CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-103001 json | PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() meth... | |
| CVE-2026-101283 json | iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_r... | |
| CVE-2026-91149 json | A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining n... | |
| CVE-2026-47097 json | AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to... | |
| CVE-2026-47096 json | AJA HELO Plus firmware before 2.1.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attacker... | |
| CVE-2025-69148 json | Unauthenticated Local File Inclusion in Quirky <= 1.23 versions. | |
| CVE-2025-62305 json | HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resulting ... | |
| CVE-2025-68421 json | Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is ... | |
| CVE-2025-68420 json | Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to whi... | |
| CVE-2025-32425 json | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate... | |
| CVE-2025-15345 json | The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' parame... | |
| CVE-2025-15025 json | Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Training and Elec... | |
| CVE-2025-14767 json | The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' att... | |
| CVE-2025-14033 json | The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing... | |
| CVE-2025-12008 json | Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Media Ap... | |
| CVE-2025-11159 json | Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerab... | |
| CVE-2025-11024 json | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Softwar... | |
| CVE-2025-62627 json | An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to... | |
| CVE-2025-62624 json | A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalatio... | |
| CVE-2025-62623 json | A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalatio... | |
| CVE-2025-15463 json | The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions ... | |
| CVE-2025-14755 json | The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct Obje... | |
| CVE-2025-9989 json | The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, a... | |
| CVE-2025-9988 json | The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the create_adv... | |
| CVE-2025-9987 json | The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.... | |
| CVE-2025-68060 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member allo... | |
| CVE-2025-66172 json | The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-a... | |
| CVE-2025-66171 json | The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-a... | |
| CVE-2025-66170 json | The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated... | |
| CVE-2025-12659 json | Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could all... | |
| CVE-2025-6577 json | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Softwar... | |
| CVE-2025-62127 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Logo Sli... | |
| CVE-2025-52613 json | HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or in... | |
| CVE-2025-31984 json | HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-... | |
| CVE-2025-31983 json | HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This could al... | |
| CVE-2025-31982 json | HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. T... | |
| CVE-2025-31978 json | HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before pr... | |
| CVE-2025-31976 json | HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communica... | |
| CVE-2025-31975 json | HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed s... | |
| CVE-2025-31974 json | HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured ro... | |
| CVE-2025-31960 json | HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting ... | |
| CVE-2025-31959 json | HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confide... | |
| CVE-2025-31957 json | HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to u... | |
| CVE-2025-62345 json | HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component cont... | |
| CVE-2025-61669 json | Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query paramet... | |
| CVE-2025-59854 json | HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the ou... | |
| CVE-2025-59853 json | HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces ... | |
| CVE-2025-59852 json | HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the... | |
| CVE-2025-59851 json | HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched l... | |
| CVE-2025-42611 json | RouterOS provides various services that rely on correct verification of client and server certificates to secure confidential... | |
| CVE-2025-31970 json | HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy doe... | |
| CVE-2025-31951 json | HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a comp... | |
| CVE-2025-13618 json | The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. This is... | |
| CVE-2025-47408 json | Memory corruption when another driver calls an IOCTL with invalid input/output buffer. | |
| CVE-2025-47407 json | Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level. | |
| CVE-2025-47406 json | Information Disclosure while processing IOCTL handler callbacks without verifying buffer size. | |
| CVE-2025-47405 json | Memory corruption when processing camera sensor input/output control codes with invalid output buffers. | |
| CVE-2025-47404 json | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | |
| CVE-2025-47403 json | Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roa... | |
| CVE-2025-58074 json | A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privi... | |
| CVE-2025-14320 json | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and ... | |
| CVE-2025-13605 json | 3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute... | |
| CVE-2025-71284 json | Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at... | |
| CVE-2025-48431 json | Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thr... | |
| CVE-2025-36335 json | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a local u... | |
| CVE-2025-36180 json | IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an att... | |
| CVE-2025-36122 json | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allo... | |
| CVE-2025-14726 json | The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data ... | |
| CVE-2025-14688 json | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allo... | |
| CVE-2025-10539 json | Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can positi... | |
| CVE-2025-10503 json | The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack ... | |
| CVE-2025-62233 json | Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinSche... | |
| CVE-2025-62110 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Rescue Sh... | |
| CVE-2025-62104 json | Missing Authorization vulnerability in Navneil Naicker ACF Galerie 4 allows Exploiting Incorrectly Configured Access Control ... | |
| CVE-2025-58922 json | Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada allows Cross Site Request Forgery.This issue affects Ava... | |
| CVE-2025-41029 json | SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, creat... | |
| CVE-2025-36074 json | IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malici... | |
| CVE-2025-31981 json | HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowin... | |
| CVE-2025-31958 json | HCL BigFix Service Management is susceptible to HTTP Request Smuggling. HTTP request smuggling vulnerabilities arise when w... | |
| CVE-2025-15638 json | Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before 0.14... | |
| CVE-2025-15626 json | Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application | |
| CVE-2025-11762 json | The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Expos... | |
| CVE-2025-10549 json | EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the install... | |
| CVE-2025-66335 json | Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling... | |
| CVE-2025-65104 json | Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data... | |
| CVE-2025-46641 json | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a... | |
| CVE-2025-46607 json | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a... | |
| CVE-2025-46606 json | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a... | |
| CVE-2025-46605 json | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a... | |
| CVE-2025-14362 json | The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to... | |
| CVE-2025-13826 json | Zervit's portable HTTP/web server is vulnerable to remote DoS attacks when a configuration reset request is made. The vulnera... | |
| CVE-2025-13480 json | Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only resourc... | |
| CVE-2025-1241 json | Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a st... | |
| CVE-2025-15625 json | Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases. | |
| CVE-2025-15624 json | Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. In a setup where OpenID is ... | |
| CVE-2025-15623 json | Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthori... | |
| CVE-2025-15622 json | Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plai... | |
| CVE-2025-15621 json | Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receive... | |
| CVE-2025-14868 json | The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitrary F... | |
| CVE-2025-12624 json | Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure t... |