CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-78685 json | Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote atta... | |
| CVE-2026-75982 json | The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in versions up ... | |
| CVE-2026-75147 json | FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyfram... | |
| CVE-2026-75019 json | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is... | |
| CVE-2026-71864 json | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ... | |
| CVE-2026-63407 json | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16... | |
| CVE-2026-62667 json | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the ... | |
| CVE-2026-61690 json | Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipArchiv... | |
| CVE-2026-53452 json | Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prio... | |
| CVE-2026-50149 json | Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is confi... | |
| CVE-2026-49255 json | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm construc... | |
| CVE-2026-48162 json | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0... | |
| CVE-2026-44255 json | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0... | |
| CVE-2026-44253 json | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3.9.0 until 4.14.5 and 5.0... | |
| CVE-2026-40507 json | OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handler. T... | |
| CVE-2026-10627 json | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in a... | |
| CVE-2025-9878 json | The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cross... | |
| CVE-2026-76243 json | stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Att... | |
| CVE-2026-76238 json | stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the decay sweep endpoint that a... | |
| CVE-2026-76235 json | A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request t... | |
| CVE-2026-76232 json | Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the repos... | |
| CVE-2026-76227 json | Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renova... | |
| CVE-2026-76222 json | GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositori... | |
| CVE-2026-76217 json | GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() an... | |
| CVE-2026-76212 json | phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the native pgsql PHP extension, declares an incorrect LIKE ESCAP... | |
| CVE-2026-76207 json | phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2F... | |
| CVE-2026-76014 json | A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c... | |
| CVE-2026-75986 json | A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element is an unknown function of ... | |
| CVE-2026-75976 json | A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi... | |
| CVE-2026-75918 json | phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled. Unau... | |
| CVE-2026-5367 json | A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Prot... | |
| CVE-2019-25766 json | Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Mod... | |
| CVE-2026-78683 json | NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParse... | |
| CVE-2026-78682 json | NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, ... | |
| CVE-2026-78681 json | NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in d... | |
| CVE-2026-78680 json | NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot... | |
| CVE-2026-78679 json | GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference p... | |
| CVE-2026-78678 json | GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --content... | |
| CVE-2026-78677 json | GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git di... | |
| CVE-2026-78676 json | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant... | |
| CVE-2026-78675 json | GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file c... | |
| CVE-2026-76846 json | Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to sy... | |
| CVE-2026-76839 json | Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offse... | |
| CVE-2026-75575 json | Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may invo... | |
| CVE-2026-75574 json | The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsa... | |
| CVE-2026-72702 json | Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which ... | |
| CVE-2026-72701 json | Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison ... | |
| CVE-2026-72700 json | The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation toke... | |
| CVE-2026-72699 json | The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() met... | |
| CVE-2026-72698 json | Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing conte... | |
| CVE-2026-72697 json | Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to validate ... | |
| CVE-2026-72696 json | Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attack... | |
| CVE-2026-72695 json | Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users ... | |
| CVE-2026-56710 json | Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction ... | |
| CVE-2026-56709 json | Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bear... | |
| CVE-2026-56708 json | Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attackers ... | |
| CVE-2026-56707 json | Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects short... | |
| CVE-2026-56706 json | Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (format (r... | |
| CVE-2026-56705 json | Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attack... | |
| CVE-2026-56704 json | Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without prope... | |
| CVE-2026-73886 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-62292 json | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image using... | |
| CVE-2026-56703 json | Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked... | |
| CVE-2026-56702 json | Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows a... | |
| CVE-2026-52875 json | Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-schedul... | |
| CVE-2026-50186 json | 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manag... | |
| CVE-2026-34968 json | Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fai... | |
| CVE-2026-34967 json | Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns ... | |
| CVE-2026-34964 json | Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which o... | |
| CVE-2026-34959 json | Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-... | |
| CVE-2026-19801 json | The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable... | |
| CVE-2026-16434 json | Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-84... | |
| CVE-2026-15023 json | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection via... | |
| CVE-2026-10630 json | The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is... | |
| CVE-2026-73885 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-73884 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-73883 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-73882 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-73881 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-73880 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-73879 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-73878 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-73867 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-73325 json | Fujitsu Research's OneCompression library before 1.2.1 contains an unsafe deserialization vulnerability that allows attackers... | |
| CVE-2026-71155 json | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version ... | |
| CVE-2026-71128 json | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is... | |
| CVE-2026-71127 json | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is... | |
| CVE-2026-66766 json | SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnera... | |
| CVE-2026-59183 json | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industr... | |
| CVE-2026-55373 json | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industr... | |
| CVE-2026-55371 json | OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in th... | |
| CVE-2026-55059 json | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industr... | |
| CVE-2026-54920 json | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industr... | |
| CVE-2026-53532 json | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industr... | |
| CVE-2026-48304 json | Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vu... | |
| CVE-2026-48301 json | Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vu... | |
| CVE-2026-48300 json | Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vu... | |
| CVE-2026-48299 json | Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vu... | |
| CVE-2026-48297 json | Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vu... | |
| CVE-2026-48289 json | Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerabi... |