flags function (src/commands/cmd_dispatcher.c) in FalkorDB before 4.20.0 allows a...
CVE-2026-107910 json An improper authentication vulnerability in the is_authenticated function (src/bolt/bolt_api.c) in FalkorDB before 4.20.0 all...
CVE-2026-107909 json A heap-based out-of-bounds write in the ws_read_frame function (src/bolt/ws.c) and the buffer_apply_mask function (src/bolt/b...
CVE-2026-107908 json A heap-based out-of-bounds write in the BoltReadHandler function (src/bolt/bolt_api.c) in FalkorDB before 4.20.0 allows a rem...
CVE-2026-87110 json An unauthenticated user with network access to the Ops Manager web port can repeatedly request monitoring endpoints that perf...
CVE-2026-87109 json An authenticated Ops Manager organization member can retrieve another member's pending authenticator enrollment seed through ...
CVE-2026-87108 json An authenticated Ops Manager user with a read-only project role can retrieve a daily host monitoring record associated with a...
CVE-2026-7827 json A stack-based buffer overflow in the _RdbLoadEntity function of the RDB graph decoders (src/serializers/decoders/*/decode_gra...
CVE-2026-7826 json A heap-based out-of-bounds read in the BufferSerializerIOv2_ReadBuffer function (src/serializers/serializer_io.c) in FalkorDB...
CVE-2026-5759 json A double free and use-after-free vulnerability in the RdbLoadDeletedNodes function of the RDB graph decoders (src/serializers...
CVE-2026-107890 json OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference caused by repeated IPP group tags in job-creation request...
CVE-2026-107889 json A flaw was found in the login theme rendering component of Keycloak. The issue occurs because the security filter responsible...
CVE-2026-107888 json OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference in cupsdCheckJobs() when a job marked job-held-on-create ...
CVE-2025-6170 json A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an...
CVE-2026-107886 json OpenPrinting CUPS before 2.4.20 contains a double-free in printer-class management. When CUPS-Add-Modify-Class replaces an ex...
CVE-2026-107885 json OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission-timeout handling of cupsdChec...
CVE-2026-106177 json A kernel buffer overflow vulnerability in HP Sure Click versions prior to 4.4.33 may allow local privilege escalation or arbi...
CVE-2026-105331 json Local privilege escalation in Checkmk 2.5.0 before 2.5.0p10 allows a user with access to edit the Oracle Instant Client refer...
CVE-2026-94586 json A command injection vulnerability exists in the WebTools administrative interface handling configuration download or file tra...
CVE-2026-94581 json An OS command injection vulnerability exists in the REST API management interface of Brocade Fabric OS versions before 9.2.2d...
CVE-2026-94577 json A privilege escalation vulnerability exists in the internal Command-Line Interface (CLI) authorization handling mechanism of ...
CVE-2026-87687 json An authorization and input validation vulnerability exists in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10....
CVE-2026-87685 json An arbitrary file manipulation vulnerability exists in the WebTools management interface of Brocade Fabric OS versions before...
CVE-2026-87675 json An OS command injection vulnerability exists in the configuration management subsystem of Brocade Fabric OS versions before 9...
CVE-2026-87664 json A session context forgery vulnerability exists in the web management daemon of Brocade Fabric OS versions 9.2.2d and 10.0.0 t...
CVE-2026-87663 json An authentication bypass and command injection vulnerability exists in the inter-switch remote execution service of Brocade F...
CVE-2026-87662 json Brocade Fabric versions before 9.2.2d and 10.0.0 through 10.0.0a1 handling of specific download protocols utilizes unsanitize...
CVE-2026-16340 json IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11....
CVE-2026-16181 json IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11....
CVE-2026-15784 json IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11....
CVE-2026-15781 json IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11....
CVE-2026-15762 json IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11....
CVE-2026-14999 json IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11....
CVE-2026-14992 json IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11....
CVE-2026-14991 json IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11....
CVE-2026-14888 json IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11....
CVE-2026-14502 json IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11....
CVE-2026-14497 json IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11....
CVE-2026-14269 json IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11....
