CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-15722 json A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in re...
CVE-2026-20000 json A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of t...
CVE-2026-73434 json A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_ri...
CVE-2026-19999 json A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The affected element is the fu...
CVE-2026-19998 json A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file offer...
CVE-2026-73433 json A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux...
CVE-2026-19387 json A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI AD...
CVE-2026-4878 json A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in t...
CVE-2025-7425 json A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory manage...
CVE-2025-6020 json A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allow...
CVE-2025-5914 json A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() fu...
CVE-2026-22072 json Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.
CVE-2026-19997 json A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /ad...
CVE-2026-19996 json A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/cust...
CVE-2026-19995 json A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/...
CVE-2026-19994 json A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /ad...
CVE-2026-17107 json A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHA...
CVE-2026-16242 json A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was star...
CVE-2026-15623 json A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior ...
CVE-2026-4740 json A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Impro...
CVE-2026-74579 json In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: fix mask build for partial field...
CVE-2026-19993 json A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of t...
CVE-2026-19992 json A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affe...
CVE-2026-74578 json In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force synchronous processing on...
CVE-2026-74577 json In the Linux kernel, the following vulnerability has been resolved: net: mpls: initialize rtm_tos in mpls_getroute() mpls_g...
CVE-2026-74576 json In the Linux kernel, the following vulnerability has been resolved: mm/slab: prevent unbounded recursion in free path with n...
CVE-2026-74575 json In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Prevent XDomain delayed work use-after-free...
CVE-2026-74574 json In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix fdev setup failure cleanup in idxd_...
CVE-2026-74573 json In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID...
CVE-2026-74572 json In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix deadlock between metadata writeback an...
CVE-2026-74571 json In the Linux kernel, the following vulnerability has been resolved: btrfs: skip global block reserve accounting for rescue m...
CVE-2026-74570 json In the Linux kernel, the following vulnerability has been resolved: ntfs: harden runlist realloc size calculations Add a sh...
CVE-2026-74569 json In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: widen NAT rewrite delta to ...
CVE-2026-74568 json In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Fix race between LPI release and re-re...
CVE-2026-74567 json In the Linux kernel, the following vulnerability has been resolved: keys: fix out-of-bounds read in keyring_get_key_chunk() ...
CVE-2026-74566 json In the Linux kernel, the following vulnerability has been resolved: keys: make keyring key-chunk byte order agree with keyri...
CVE-2026-74565 json In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: make nft_object rhltable per table...
CVE-2026-74564 json In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_hashlimit: validate hashtable supports XT_...
CVE-2026-74563 json In the Linux kernel, the following vulnerability has been resolved: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rd...
CVE-2026-74562 json In the Linux kernel, the following vulnerability has been resolved: nexthop: take nh->lock for f6i_list walks in replace che...
CVE-2026-74561 json In the Linux kernel, the following vulnerability has been resolved: nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flu...
CVE-2026-74560 json In the Linux kernel, the following vulnerability has been resolved: xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-...
CVE-2026-74559 json In the Linux kernel, the following vulnerability has been resolved: xsk: drain continuation descs after overflow in xsk_buil...
CVE-2026-74558 json In the Linux kernel, the following vulnerability has been resolved: xsk: reclaim invalid Tx descriptors in ZC batch path Th...
CVE-2026-19988 json A vulnerability was detected in Alaev SEO Tools Extension up to 1.0.10 on Chrome. This impacts the function addDiv of the fil...
CVE-2026-19987 json A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknown fun...
CVE-2026-14832 json The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership check on...
CVE-2026-13700 json The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and at...
CVE-2026-74557 json In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi: Fix stale-data leak into the SCSI sense ...
CVE-2026-74556 json In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi_tcp: Bound SCSI Response data segment to ...
CVE-2026-74555 json In the Linux kernel, the following vulnerability has been resolved: scsi: libsas: Fix HA resume deadlock and hisi_sas disk-w...
CVE-2026-74554 json In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_...
CVE-2026-74553 json In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775-core) Fix number of temperature register...
CVE-2026-74552 json In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Only report alarms if driver is ready Use...
CVE-2026-74551 json In the Linux kernel, the following vulnerability has been resolved: hwmon: (nzxt-smart2) DMA-align output buffer Sashiko re...
