CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-102266 json | PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affected be... | |
| CVE-2026-102265 json | PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affe... | |
| CVE-2026-101918 json | PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_fr... | |
| CVE-2026-101917 json | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT get_signing_key_from_jwt is affected bec... | |
| CVE-2026-101110 json | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s boo... | |
| CVE-2026-106217 json | Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised th... | |
| CVE-2026-106215 json | Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memor... | |
| CVE-2026-58052 json | 7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its gua... | |
| CVE-2026-106214 json | Information leak in Proxy in Google Chrome on on Windows prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensit... | |
| CVE-2026-102268 json | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected beca... | |
| CVE-2026-102267 json | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect... | |
| CVE-2026-107355 json | Rejected reason: ** This candidate has been removed by an organization. | |
| CVE-2026-107354 json | Rejected reason: ** This candidate has been removed by an organization. | |
| CVE-2026-107353 json | traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototy... | |
| CVE-2026-107176 json | A flaw was found in the cluster-samples-operator. The RBAC Role coreos-pull-secret-reader in namespace openshift-config grant... | |
| CVE-2026-107161 json | A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes ... | |
| CVE-2026-97717 json | CVE-2026-97717 is a vulnerability in the proxy sub-system of Secure Access servers prior to 14.60. Authenticated attackers ca... | |
| CVE-2026-97716 json | CVE-2026-97716 is a vulnerability in the connection set up sub-system of Secure Access servers prior to version 14.60. Unauth... | |
| CVE-2026-97715 json | CVE-2026-97715 is a vulnerability in the client registration process of Secure Access servers prior to version 14.60. Authen... | |
| CVE-2026-97714 json | CVE-2026-97714 is a is a vulnerability in the authentication sub-system of Secure Access servers prior to version 14.60. Atta... | |
| CVE-2026-34499 json | Use of hard-coded cryptographic key vulnerability in Johnson Controls ADVMS allows Read Sensitive Constants Within an Executa... | |
| CVE-2026-107224 json | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, a Zip64 uncompr... | |
| CVE-2026-107221 json | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0, checkRow sizes ... | |
| CVE-2026-107219 json | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, agile decryptio... | |
| CVE-2026-107214 json | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption ... | |
| CVE-2026-106164 json | In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnera... | |
| CVE-2026-106066 json | A heap-based buffer overflow was found in GIMP’s raw data export plug-in. When exporting very large images, g_malloc() sizi... | |
| CVE-2026-106064 json | A heap-based buffer overflow was found in GIMP’s GIF export plug-in. Exporting an image with very large width and height ca... | |
| CVE-2026-96335 json | Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured Access Control Security L... | |
| CVE-2026-95595 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fontsplugin Disable and... | |
| CVE-2026-94670 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest Forms allows Re... | |
| CVE-2026-76488 json | A vulnerability in the export policies functionality of Cisco Application Policy Infrastructure Controller (APIC) could allow... | |
| CVE-2026-76482 json | As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Pr... | |
| CVE-2026-76469 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has co... | |
| CVE-2026-76463 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has co... | |
| CVE-2026-76455 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conduct... | |
| CVE-2026-20362 json | A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to con... | |
| CVE-2026-20032 json | A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privi... | |
| CVE-2026-106550 json | Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prot... | |
| CVE-2026-106404 json | Incorrect authorization in FontAccess in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised t... | |
| CVE-2026-106403 json | Incorrect authorization in Accessibility in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromise... | |
| CVE-2026-106367 json | Missing authorization in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging soc... | |
| CVE-2026-106348 json | Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information... | |
| CVE-2026-106063 json | A heap-based buffer overflow was found in GIMP’s DICOM export plug-in. When exporting an image with extremely large width a... | |
| CVE-2026-103870 json | A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as director... | |
| CVE-2026-80048 json | A flaw was found in `sssd-kcm`. A local user or process able to connect to the `sssd-kcm` UNIX socket can exploit this vulner... | |
| CVE-2026-76752 json | Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy... | |
| CVE-2026-76751 json | A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitati... | |
| CVE-2026-76750 json | Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Succ... | |
| CVE-2026-76749 json | A sensitive information disclosure vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated remo... | |
