CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-66411 json | DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unauthenti... | |
| CVE-2026-66410 json | Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or altered. | |
| CVE-2026-66409 json | DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be ... | |
| CVE-2026-66408 json | The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected p... | |
| CVE-2026-66407 json | DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key... | |
| CVE-2026-66406 json | DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle attack ... | |
| CVE-2026-66405 json | DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the aff... | |
| CVE-2026-66404 json | DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity lo... | |
| CVE-2026-66403 json | DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information sto... | |
| CVE-2026-21084 json | Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information. | |
| CVE-2026-21083 json | Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. | |
| CVE-2026-21082 json | Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. | |
| CVE-2026-21081 json | Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to ... | |
| CVE-2026-21080 json | Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sens... | |
| CVE-2026-21079 json | Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmi... | |
| CVE-2026-21078 json | Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacen... | |
| CVE-2026-21077 json | Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. | |
| CVE-2026-71226 json | Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted... | |
| CVE-2026-71225 json | A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful ... | |
| CVE-2026-21076 json | Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. | |
| CVE-2026-21075 json | Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access s... | |
| CVE-2026-21074 json | Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bi... | |
| CVE-2026-21073 json | Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary acti... | |
| CVE-2026-21072 json | Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of... | |
| CVE-2026-21071 json | Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-... | |
| CVE-2026-21070 json | Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive in... | |
| CVE-2026-21069 json | Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attacker... | |
| CVE-2026-21068 json | Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arb... | |
| CVE-2026-21067 json | Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | |
| CVE-2026-21066 json | Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-... | |
| CVE-2026-21065 json | Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds ... | |
| CVE-2026-21064 json | Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. | |
| CVE-2026-21063 json | Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to byp... | |
| CVE-2026-14226 json | The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-list... | |
| CVE-2026-64940 json | Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expressi... | |
| CVE-2026-57279 json | Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be e... | |
| CVE-2026-21062 json | Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. | |
| CVE-2026-21061 json | Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related fun... | |
| CVE-2026-21060 json | Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across... | |
| CVE-2026-21059 json | Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers ... | |
| CVE-2026-21058 json | Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Sams... | |
| CVE-2026-19089 json | The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepte... | |
| CVE-2026-19077 json | The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete... | |
| CVE-2026-19075 json | All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiov... | |
| CVE-2026-19074 json | The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vul... | |
| CVE-2026-19053 json | The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL sta... | |
| CVE-2026-19049 json | The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and ... | |
| CVE-2026-18960 json | The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowin... | |
| CVE-2026-18946 json | The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through ... | |
| CVE-2026-18934 json | The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to ed... | |
| CVE-2026-18786 json | The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and uncon... | |
| CVE-2026-18666 json | The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before usi... | |
| CVE-2026-18470 json | The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the accoun... | |
| CVE-2026-18469 json | The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-... | |
| CVE-2026-18468 json | The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account ... | |
| CVE-2026-18200 json | The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user makin... | |
| CVE-2026-18030 json | The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password chan... | |
| CVE-2026-17542 json | The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector end... | |
| CVE-2026-17541 json | The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing una... | |
| CVE-2026-17540 json | The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authent... | |
| CVE-2026-17023 json | The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state ... | |
| CVE-2026-17022 json | The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loa... | |
| CVE-2026-17021 json | The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modifica... | |
| CVE-2026-17020 json | The Salon Booking System WordPress plugin through 10.30.33 does not verify that a requested booking belongs to the caller on... | |
| CVE-2026-17019 json | The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does... | |
| CVE-2026-17018 json | The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict whi... | |
| CVE-2026-17016 json | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount act... | |
| CVE-2026-17012 json | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal ... | |
| CVE-2026-17010 json | The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before output... | |
| CVE-2026-16985 json | The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written b... | |
| CVE-2026-16949 json | The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL state... | |
| CVE-2026-16299 json | The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauth... | |
| CVE-2026-16298 json | The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticat... | |
| CVE-2026-16257 json | The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose o... | |
| CVE-2026-15238 json | The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, ... | |
| CVE-2026-15237 json | The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST end... | |
| CVE-2026-15229 json | The Pinpoint Booking System WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allow... | |
| CVE-2026-15047 json | The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an in... | |
| CVE-2026-14941 json | The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several s... | |
| CVE-2026-14860 json | The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-... | |
| CVE-2026-14293 json | The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from ... | |
| CVE-2026-14238 json | The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body befo... | |
| CVE-2026-14237 json | The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization c... | |
| CVE-2026-14211 json | The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee ... | |
| CVE-2026-14206 json | The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a sa... | |
| CVE-2026-13701 json | The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it on the... | |
| CVE-2026-13600 json | The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a W... | |
| CVE-2026-13170 json | The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a l... | |
| CVE-2026-13133 json | A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded ... | |
| CVE-2026-12971 json | The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing us... | |
| CVE-2026-12570 json | A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .ke... | |
| CVE-2026-17519 json | Rejected reason: none | |
| CVE-2026-72522 json | libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as hi... | |
| CVE-2026-19389 json | Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) w... | |
| CVE-2026-19387 json | A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI AD... | |
| CVE-2026-19384 json | A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown fu... | |
| CVE-2025-12150 json | A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configu... | |
| CVE-2026-19383 json | A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_exec of... | |
| CVE-2026-19382 json | A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys ... | |
| CVE-2026-19381 json | A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown f... |