CVE-2026-74550 json In the Linux kernel, the following vulnerability has been resolved: net: do not send ICMP/NDISC Redirects when peer allocati...
CVE-2026-74549 json In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775-core) Prevent access to unsupported weig...
CVE-2026-74548 json In the Linux kernel, the following vulnerability has been resolved: forcedeth: fix UAF of txrx_stats in nv_remove nv_remove...
CVE-2026-74547 json In the Linux kernel, the following vulnerability has been resolved: hwmon: (adt7470) Fix busy-loop and I2C flooding in updat...
CVE-2026-74546 json In the Linux kernel, the following vulnerability has been resolved: hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan ...
CVE-2026-74545 json In the Linux kernel, the following vulnerability has been resolved: rtase: fix double free of multi-frag skb on DMA map fail...
CVE-2026-74544 json In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_u32: validate offshift to prevent shift-o...
CVE-2026-74543 json In the Linux kernel, the following vulnerability has been resolved: net: udp_tunnel: fix memory leak in udp_tunnel_nic_unreg...
CVE-2026-74542 json In the Linux kernel, the following vulnerability has been resolved: netfs: Fix folio_queue ENOMEM in writeback by adding a m...
CVE-2026-74541 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: clear iso_data always when detaching con...
CVE-2026-74540 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp l2cap...
CVE-2026-74539 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: lock sk in iso_sock_getname Accessing i...
CVE-2026-74538 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: lock sk in iso_connect_ind Accessing is...
CVE-2026-74537 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: hold sk properly in iso_conn_ready sk d...
CVE-2026-74536 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix leaking sk after socket release iso...
CVE-2026-74535 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: avoid deadlocks in iso_sock_timeout iso...
CVE-2026-74534 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix refcounting of iso_conn iso_conn_de...
CVE-2026-74533 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix race of kfree vs kref_get_unless_zer...
CVE-2026-74532 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: Validate length before parsing diagn...
CVE-2026-74531 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: hold conn reference in abort_conn_s...
CVE-2026-74530 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_big_sync()...
CVE-2026-74529 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() ...
CVE-2026-74528 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_past_sync() callba...
CVE-2026-74527 json In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Block VFs from clobbering special CGX PKIN...
CVE-2026-74526 json In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uev...
CVE-2026-74525 json In the Linux kernel, the following vulnerability has been resolved: net: sxgbe: free TX rings on RX allocation failure When...
CVE-2026-74524 json In the Linux kernel, the following vulnerability has been resolved: riscv: mm: Fix out-of-bounds page-table walk during memo...
CVE-2026-74523 json In the Linux kernel, the following vulnerability has been resolved: qede: sync udp_tunnel ports outside qede_lock in the rec...
CVE-2026-74522 json In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __close_file_table_ids() A...
CVE-2026-74521 json In the Linux kernel, the following vulnerability has been resolved: ksmbd: use memcmp() to compare ClientGUIDs ClientGUID i...
CVE-2026-74520 json In the Linux kernel, the following vulnerability has been resolved: iommu/iommufd: Fix IOPF group ownership UAF iopf_group_...
CVE-2026-74519 json In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: don't free uninitialized dev_name o...
CVE-2026-74518 json In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix list corruption in allocate_file_region_...
CVE-2026-74517 json In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Cancel delayed I/O APIC EOI handling before de...
CVE-2026-74516 json In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibi...
CVE-2026-74515 json In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Reject adapter interrupt forwarding if a...
CVE-2026-74514 json In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix memory accounting for pinned/unpinne...
CVE-2026-74513 json In the Linux kernel, the following vulnerability has been resolved: dibs: fix use-after-free of dmb_node in loopback attach/...
CVE-2026-74512 json In the Linux kernel, the following vulnerability has been resolved: audit: fix potential use-after-free in audit_del_rule() ...
CVE-2026-74511 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix pending command UAF in EIR updates ...
CVE-2026-74510 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix UAF in pair command cancellation T...
CVE-2026-74509 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix advertising data UAFs hci_find...
CVE-2026-74508 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: reject frames without a transaction hea...
CVE-2026-74507 json In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: validate numbered report payloads When...
CVE-2026-74506 json In the Linux kernel, the following vulnerability has been resolved: afs: Fix UAF when sending a message In afs_make_call(),...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report