CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2025-49796 json A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corru...
CVE-2025-49794 json A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstance...
CVE-2025-7425 json A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory manage...
CVE-2025-5914 json A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() fu...
CVE-2026-2100 json A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remo...
CVE-2025-5278 json A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The prog...
CVE-2026-10848 json The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) u...
CVE-2026-10840 json A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:a...
CVE-2026-4878 json A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in t...
CVE-2025-1244 json A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arb...
CVE-2026-9856 json A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via pat...
CVE-2026-65321 json PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL...
CVE-2026-10774 json Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth...
CVE-2026-68583 json luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that al...
CVE-2026-68582 json Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collecti...
CVE-2026-68581 json Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-...
CVE-2026-68580 json FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, s...
CVE-2026-68579 json FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read ...
CVE-2026-68578 json ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permis...
CVE-2026-67357 json ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leak...
CVE-2026-67356 json ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing sch...
CVE-2026-9804 json A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a pa...
CVE-2026-7374 json A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit pe...
CVE-2025-71401 json better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER...
CVE-2025-71400 json better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion e...
CVE-2025-71399 json Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by ...
CVE-2025-5318 json A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handl...
CVE-2025-4373 json A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the posi...
CVE-2025-2842 json A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed b...
CVE-2025-2786 json A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploy...
CVE-2026-67321 json axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when s...
CVE-2026-67315 json axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassP...
CVE-2026-67309 json Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's Re...
CVE-2026-67308 json Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arb...
CVE-2026-17107 json A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHA...
CVE-2026-16242 json A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was star...
CVE-2025-6020 json A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allow...
CVE-2026-46579 json A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend do...
CVE-2026-6492 json A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The ...
CVE-2026-1784 json The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that...
CVE-2026-5084 json WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely. The session handler generates the se...
CVE-2026-12231 json The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox...
CVE-2026-16232 json An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacke...
CVE-2026-18573 json A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization ...
CVE-2026-18572 json Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (fo...
CVE-2026-18571 json A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This...
CVE-2026-18570 json A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is ...
CVE-2026-16540 json The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to...
CVE-2026-16292 json The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata ...
CVE-2026-16291 json The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before de...
CVE-2026-16285 json The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streamin...
CVE-2026-16273 json The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or es...
CVE-2026-16261 json The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requeste...
CVE-2026-16256 json The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions availab...
CVE-2026-16064 json The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object...
CVE-2026-16063 json The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content s...
CVE-2026-16062 json The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-control...
CVE-2026-16042 json The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any...
CVE-2026-15939 json The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API t...
CVE-2026-15385 json The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu c...
CVE-2026-15248 json The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment befor...
CVE-2026-15241 json The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its...
CVE-2026-15236 json The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAut...
CVE-2026-15206 json The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was ac...
CVE-2026-15151 json The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX ...
CVE-2026-14938 json The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong ...
CVE-2026-14920 json ## Summary
CVE-2026-14864 json The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortc...
CVE-2026-14841 json The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting...
CVE-2026-14817 json The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain ...
CVE-2026-13389 json The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API r...
CVE-2026-12586 json The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset acti...
CVE-2026-11872 json The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJ...
CVE-2025-15675 json The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields before out...
CVE-2026-9335 json A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper ha...
CVE-2024-11831 json A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not prope...
CVE-2026-18352 json The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.1...
CVE-2026-13339 json The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 v...
CVE-2026-8457 json The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and includin...
CVE-2026-17002 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-7195 json Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a ra...
CVE-2025-11393 json A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this...
CVE-2026-18556 json Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. Thi...
CVE-2026-7163 json A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multiclu...
CVE-2025-2843 json A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of t...
CVE-2026-55735 json Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim'...
CVE-2026-55734 json Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows...
CVE-2026-55733 json Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creati...
CVE-2026-54894 json Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creati...
CVE-2025-52936 json Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh.This issue affects sslh: befor...
CVE-2024-10918 json Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus respons...
CVE-2026-18536 json Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::Rand...
CVE-2026-15105 json A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file...
CVE-2026-67355 json guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain fiel...
CVE-2026-67354 json guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the opti...
CVE-2026-67353 json guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Se...
CVE-2026-67352 json luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authe...
CVE-2026-67344 json ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYPE ......
CVE-2026-67343 json ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authen...
CVE-2026-67342 json ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Promet...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report