CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-18874 json A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Mar...
CVE-2026-4878 json A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in t...
CVE-2025-5318 json A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handl...
CVE-2025-4373 json A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the posi...
CVE-2026-76827 json A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with o...
CVE-2026-75485 json A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object...
CVE-2026-73834 json A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Cust...
CVE-2026-71846 json A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets g...
CVE-2026-71845 json A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, inc...
CVE-2026-71475 json A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into ...
CVE-2026-71474 json A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can...
CVE-2026-71468 json A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuse...
CVE-2026-64927 json A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to...
CVE-2026-54100 json A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH...
CVE-2026-54099 json A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-ap...
CVE-2025-7425 json A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory manage...
CVE-2025-6020 json A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allow...
CVE-2025-5914 json A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() fu...
CVE-2025-5278 json A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The prog...
CVE-2025-2842 json A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed b...
CVE-2025-2786 json A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploy...
CVE-2026-76139 json A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote sourc...
CVE-2026-73267 json A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions t...
CVE-2026-73266 json A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit ...
CVE-2026-66795 json A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperl...
CVE-2026-66794 json A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an u...
CVE-2026-19130 json A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific perm...
CVE-2026-73269 json A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a spec...
CVE-2026-73268 json A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update per...
CVE-2026-17107 json A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHA...
CVE-2026-16242 json A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was star...
CVE-2026-10090 json A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster...
CVE-2026-10059 json A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-s...
CVE-2026-86145 json PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA...
CVE-2026-78408 json The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later...
CVE-2026-4740 json A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Impro...
CVE-2026-86197 json Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss ...
CVE-2026-86196 json Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpo...
CVE-2026-86195 json grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the st...
CVE-2026-86194 json Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymo...
CVE-2026-86193 json grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-sup...
CVE-2026-86192 json SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint...
CVE-2026-86191 json SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that a...
CVE-2026-86190 json WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records inc...
CVE-2026-86189 json WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write ...
CVE-2026-86188 json AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to exec...
CVE-2026-86187 json WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only...
CVE-2026-86186 json AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight pro...
CVE-2026-50237 json A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant...
CVE-2026-50236 json An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetc...
CVE-2026-42965 json A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a...
CVE-2026-1784 json The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that...
CVE-2026-86185 json Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript co...
CVE-2026-86184 json Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthe...
CVE-2026-49332 json A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forw...
CVE-2026-46579 json A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend do...
CVE-2026-15550 json The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including,...
CVE-2026-12843 json The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the p...
CVE-2026-10196 json The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PH...
CVE-2025-15647 json CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge interse...
CVE-2025-15614 json ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive ...
CVE-2025-9049 json The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2026-86178 json Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing aut...
CVE-2026-86177 json Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers w...
CVE-2026-86176 json NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscr...
CVE-2026-86175 json NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticat...
CVE-2026-86174 json Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authen...
CVE-2026-86173 json MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenti...
CVE-2026-86169 json Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code def...
CVE-2026-85665 json Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary l...
CVE-2026-85604 json Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The ...
CVE-2026-85602 json The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based ...
CVE-2026-85600 json Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml()...
CVE-2026-85599 json Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [detai...
CVE-2026-85598 json Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editor...
CVE-2026-85597 json Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthe...
CVE-2026-85596 json Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS ...
CVE-2026-85595 json Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the di...
CVE-2026-86124 json AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and ...
CVE-2026-86123 json SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute a...
CVE-2026-86122 json Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitra...
CVE-2026-86121 json Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind...
CVE-2026-86120 json APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce...
CVE-2026-86119 json Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video...
CVE-2026-86118 json gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated ...
CVE-2026-86117 json Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into ex...
CVE-2026-86116 json Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authen...
CVE-2026-86115 json Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SS...
CVE-2026-86114 json Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, mo...
CVE-2026-86113 json BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authentica...
CVE-2026-86112 json BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authentic...
CVE-2026-86111 json BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated atta...
CVE-2026-76573 json The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'not_found...
CVE-2024-11080 json The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in ve...
CVE-2026-85414 json The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode At...
CVE-2026-83625 json The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all ...
CVE-2026-81543 json The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and ...
CVE-2026-75586 json The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[id]' ...
CVE-2026-75018 json The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.1...
CVE-2026-84937 json The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before ...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report