| CVE-2026-76748 json | A privilege escalation vulnerability exists in the API of AOS-S. Successful exploitation could allow an authenticated read-on... | |
| CVE-2026-76747 json | Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthentica... | |
| CVE-2026-76746 json | An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated adja... | |
| CVE-2026-76745 json | Memory corruption vulnerabilities exist in AOS-S that are reachable by an unauthenticated adjacent attacker. Successful explo... | |
| CVE-2026-76744 json | Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthentica... | |
| CVE-2026-76743 json | A vulnerability have been identified in the management interface of AOS-S that could potentially allow an unauthenticated rem... | |
| CVE-2026-42713 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gopiplus Post title mar... | |
| CVE-2026-42708 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Autho... | |
| CVE-2026-106307 json | Incorrect authorization in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the ... | |
| CVE-2026-106301 json | Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the... | |
| CVE-2026-106271 json | Missing authorization in Workers in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the re... | |
| CVE-2026-106263 json | Improper input validation in SignIn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engin... | |
| CVE-2026-106205 json | Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had co... | |
| CVE-2026-92142 json | Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on ... | |
| CVE-2026-91085 json | Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.... | |
| CVE-2026-91048 json | The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactor... | |
| CVE-2026-91012 json | org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config... | |
| CVE-2026-81862 json | Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` an... | |
| CVE-2026-48558 json | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC ... | |
| CVE-2025-14508 json | The MediaCommander – Bring Folders to Media, Posts, and Pages plugin for WordPress is vulnerable to unauthorized data delet... | |
| CVE-2025-14477 json | The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1.0 due to insuf... | |
| CVE-2025-14476 json | The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versio... | |
| CVE-2025-14475 json | The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all versions ... | |
| CVE-2025-14462 json | The Lucky Draw Contests plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... | |
| CVE-2025-14454 json | The Image Slider by Ays- Responsive Slider and Carousel plugin for WordPress is vulnerable to Cross-Site Request Forgery in a... | |
| CVE-2025-14451 json | The Solutions Ad Manager plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.0.0. Thi... | |
| CVE-2025-14447 json | The AnnunciFunebri Impresa plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... | |
| CVE-2025-14446 json | The Popup Builder (Easy Notify Lite) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... | |
| CVE-2025-14440 json | The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01... | |
| CVE-2025-14397 json | The Postem Ipsum plugin for WordPress is vulnerable to unauthorized modification of data to Privilege Escalation due to a mis... | |
| CVE-2025-14395 json | The Popover Windows plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... | |
| CVE-2025-14394 json | The Popover Windows plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2. T... | |
| CVE-2025-14378 json | The Quick Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u... | |
| CVE-2025-14367 json | The Easy Theme Options plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.... | |
| CVE-2025-14366 json | The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and includin... | |
| CVE-2025-14365 json | The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and includin... | |
| CVE-2025-14288 json | The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery... | |
| CVE-2025-14278 json | The HT Slider for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slide_title' parameter... | |
| CVE-2025-14056 json | The Custom Post Type UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter during cu... | |
| CVE-2025-14050 json | The Design Import/Export plugin for WordPress is vulnerable to SQL Injection via XML File Import in all versions up to, and i... | |
| CVE-2025-13705 json | The Custom Frames plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter of the 'customf... | |
| CVE-2025-13403 json | The Employee Spotlight – Team Member Showcase & Meet the Team Plugin for WordPress is vulnerable to unauthorized tracking s... | |
| CVE-2025-13094 json | The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation... | |
| CVE-2025-13093 json | The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized modificat... | |
| CVE-2025-13092 json | The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized access of... | |
| CVE-2025-13077 json | The افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce plugin for WordPress is v... | |
| CVE-2025-12512 json | The GenerateBlocks plugin for WordPress is vulnerable to information exposure due to missing object-level authorization check... | |
| CVE-2025-12362 json | The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulnerab... | |
| CVE-2025-12109 json | The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Si... | |
| CVE-2025-12077 json | The WP to LinkedIn Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all v... |