CVE-2026-105816 json Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference binaries within the confi...
CVE-2026-89322 json Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of resource and policy names...
CVE-2026-87674 json A local privilege escalation vulnerability exists in the system logging daemon of Brocade Fabric OS versions before 9.2.2d an...
CVE-2026-87673 json An OS command injection vulnerability exists in maintenance command-line diagnostic utilities on Brocade Fabric OS versions b...
CVE-2026-87666 json An OS command injection vulnerability exists in the time and zone management subsystem of Brocade Fabric OS versions before 9...
CVE-2026-76459 json As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conduct...
CVE-2026-76268 json In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representat...
CVE-2026-76266 json In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux, a local user who can run commands as the us...
CVE-2026-72693 json `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged conte...
CVE-2026-58015 json A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not...
CVE-2026-58014 json A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c f...
CVE-2026-15563 json A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an a...
CVE-2026-15555 json A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the J...
CVE-2024-3727 json A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated r...
CVE-2023-22894 json Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the q...
CVE-2021-3199 json Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is u...
CVE-2016-3081 json Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow ...
CVE-2015-5477 json named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUI...
CVE-2015-3306 json The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site ...
CVE-2026-107161 json A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes ...
CVE-2026-106061 json A flaw was found in GIMP’s X cursor (XMC) thumbnail loader. When GIMP generates a thumbnail for a crafted XMC file, it allo...
CVE-2026-93678 json IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to impr...
CVE-2026-46569 json In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attac...
CVE-2025-70522 json The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any s...
CVE-2025-70517 json The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any s...
CVE-2026-106587 json In sshd in OpenSSH before 10.6, the value "none" for a configuration option is sometimes interpreted as a filename but was in...
CVE-2026-106555 json In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication ...
CVE-2026-106508 json Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package i...
CVE-2026-106503 json Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-...
CVE-2026-106498 json Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/...
CVE-2026-106492 json Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults pa...
CVE-2026-106487 json Backstage is an open framework for building developer portals. Prior to 0.21.10, the @backstage/plugin-kubernetes-backend pac...
CVE-2026-106460 json Backstage is an open framework for building developer portals. From 0.3.0 until 0.6.15 and 0.7.5, the @backstage/plugin-auth-...
CVE-2026-106455 json Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-te...
CVE-2026-106450 json yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocate...
CVE-2026-106445 json Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProp...
CVE-2026-106440 json Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.0.dev10, the hydra-optuna...
CVE-2026-104046 json A flaw was found in SSSD (System Security Services Daemon). When Identity Provider (IdP) authentication is enabled, pre-authe...
CVE-2026-93448 json IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to impr...
CVE-2026-76061 json A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious c...
CVE-2026-63697 json Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged a...
CVE-2026-106422 json Incorrect authorization in API in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy ...
CVE-2026-106384 json Missing authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised ...
CVE-2026-106359 json Confused deputy in DeviceBoundSessionCredentials in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass ...
CVE-2026-106353 json Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging so...
CVE-2026-106289 json Missing authorization in FedCM in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy ...
CVE-2026-106261 json Uninitialized resource in Video in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory inside the s...
CVE-2026-106221 json Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social ...
CVE-2026-106216 json Cross-site request forgery in ReadingList in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker lev...
CVE-2026-106199 json Incorrect authorization in Actor in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had comp...
CVE-2026-106120 json LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2, enabling ownPropertyOnl...
CVE-2026-106115 json ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStri...
CVE-2026-106110 json ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compresse...
CVE-2026-106104 json Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.23.3, Platform.parseSSR() pa...
CVE-2026-105957 json A vulnerability was detected in SourceCodester Performance Indicator System 1.0. The affected element is an unknown function ...
CVE-2026-103778 json Dell Command | Configure (DCC), versions prior to 5.2.3.35 contain a Use of Hard-coded Cryptographic Key vulnerability. An un...
CVE-2026-106038 json Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allows unauthenticated attack...
CVE-2026-105920 json A vulnerability was determined in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The...
CVE-2026-105868 json Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4....
CVE-2026-105863 json Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom fie...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report