CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-80177 json | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im... | |
| CVE-2026-80124 json | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an In... | |
| CVE-2026-80123 json | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Ser... | |
| CVE-2026-80055 json | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im... | |
| CVE-2026-79636 json | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im... | |
| CVE-2026-75927 json | The PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin for WordPress i... | |
| CVE-2026-58015 json | A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not... | |
| CVE-2026-58014 json | A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c f... | |
| CVE-2026-58013 json | A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a cu... | |
| CVE-2026-58012 json | A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compi... | |
| CVE-2026-19778 json | The WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping plugin for WordPress is vulnerable... | |
| CVE-2026-19729 json | A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Bui... | |
| CVE-2026-17523 json | In the Linux kernel, the following vulnerability has been resolved: can: bcm: switch timer to HRTIMER_MODE_SOFT and remove h... | |
| CVE-2026-17149 json | The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is ... | |
| CVE-2026-15588 json | A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authen... | |
| CVE-2026-15398 json | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to auth... | |
| CVE-2026-58011 json | A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gda... | |
| CVE-2026-58010 json | A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c... | |
| CVE-2026-87747 json | The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers can ex... | |
| CVE-2026-85117 json | The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs the shortcode parser over the whole rendered Contact Form 7 for... | |
| CVE-2026-83537 json | The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed befor... | |
| CVE-2026-80440 json | The Hustle WordPress plugin before 7.8.14.2 does not prevent shortcodes in submitted form values from being executed when it ... | |
| CVE-2026-19855 json | The CleanTalk WordPress plugin before 6.87 does not prevent unauthenticated, user-supplied comment content from being passed ... | |
| CVE-2026-19802 json | The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions... | |
| CVE-2025-7062 json | A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Educatio... | |
| CVE-2026-63622 json | A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a s... | |
| CVE-2026-85418 json | The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.9 does... | |
| CVE-2026-85133 json | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its settings... | |
| CVE-2026-85132 json | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scann... | |
| CVE-2026-85037 json | The Sunshine Photo Cart WordPress plugin before 3.7 does not validate that a client-supplied price identifier belongs to the... | |
| CVE-2026-84908 json | The WPFunnels plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.12.13. This is ... | |
| CVE-2026-84222 json | The Kirki WordPress plugin before 6.3.0 does not check whether the requester is allowed to read a post before rendering and ... | |
| CVE-2026-84113 json | The Quentn WP WordPress plugin before 1.2.15 does not properly sanitise and escape a parameter before using it in an SQL quer... | |
| CVE-2026-84068 json | The Quentn WP WordPress plugin before 1.2.15 does not adequately escape a request parameter before using it in an unprepared ... | |
| CVE-2026-83593 json | The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Si... | |
| CVE-2026-8615 json | The Reviso Exporter for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ... | |
| CVE-2026-83541 json | The Sina Extension for Elementor WordPress plugin before 3.10.4 does not properly escape a Table widget setting before output... | |
| CVE-2026-82848 json | The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment... | |
| CVE-2026-82185 json | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have capability or nonce checks on some of its A/B testing ac... | |
| CVE-2026-82184 json | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor co... | |
| CVE-2026-81741 json | The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect ta... | |
| CVE-2026-81022 json | The SupportCandy WordPress plugin before 3.5.3 does not validate a submitted per-ticket authorization code before disclosing... | |
| CVE-2026-81021 json | The SupportCandy WordPress plugin before 3.5.3 does not perform an authorization check on one of its support-ticket attachme... | |
| CVE-2026-80341 json | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belong... | |
| CVE-2026-80340 json | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not validate the order key before adding order... | |
| CVE-2026-80339 json | The Payment Plugins for Stripe WooCommerce WordPress plugin before 4.0.12 does not validate the order key before adding order... | |
| CVE-2026-76009 json | The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up t... | |
| CVE-2026-75905 json | The WP Recipe Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.8.0. ... | |
| CVE-2026-75861 json | The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not verify that the user redeeming a gift card is... | |
| CVE-2026-19946 json | The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This... | |
| CVE-2026-18042 json | The WP Travel WordPress plugin before 12.0.2 does not verify that the requester is authorized to act on the booking targeted... | |
| CVE-2026-16960 json | The Loops & Logic WordPress plugin before 4.3.0 does not restrict its public template-data action to the data a visitor is pe... | |
| CVE-2026-16517 json | A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in arc... | |
| CVE-2026-14962 json | The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before u... | |
| CVE-2026-13146 json | The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its ba... | |
| CVE-2026-13144 json | The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester is authorized to modify the targete... | |
| CVE-2026-6893 json | A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially c... | |
| CVE-2025-15690 json | The Content Mask WordPress plugin before 1.8.5.6 does not properly sanitise and escape content submitted with a post before o... | |
| CVE-2026-87737 json | An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST ellip... | |
| CVE-2026-87736 json | An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read ... | |
| CVE-2026-87735 json | An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a smal... | |
| CVE-2026-87734 json | An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of s... | |
| CVE-2026-87733 json | An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub... | |
| CVE-2026-87732 json | An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha... | |
| CVE-2026-21113 json | Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to i... | |
| CVE-2026-21112 json | Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsun... | |
| CVE-2026-21111 json | Out-of-bounds write in libsthmbc.so prior to One UI 8.5 allows local attackers to write out-of-bounds memory. | |
| CVE-2026-21110 json | Out-of-bounds write in libsavscmn.so prior to One UI 8.5 allows local attackers to execute arbitrary code. | |
| CVE-2026-21109 json | Improper access control in Watch Plugin prior to Android Watch 17 allows local attackers to access sensitive information. | |
| CVE-2026-21108 json | Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access ... | |
| CVE-2026-21107 json | Out-of-bounds write in Samsung Notes prior to version 4.4.45.5 allows local attackers to write out-of-bounds memory. | |
| CVE-2026-21106 json | Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attacker... | |
| CVE-2026-21105 json | Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attacke... | |
| CVE-2026-21104 json | Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute... | |
| CVE-2026-21103 json | Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system pri... | |
| CVE-2026-21102 json | Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with ro... | |
| CVE-2026-21101 json | Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially ... | |
| CVE-2026-21100 json | Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity. | |
| CVE-2026-21099 json | Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive inform... | |
| CVE-2026-21098 json | Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 allows local attackers to establish a connection w... | |
| CVE-2026-21097 json | Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to la... | |
| CVE-2026-21096 json | Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers ... | |
| CVE-2026-21095 json | Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers t... | |
| CVE-2026-21094 json | Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds ... | |
| CVE-2026-21093 json | Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-... | |
| CVE-2026-21092 json | Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server... | |
| CVE-2026-21091 json | Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds m... | |
| CVE-2026-21090 json | Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memo... | |
| CVE-2026-21089 json | Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers ... | |
| CVE-2026-21088 json | Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local atta... | |
| CVE-2026-21087 json | Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with syst... | |
| CVE-2026-21086 json | Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration. | |
| CVE-2026-81996 json | Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privi... | |
| CVE-2026-81990 json | Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of ... | |
| CVE-2026-81989 json | Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of ... | |
| CVE-2026-81988 json | Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of ... | |
| CVE-2026-81986 json | Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of ... | |
| CVE-2026-81985 json | Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of ... | |
| CVE-2026-81983 json | Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the conte... | |
| CVE-2026-81980 json | Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the conte... |