CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-75860 json | The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its action... | |
| CVE-2026-74992 json | The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with th... | |
| CVE-2026-23903 json | Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users... | |
| CVE-2026-19699 json | The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, al... | |
| CVE-2026-19697 json | The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allow... | |
| CVE-2026-19615 json | The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it ac... | |
| CVE-2026-18917 json | A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePag... | |
| CVE-2026-15049 json | The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through i... | |
| CVE-2026-13601 json | A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A mal... | |
| CVE-2026-13405 json | The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writ... | |
| CVE-2026-77014 json | A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c... | |
| CVE-2026-76610 json | Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ... | |
| CVE-2026-14953 json | A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges usin... | |
| CVE-2026-14952 json | An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBac... | |
| CVE-2026-14951 json | An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using ... | |
| CVE-2026-14950 json | An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it... | |
| CVE-2026-14949 json | A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through... | |
| CVE-2026-14948 json | A low privileged remote attacker can hijack an active administrative session without needing to know the administrator passwo... | |
| CVE-2026-14947 json | A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can e... | |
| CVE-2026-14946 json | A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve... | |
| CVE-2026-76569 json | Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4 | |
| CVE-2026-76565 json | Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7 | |
| CVE-2026-76564 json | Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7 | |
| CVE-2026-75948 json | Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form... | |
| CVE-2026-18963 json | A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and ... | |
| CVE-2025-14601 json | An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute ar... | |
| CVE-2026-71368 json | F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected produ... | |
| CVE-2026-14163 json | In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in th... | |
| CVE-2025-14602 json | The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows... | |
| CVE-2026-75963 json | The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 v... | |
| CVE-2026-73542 json | Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacke... | |
| CVE-2026-17153 json | The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1... | |
| CVE-2024-53920 json | In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on un... | |
| CVE-2026-76957 json | libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOT... | |
| CVE-2026-76956 json | In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which ... | |
| CVE-2026-19582 json | In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could execute arbitrary code unkno... | |
| CVE-2026-72530 json | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to... | |
| CVE-2026-72529 json | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to... | |
| CVE-2026-71176 json | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL C... | |
| CVE-2026-48711 json | SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SSHFS accepts a bracketed m... | |
| CVE-2026-47187 json | SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return ab... | |
| CVE-2026-23501 json | Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS ... | |
| CVE-2026-20315 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team h... | |
| CVE-2026-20231 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team h... | |
| CVE-2026-16885 json | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer o... | |
| CVE-2026-16816 json | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due t... | |
| CVE-2026-16814 json | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer ov... | |
| CVE-2026-16703 json | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privil... | |
| CVE-2026-16656 json | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentic... | |
| CVE-2026-76221 json | GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to ... | |
| CVE-2026-76220 json | GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by ... | |
| CVE-2026-76218 json | GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without ... | |
| CVE-2026-70421 json | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileg... | |
| CVE-2026-58088 json | The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding program header... | |
| CVE-2026-58087 json | The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protecting ... | |
| CVE-2026-58083 json | While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on the kqueue's... | |
| CVE-2026-54796 json | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Co... | |
| CVE-2026-54795 json | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Co... | |
| CVE-2026-49429 json | The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit integer for the... | |
| CVE-2026-49428 json | Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage ob... | |
| CVE-2026-49427 json | Pages belonging to largepage shared memory objects were not explicitly wired. When sendfile(2) transmitted such an object wi... | |
| CVE-2026-49422 json | The RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace, then reacquires the loc... | |
| CVE-2026-49420 json | The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewritten... | |
| CVE-2026-49419 json | When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller's current p... | |
| CVE-2026-19490 json | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through ... | |
| CVE-2026-15078 json | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain unauthorized access to AIX systems du... | |
| CVE-2026-15068 json | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands d... | |
| CVE-2026-15065 json | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the ex... | |
| CVE-2026-76047 json | Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the ... | |
| CVE-2026-76046 json | Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised... | |
| CVE-2026-76045 json | Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside t... | |
| CVE-2026-76044 json | Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer pro... | |
| CVE-2026-76043 json | Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code insi... | |
| CVE-2026-76040 json | Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engi... | |
| CVE-2026-76038 json | Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the ... | |
| CVE-2026-76037 json | Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to poten... | |
| CVE-2026-76036 json | Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary... | |
| CVE-2026-76035 json | Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to execute... | |
| CVE-2026-76034 json | Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside... | |
| CVE-2026-73920 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-71167 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-71166 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-49418 json | When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping range are m... | |
| CVE-2026-49415 json | During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are updated. Du... | |
| CVE-2026-21584 json | This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, an... | |
| CVE-2026-21582 json | This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in ... | |
| CVE-2026-71062 json | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Dif... | |
| CVE-2026-70951 json | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Document Management). Supported versions t... | |
| CVE-2026-70949 json | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versio... | |
| CVE-2026-70859 json | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affe... | |
| CVE-2026-70857 json | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affe... | |
| CVE-2026-70856 json | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supported versions that are ... | |
| CVE-2026-62596 json | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions t... | |
| CVE-2026-62595 json | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions t... | |
| CVE-2026-62593 json | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions t... | |
| CVE-2026-62592 json | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions t... | |
| CVE-2026-62591 json | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions t... | |
| CVE-2026-62590 json | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions t... | |
| CVE-2026-62589 json | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions t... | |
| CVE-2026-62588 json | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions t... |