CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-64285 json | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Pin source page for write when adding CPUID da... | |
| CVE-2026-62713 json | Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges loca... | |
| CVE-2026-62712 json | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-62711 json | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-62701 json | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-62700 json | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-62699 json | Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to exec... | |
| CVE-2026-62696 json | Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to el... | |
| CVE-2026-62695 json | Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-62693 json | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module al... | |
| CVE-2026-62692 json | Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-62690 json | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications all... | |
| CVE-2026-62688 json | Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-61363 json | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| CVE-2025-71391 json | SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users... | |
| CVE-2026-48447 json | Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in th... | |
| CVE-2026-48441 json | Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabil... | |
| CVE-2026-48410 json | Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co... | |
| CVE-2026-48409 json | Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co... | |
| CVE-2026-48408 json | Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co... | |
| CVE-2026-62702 json | Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-61365 json | Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate priv... | |
| CVE-2026-61352 json | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows a... | |
| CVE-2026-48407 json | Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co... | |
| CVE-2026-48406 json | Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co... | |
| CVE-2026-48405 json | Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co... | |
| CVE-2026-48404 json | Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co... | |
| CVE-2026-48397 json | Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execut... | |
| CVE-2026-47940 json | Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code executio... | |
| CVE-2026-42976 json | Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-73403 json | Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions. | |
| CVE-2026-73401 json | Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions. | |
| CVE-2026-73357 json | Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions. | |
| CVE-2026-73353 json | Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. | |
| CVE-2026-73349 json | Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. | |
| CVE-2026-73346 json | Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. | |
| CVE-2026-73344 json | Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. | |
| CVE-2026-73340 json | Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. | |
| CVE-2026-73188 json | Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions. | |
| CVE-2026-67991 json | crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-ser... | |
| CVE-2026-67990 json | basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and P... | |
| CVE-2026-67986 json | amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in Aw... | |
| CVE-2026-66704 json | Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. | |
| CVE-2026-66700 json | Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions. | |
| CVE-2026-66698 json | Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions. | |
| CVE-2026-66697 json | Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions... | |
| CVE-2026-66693 json | Subscriber Broken Access Control in Motors <= 1.4.113 versions. | |
| CVE-2026-66691 json | Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. | |
| CVE-2026-66689 json | Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker <= 2.0.0 versions. | |
| CVE-2026-66687 json | Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions. | |
| CVE-2026-66661 json | Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions. | |
| CVE-2026-66660 json | Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions. | |
| CVE-2026-66658 json | Subscriber SQL Injection in Reviewer <= 3.14.2 versions. | |
| CVE-2026-66657 json | Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. | |
| CVE-2026-66656 json | Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. | |
| CVE-2026-66655 json | Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions. | |
| CVE-2026-66654 json | Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions. | |
| CVE-2026-66653 json | Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. | |
| CVE-2026-66478 json | Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. | |
| CVE-2026-66472 json | Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. | |
| CVE-2026-66471 json | Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions. | |
| CVE-2026-66469 json | Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions. | |
| CVE-2026-66468 json | Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions. | |
| CVE-2026-66467 json | Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. | |
| CVE-2026-66466 json | Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Q... | |
| CVE-2026-66465 json | Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. | |
| CVE-2026-66464 json | Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions. | |
| CVE-2026-66463 json | Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions. | |
| CVE-2026-66462 json | Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions. | |
| CVE-2026-66461 json | Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. | |
| CVE-2026-66460 json | Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions. | |
| CVE-2026-66459 json | Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions. | |
| CVE-2026-66458 json | Unauthenticated SQL Injection in RealPress <= 1.1.2 versions. | |
| CVE-2026-66456 json | Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. | |
| CVE-2026-66455 json | Subscriber Broken Access Control in ReactPress <= 3.4.0 versions. | |
| CVE-2026-66454 json | Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions. | |
| CVE-2026-66453 json | Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. | |
| CVE-2026-66450 json | Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions. | |
| CVE-2026-66449 json | Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions. | |
| CVE-2026-66446 json | Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. | |
| CVE-2026-66444 json | Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions. | |
| CVE-2026-66443 json | Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions. | |
| CVE-2026-66441 json | Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions. | |
| CVE-2026-66436 json | Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. | |
| CVE-2026-66432 json | Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions. | |
| CVE-2026-66431 json | Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. | |
| CVE-2026-66430 json | Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | |
| CVE-2026-66429 json | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | |
| CVE-2026-66426 json | Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions. | |
| CVE-2026-66424 json | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. | |
| CVE-2026-65582 json | Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions. | |
| CVE-2026-65580 json | Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions. | |
| CVE-2026-61984 json | Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions. | |
| CVE-2026-61980 json | Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions. | |
| CVE-2026-61979 json | Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions. | |
| CVE-2026-61978 json | Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions. | |
| CVE-2026-61974 json | Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions. | |
| CVE-2026-61969 json | Unauthenticated SQL Injection in Listdom <= 5.6.0 versions. | |
| CVE-2026-61967 json | Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. | |
| CVE-2026-61966 json | Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions. |