CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-19389 json | Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) w... | |
| CVE-2026-19387 json | A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI AD... | |
| CVE-2026-19384 json | A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown fu... | |
| CVE-2025-12150 json | A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configu... | |
| CVE-2026-19383 json | A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_exec of... | |
| CVE-2026-19382 json | A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys ... | |
| CVE-2026-19381 json | A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown f... | |
| CVE-2026-19380 json | A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the comp... | |
| CVE-2026-19379 json | A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the co... | |
| CVE-2026-3298 json | The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buf... | |
| CVE-2026-3087 json | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the arc... | |
| CVE-2026-19378 json | A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file... | |
| CVE-2026-19376 json | A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the... | |
| CVE-2026-19375 json | A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article o... | |
| CVE-2026-19374 json | A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the... | |
| CVE-2026-19373 json | A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeReque... | |
| CVE-2026-19372 json | A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is th... | |
| CVE-2026-19371 json | A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src... | |
| CVE-2026-12372 json | A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nl... | |
| CVE-2026-19370 json | A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.... | |
| CVE-2026-15534 json | Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized su... | |
| CVE-2026-19369 json | A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of... | |
| CVE-2026-19368 json | A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src... | |
| CVE-2026-19367 json | A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality o... | |
| CVE-2026-70395 json | Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge ... | |
| CVE-2026-64586 json | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device removal ... | |
| CVE-2026-64563 json | In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhasht... | |
| CVE-2026-19366 json | A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/insertCre... | |
| CVE-2026-19365 json | A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the file src... | |
| CVE-2026-64523 json | In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take a long-lived file reference at submi... | |
| CVE-2026-64427 json | In the Linux kernel, the following vulnerability has been resolved: HID: logitech-dj: Fix maxfield check in DJ short report ... | |
| CVE-2026-63979 json | In the Linux kernel, the following vulnerability has been resolved: net/handshake: hand off the pinned file reference to acc... | |
| CVE-2026-63978 json | In the Linux kernel, the following vulnerability has been resolved: net/handshake: Drain pending requests at net namespace e... | |
| CVE-2026-0976 json | A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matr... | |
| CVE-2026-69659 json | Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a... | |
| CVE-2026-19364 json | A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of... | |
| CVE-2026-19363 json | A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is the function unwrap of the file src/handler.rs... | |
| CVE-2026-19362 json | A vulnerability has been found in lmammino oidc-authorizer 0.4.0. This issue affects the function parse_token_from_header of ... | |
| CVE-2026-19361 json | A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the... | |
| CVE-2026-9804 json | A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a pa... | |
| CVE-2026-7374 json | A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit pe... | |
| CVE-2025-6020 json | A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allow... | |
| CVE-2025-5278 json | A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The prog... | |
| CVE-2025-2842 json | A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed b... | |
| CVE-2025-2786 json | A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploy... | |
| CVE-2024-11831 json | A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not prope... | |
| CVE-2026-19360 json | A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of ... | |
| CVE-2026-19359 json | A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function Sitew... | |
| CVE-2026-4878 json | A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in t... | |
| CVE-2025-7195 json | Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a ra... | |
| CVE-2026-19358 json | A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFuncti... | |
| CVE-2026-17107 json | A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHA... | |
| CVE-2026-16242 json | A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was star... | |
| CVE-2026-19357 json | A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get ... | |
| CVE-2026-1609 json | A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account... | |
| CVE-2026-16093 json | Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to u... | |
| CVE-2026-16089 json | A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authoriz... | |
| CVE-2026-16072 json | A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage or... | |
| CVE-2026-15943 json | A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue o... | |
| CVE-2026-15945 json | A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permi... | |
| CVE-2026-10849 json | The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server i... | |
| CVE-2026-62870 json | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | |
| CVE-2026-11368 json | The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel vi... | |
| CVE-2024-10302 json | The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows ar... | |
| CVE-2026-19356 json | A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/lis... | |
| CVE-2026-19355 json | A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the ... | |
| CVE-2026-19354 json | A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknow... | |
| CVE-2024-6832 json | The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a ... | |
| CVE-2026-18651 json | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credent... | |
| CVE-2026-19353 json | A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file in... | |
| CVE-2026-19352 json | A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the... | |
| CVE-2026-19351 json | A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the funct... | |
| CVE-2026-19350 json | A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice... | |
| CVE-2026-19348 json | A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of th... | |
| CVE-2026-19347 json | A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of ... | |
| CVE-2026-19346 json | A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /g... | |
| CVE-2026-19345 json | A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateT... | |
| CVE-2026-19344 json | A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functional... | |
| CVE-2026-19343 json | A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality... | |
| CVE-2026-19342 json | A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.... | |
| CVE-2026-19341 json | A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the fi... | |
| CVE-2026-19340 json | A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-... | |
| CVE-2026-19339 json | A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the fun... | |
| CVE-2026-19338 json | A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenera... | |
| CVE-2026-19337 json | A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index... | |
| CVE-2026-19336 json | A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApp... | |
| CVE-2026-19335 json | A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSk... | |
| CVE-2026-18603 json | The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or owner... | |
| CVE-2026-18473 json | The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL... | |
| CVE-2026-18465 json | The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also a... | |
| CVE-2026-18464 json | The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also a... | |
| CVE-2026-18357 json | The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its ... | |
| CVE-2026-18037 json | The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its pub... | |
| CVE-2026-18032 json | The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticate... | |
| CVE-2026-17044 json | The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a ... | |
| CVE-2026-17017 json | The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQ... | |
| CVE-2026-17014 json | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its publi... | |
| CVE-2026-17011 json | The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints,... | |
| CVE-2026-16992 json | The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its RES... | |
| CVE-2026-16988 json | The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for... |