CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-94049 json A flaw has been found in 06ketan slideshot up to 4.4.0. This impacts the function render_slides of the file packages/cli/src/...
CVE-2026-94048 json A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the fil...
CVE-2026-94047 json A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32. The impacted element is the function importTemp...
CVE-2026-94046 json A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8. The affected element is the function get_file_snippet ...
CVE-2026-94045 json A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0. Impacted is an unknown function of the file contro...
CVE-2026-94044 json A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affects th...
CVE-2026-94043 json A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/f...
CVE-2026-94042 json A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This...
CVE-2026-94041 json A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c....
CVE-2026-88857 json Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Jo...
CVE-2026-88856 json Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Jo...
CVE-2026-88855 json Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6...
CVE-2026-88854 json Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The...
CVE-2026-94040 json A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderAction of...
CVE-2026-94039 json A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/in...
CVE-2026-94038 json A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of the fil...
CVE-2026-94037 json A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405. This affects t...
CVE-2026-94036 json A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an ...
CVE-2026-94035 json A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file ...
CVE-2026-94034 json A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the...
CVE-2026-94033 json A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code of t...
CVE-2026-94032 json A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown part of the file /module/departmen...
CVE-2026-94031 json A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914. Affected by this issue is the ...
CVE-2026-94030 json A security vulnerability has been detected in SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c. Affected by this vul...
CVE-2026-92965 json The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied...
CVE-2026-92541 json The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its ...
CVE-2026-92540 json The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capabili...
CVE-2026-92423 json The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesti...
CVE-2026-92422 json The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into ...
CVE-2026-92410 json The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion...
CVE-2026-87840 json The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative booking-...
CVE-2026-87839 json The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the ob...
CVE-2026-87068 json The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a regist...
CVE-2026-87067 json The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialis...
CVE-2026-85017 json The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and...
CVE-2026-84223 json The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, allowin...
CVE-2026-82842 json The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming singl...
CVE-2026-81654 json The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capabil...
CVE-2026-81653 json The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image own...
CVE-2026-81652 json The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled...
CVE-2026-81651 json The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns ...
CVE-2026-81650 json The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files ...
CVE-2026-87963 json The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using ...
CVE-2026-16542 json The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesti...
CVE-2026-14844 json The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before outpu...
CVE-2026-94028 json A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the file...
CVE-2026-94016 json A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the...
CVE-2026-94015 json A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file...
CVE-2026-92254 json Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver ...
CVE-2026-92253 json Improper link resolution before file access in the quarantine restoration process of WatchDog Anti-Virus 1.8.640 on Windows a...
CVE-2026-92252 json Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows allow local, low-privileged use...
CVE-2026-90817 json An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing...
CVE-2026-94113 json Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whiteliste...
CVE-2026-94112 json mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes...
CVE-2026-94111 json Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin valid...
CVE-2026-94109 json openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to ...
CVE-2026-94108 json getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to ...
CVE-2026-94107 json NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates...
CVE-2026-94106 json getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in co...
CVE-2026-94105 json NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller that a...
CVE-2026-94104 json NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to val...
CVE-2026-94004 json A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_js.php...
CVE-2026-94003 json A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bi...
CVE-2026-93997 json A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown funct...
CVE-2026-93980 json A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown code of ...
CVE-2026-93979 json A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of the fi...
CVE-2026-93978 json A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown func...
CVE-2026-93977 json A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown funct...
CVE-2026-13577 json Dancer2 versions before 2.2.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dancer2::...
CVE-2026-93976 json A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/add-u...
CVE-2026-93975 json A vulnerability has been found in code-projects Assessment Management 1.0. This impacts an unknown function of the file admin...
CVE-2026-86555 json The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext ...
CVE-2026-86554 json SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. W...
CVE-2026-86553 json SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using t...
CVE-2026-86552 json SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired...
CVE-2026-93974 json A flaw has been found in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /...
CVE-2026-93973 json A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown func...
CVE-2026-93972 json A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is a...
CVE-2026-93971 json A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevops/se...
CVE-2026-93970 json A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file bac...
CVE-2026-93969 json A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuse...
CVE-2026-93968 json A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/seria...
CVE-2026-93967 json A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this issue is the function generate_host_task of the fil...
CVE-2026-93966 json A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this vulnerability is the function paramiko.SSHClie...
CVE-2026-93965 json A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/serv...
CVE-2026-93964 json A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertifi...
CVE-2026-93963 json A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function of t...
CVE-2026-93962 json A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_mallo...
CVE-2026-93961 json A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of the ...
CVE-2026-93960 json A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Control...
CVE-2026-88097 json Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
CVE-2026-93959 json A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown proce...
CVE-2026-94084 json Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.respon...
CVE-2026-94083 json Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is e...
CVE-2026-93958 json A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi o...
CVE-2026-93957 json A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function SearchEngine::matchesSingleFilter...
CVE-2026-86551 json The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by qu...
CVE-2026-90971 json Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows ...
CVE-2026-90969 json Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticat...
CVE-2026-88922 json The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompressi...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report