CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-57097 json | Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack. | |
| CVE-2026-50346 json | Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-50345 json | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an auth... | |
| CVE-2026-50339 json | Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to dis... | |
| CVE-2026-49216 json | Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-au... | |
| CVE-2026-50337 json | Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-63429 json | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no globa... | |
| CVE-2026-63428 json | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id, name... | |
| CVE-2026-63102 json | rConfig before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles ... | |
| CVE-2026-51027 json | An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component. | |
| CVE-2026-51026 json | Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a craft... | |
| CVE-2026-48824 json | Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-4... | |
| CVE-2026-46671 json | Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciously c... | |
| CVE-2026-46428 json | lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in le... | |
| CVE-2026-46415 json | The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's I... | |
| CVE-2026-46412 json | @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Bet... | |
| CVE-2026-45797 json | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated file u... | |
| CVE-2026-45713 json | Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSiz... | |
| CVE-2026-45712 json | Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…... | |
| CVE-2026-45711 json | Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <out-dir... | |
| CVE-2026-45709 json | Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Reques... | |
| CVE-2026-35198 json | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the... | |
| CVE-2026-32822 json | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycl... | |
| CVE-2026-32807 json | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycl... | |
| CVE-2026-28220 json | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues... | |
| CVE-2026-6793 json | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consu... | |
| CVE-2026-63763 json | SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged us... | |
| CVE-2026-63757 json | SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attache... | |
| CVE-2026-63751 json | SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allows au... | |
| CVE-2026-59238 json | Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderAuditD... | |
| CVE-2026-57857 json | The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooComme... | |
| CVE-2026-57310 json | Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker who ... | |
| CVE-2026-57309 json | A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL... | |
| CVE-2026-54910 json | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpo... | |
| CVE-2026-45270 json | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module regi... | |
| CVE-2026-27823 json | A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authentic... | |
| CVE-2026-26199 json | HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is i... | |
| CVE-2026-26197 json | HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is corrupte... | |
| CVE-2026-26081 json | HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ... | |
| CVE-2026-26080 json | HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy En... | |
| CVE-2026-25039 json | Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize t... | |
| CVE-2026-21824 json | HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal d... | |
| CVE-2026-16252 json | A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System 8.2.2... | |
| CVE-2026-13724 json | Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Tra... | |
| CVE-2026-12973 json | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one... | |
| CVE-2026-12972 json | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one... | |
| CVE-2026-12970 json | The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute,... | |
| CVE-2026-12898 json | The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before ... | |
| CVE-2026-12724 json | The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request... | |
| CVE-2026-12723 json | The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauth... | |
| CVE-2026-12228 json | A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest... | |
| CVE-2026-56741 json | JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-teln... | |
| CVE-2026-47871 json | VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authent... | |
| CVE-2026-47870 json | VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access ma... | |
| CVE-2026-47869 json | VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access m... | |
| CVE-2026-47868 json | VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able ... | |
| CVE-2026-47867 json | VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to ... | |
| CVE-2026-47866 json | VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limite... | |
| CVE-2026-47865 json | VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to... | |
| CVE-2026-16158 json | Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenat... | |
| CVE-2026-16150 json | A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the function extendDefaults/extend... | |
| CVE-2026-16127 json | A vulnerability was identified in zevorn rt-claw up to 0.2.0. This affects the function claw_net_get/claw_net_post of the fil... | |
| CVE-2026-16121 json | A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file intern... | |
| CVE-2026-16117 json | Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is... | |
| CVE-2026-16088 json | A vulnerability was detected in halo-dev halo up to 2.24.2. Affected by this vulnerability is the function Download of the fi... | |
| CVE-2026-16077 json | A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. Impacted is the function _normalize_rw_path of the file astrbo... | |
| CVE-2026-15631 json | Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destinatio... | |
| CVE-2025-71397 json | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permission... | |
| CVE-2025-71391 json | SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users... | |
| CVE-2024-58366 json | SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting i... | |
| CVE-2024-58359 json | SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand()... | |
| CVE-2026-61643 json | FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can save... | |
| CVE-2026-55518 json | Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach... | |
| CVE-2026-54242 json | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image proxy's U... | |
| CVE-2026-52887 json | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0... | |
| CVE-2026-50274 json | Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monitoring... | |
| CVE-2026-50197 json | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent inte... | |
| CVE-2026-50163 json | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates... | |
| CVE-2026-49852 json | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. P... | |
| CVE-2026-48504 json | OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context i... | |
| CVE-2026-46485 json | Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or ... | |
| CVE-2026-44979 json | @hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname, only... | |
| CVE-2026-38755 json | A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service ... | |
| CVE-2026-38754 json | A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (... | |
| CVE-2026-38753 json | A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (... | |
| CVE-2026-38752 json | A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Se... | |
| CVE-2026-15415 json | AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure requi... | |
| CVE-2026-15091 json | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neu... | |
| CVE-2026-14979 json | IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Int... | |
| CVE-2025-45870 json | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class,... | |
| CVE-2026-62685 json | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified... | |
| CVE-2026-57956 json | SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organiza... | |
| CVE-2026-50148 json | Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.... | |
| CVE-2026-49997 json | SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. Prior to 3.1.0, Document::... | |
| CVE-2026-45806 json | Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import passed ... | |
| CVE-2026-0487 json | SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, all... | |
| CVE-2024-38093 json | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |
| CVE-2024-38083 json | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |
| CVE-2024-38082 json | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |
| CVE-2024-37325 json | Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability |