CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-91088 json | A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file util... | |
| CVE-2026-91087 json | A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/... | |
| CVE-2026-91086 json | A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process o... | |
| CVE-2026-91005 json | A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file... | |
| CVE-2026-90711 json | proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Expres... | |
| CVE-2026-89141 json | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object ... | |
| CVE-2026-82209 json | When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie`... | |
| CVE-2026-82208 json | With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, lib... | |
| CVE-2026-80255 json | A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secu... | |
| CVE-2026-80231 json | A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different ... | |
| CVE-2026-75983 json | The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege ... | |
| CVE-2026-18063 json | The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all... | |
| CVE-2026-15402 json | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stor... | |
| CVE-2026-80230 json | When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPE... | |
| CVE-2026-80229 json | When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles.... | |
| CVE-2026-19931 json | A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when t... | |
| CVE-2026-18924 json | A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other han... | |
| CVE-2026-18917 json | A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePag... | |
| CVE-2026-13608 json | A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted a... | |
| CVE-2026-9547 json | When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` call... | |
| CVE-2026-9546 json | A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation... | |
| CVE-2026-9545 json | In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to... | |
| CVE-2026-9080 json | Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability... | |
| CVE-2026-9079 json | libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old cr... | |
| CVE-2026-8932 json | libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should ha... | |
| CVE-2026-8927 json | When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to c... | |
| CVE-2026-8926 json | When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a ... | |
| CVE-2026-8925 json | The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the po... | |
| CVE-2026-8924 json | A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix L... | |
| CVE-2026-8458 json | libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they ... | |
| CVE-2026-8286 json | A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connect... | |
| CVE-2026-12064 json | When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between th... | |
| CVE-2026-11856 json | Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then chang... | |
| CVE-2026-11586 json | By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for ... | |
| CVE-2026-11564 json | libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the s... | |
| CVE-2026-11352 json | An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against... | |
| CVE-2026-10536 json | A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT... | |
| CVE-2026-7168 json | Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then cha... | |
| CVE-2026-6429 json | When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for... | |
| CVE-2026-6276 json | Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using ... | |
| CVE-2026-6253 json | curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following condition... | |
| CVE-2026-5773 json | libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent conne... | |
| CVE-2026-5545 json | libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Nego... | |
| CVE-2026-4873 json | A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same c... | |
| CVE-2026-3784 json | curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different ... | |
| CVE-2026-3783 json | When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl coul... | |
| CVE-2026-1965 json | libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS reques... | |
| CVE-2025-15224 json | When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ... | |
| CVE-2025-15079 json | When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly acc... | |
| CVE-2025-14819 json | When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libc... | |
| CVE-2025-14524 json | When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second... | |
| CVE-2025-14017 json | When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertentl... | |
| CVE-2025-13034 json | When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool, curl should check the public... | |
| CVE-2025-10966 json | curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host veri... | |
| CVE-2025-10148 json | curl's WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the specification says. Instead i... | |
| CVE-2026-91004 json | A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown func... | |
| CVE-2026-91003 json | A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the com... | |
| CVE-2026-91002 json | A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the fi... | |
| CVE-2026-91001 json | A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the ... | |
| CVE-2026-86701 json | Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components. A ... | |
| CVE-2026-81320 json | A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 ... | |
| CVE-2026-81303 json | A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tena... | |
| CVE-2026-18232 json | The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its ... | |
| CVE-2026-17495 json | moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2... | |
| CVE-2026-16593 json | The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a ... | |
| CVE-2026-16592 json | The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcod... | |
| CVE-2026-15758 json | The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive... | |
| CVE-2026-90881 json | A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi o... | |
| CVE-2026-90880 json | A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bi... | |
| CVE-2026-90879 json | A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz/publ... | |
| CVE-2026-90878 json | A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completio... | |
| CVE-2026-90877 json | A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown funct... | |
| CVE-2026-90876 json | A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is an un... | |
| CVE-2026-90858 json | A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affecte... | |
| CVE-2026-90857 json | A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown function o... | |
| CVE-2026-87719 json | GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 befo... | |
| CVE-2026-86917 json | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15... | |
| CVE-2026-85921 json | Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-85892 json | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based... | |
| CVE-2026-84631 json | This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able ... | |
| CVE-2026-84568 json | A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoi... | |
| CVE-2026-84505 json | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS ... | |
| CVE-2026-76461 json | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated,... | |
| CVE-2026-76443 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Sec... | |
| CVE-2026-76442 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Sec... | |
| CVE-2026-76441 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Sec... | |
| CVE-2026-76440 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Sec... | |
| CVE-2026-75624 json | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated atta... | |
| CVE-2026-65414 json | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iO... | |
| CVE-2026-65362 json | This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 2... | |
| CVE-2026-64712 json | This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 2... | |
| CVE-2026-64701 json | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6... | |
| CVE-2026-63427 json | An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to p... | |
| CVE-2026-60163 json | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supp... | |
| CVE-2026-59569 json | An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentia... | |
| CVE-2026-43786 json | This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8,... | |
| CVE-2026-43783 json | A race condition was addressed with improved locking. This issue is fixed in macOS Tahoe 26.6. A malicious app may be able to... | |
| CVE-2026-43692 json | A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Sequoia... | |
| CVE-2026-43691 json | A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8... | |
| CVE-2026-43689 json | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and i... |