CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-43730 json | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe ... | |
| CVE-2026-60549 json | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Suppo... | |
| CVE-2026-60547 json | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Suppo... | |
| CVE-2026-60545 json | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Suppo... | |
| CVE-2026-60537 json | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Suppo... | |
| CVE-2026-60536 json | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Application... | |
| CVE-2026-60535 json | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Application... | |
| CVE-2026-60534 json | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Application... | |
| CVE-2026-60533 json | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector... | |
| CVE-2026-60532 json | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Application... | |
| CVE-2026-60531 json | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported vers... | |
| CVE-2026-28931 json | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 2... | |
| CVE-2026-28928 json | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS ... | |
| CVE-2026-66745 json | Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that a... | |
| CVE-2026-59932 json | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 throug... | |
| CVE-2026-50738 json | A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after th... | |
| CVE-2026-50737 json | When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's defa... | |
| CVE-2026-50736 json | The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, e... | |
| CVE-2026-50735 json | pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol message... | |
| CVE-2026-49258 json | Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) doe... | |
| CVE-2026-48396 json | Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context o... | |
| CVE-2026-48395 json | Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of ... | |
| CVE-2026-48394 json | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of th... | |
| CVE-2026-48393 json | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of th... | |
| CVE-2026-48392 json | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of th... | |
| CVE-2026-48391 json | Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of ... | |
| CVE-2026-48390 json | Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could l... | |
| CVE-2026-48374 json | Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that co... | |
| CVE-2026-7769 json | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterl... | |
| CVE-2026-7362 json | IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 th... | |
| CVE-2026-5114 json | The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and inclu... | |
| CVE-2026-4932 json | IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical acc... | |
| CVE-2026-4912 json | The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up... | |
| CVE-2026-59933 json | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 throug... | |
| CVE-2026-59931 json | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 throug... | |
| CVE-2026-51273 json | In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the ID3 tag parsing function showI... | |
| CVE-2026-51271 json | In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the WAV header parsing function re... | |
| CVE-2026-51267 json | schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation and encoding m... | |
| CVE-2026-51266 json | schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the HTTP request header construction logi... | |
| CVE-2026-51263 json | schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow. The Audio::openai_speech function in the Audio library ma... | |
| CVE-2026-51260 json | Unsafe fixed-size memcpy operation in AudioBuffer::writeSpace() of schreibfaul1 ESP32-audioI2S 3.4.5 allows remote heap buffe... | |
| CVE-2026-48372 json | Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the... | |
| CVE-2026-48058 json | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/we... | |
| CVE-2026-47768 json | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minte... | |
| CVE-2026-47726 json | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/ap... | |
| CVE-2026-47725 json | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every /ui/*... | |
| CVE-2026-18107 json | A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a c... | |
| CVE-2026-16771 json | In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on i... | |
| CVE-2026-16498 json | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP s... | |
| CVE-2026-16496 json | The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transp... | |
| CVE-2026-16313 json | A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data ... | |
| CVE-2026-15992 json | The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. ... | |
| CVE-2026-15304 json | The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions up to... | |
| CVE-2026-14869 json | The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP tra... | |
| CVE-2026-64772 json | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, m... | |
| CVE-2026-64765 json | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequ... | |
| CVE-2026-64755 json | An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app ... | |
| CVE-2026-64754 json | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, ma... | |
| CVE-2026-64749 json | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8,... | |
| CVE-2026-64727 json | A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.6, tvOS 26.6. An ap... | |
| CVE-2026-64718 json | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS... | |
| CVE-2026-64702 json | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma... | |
| CVE-2026-60520 json | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions ... | |
| CVE-2026-51259 json | Unchecked unsigned integer overflow in buffer size calculation in schreibfaul1 ESP32-audioI2S 3.4.5 leads to undersized PSRAM... | |
| CVE-2026-51254 json | schreibfaul1 ESP32-audioI2S v3.4.5 has an integer underflow vulnerability in the MP3Decoder::GetBits() function of the MP3 de... | |
| CVE-2026-51252 json | schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to missin... | |
| CVE-2026-51251 json | Schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::decode() function of the MP3 decoder... | |
| CVE-2026-43817 json | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tah... | |
| CVE-2026-43816 json | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, ma... | |
| CVE-2026-43800 json | An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.6 and iPadOS 26.... | |
| CVE-2026-43792 json | An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An... | |
| CVE-2026-43768 json | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macO... | |
| CVE-2026-43758 json | An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonom... | |
| CVE-2026-43744 json | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, ma... | |
| CVE-2026-43729 json | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8,... | |
| CVE-2026-28932 json | A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed ... | |
| CVE-2021-32087 json | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials.... | |
| CVE-2026-60519 json | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions ... | |
| CVE-2026-60437 json | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions ... | |
| CVE-2026-60436 json | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions ... | |
| CVE-2026-60362 json | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions ... | |
| CVE-2026-60360 json | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions ... | |
| CVE-2026-60359 json | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions ... | |
| CVE-2026-52722 json | A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimens... | |
| CVE-2026-52720 json | A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly... | |
| CVE-2026-64730 json | The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvO... | |
| CVE-2026-64729 json | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS ... | |
| CVE-2026-64728 json | A permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, mac... | |
| CVE-2026-43811 json | A race condition was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to m... | |
| CVE-2026-43804 json | This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, mac... | |
| CVE-2026-64783 json | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS... | |
| CVE-2026-64758 json | The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS ... | |
| CVE-2026-64757 json | A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPad... | |
| CVE-2026-64751 json | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS ... | |
| CVE-2026-64746 json | An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 2... | |
| CVE-2026-64741 json | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, tvOS 26.6, v... | |
| CVE-2026-64733 json | This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tv... | |
| CVE-2026-64732 json | This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6. An attacker with... | |
| CVE-2026-67184 json | TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash... | |
| CVE-2026-67183 json | TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory ... |