CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-16766 json | Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Optio... | |
| CVE-2026-7163 json | A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multiclu... | |
| CVE-2025-11393 json | A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this... | |
| CVE-2026-7374 json | A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit pe... | |
| CVE-2026-10681 json | In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread pe... | |
| CVE-2026-66013 json | OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthen... | |
| CVE-2026-66012 json | SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by ... | |
| CVE-2026-66011 json | ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options ar... | |
| CVE-2021-47927 json | WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated atta... | |
| CVE-2021-47926 json | Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inje... | |
| CVE-2021-47925 json | CMDBuild 3.3.2 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject arb... | |
| CVE-2021-47924 json | Ultimate Product Catalogue 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to ... | |
| CVE-2021-47923 json | OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitra... | |
| CVE-2026-42453 json | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to versio... | |
| CVE-2026-42452 json | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to versio... | |
| CVE-2026-32683 json | Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmissio... | |
| CVE-2026-3208 json | The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing ... | |
| CVE-2026-1749 json | There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user t... | |
| CVE-2025-71256 json | In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional ex... | |
| CVE-2025-71253 json | In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional e... | |
| CVE-2025-15634 json | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sen... | |
| CVE-2025-15633 json | An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges ... | |
| CVE-2021-47922 json | Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject ... | |
| CVE-2021-47910 json | AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to in... | |
| CVE-2021-47907 json | Rocket LMS 1.1 contains a persistent cross-site scripting vulnerability in the support ticket module that allows authenticate... | |
| CVE-2026-40934 json | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentic... | |
| CVE-2026-32936 json | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized... | |
| CVE-2026-32934 json | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into u... | |
| CVE-2026-32699 json | FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to... | |
| CVE-2026-32603 json | Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial of s... | |
| CVE-2026-31893 json | Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any local... | |
| CVE-2026-31835 json | Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authentication flo... | |
| CVE-2026-30923 json | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity... | |
| CVE-2026-28780 json | Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP... | |
| CVE-2026-27960 json | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 throug... | |
| CVE-2026-25589 json | RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does ... | |
| CVE-2026-25588 json | RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not pro... | |
| CVE-2025-71251 json | In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with n... | |
| CVE-2024-52911 json | Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is 0.14... | |
| CVE-2026-33023 json | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built with t... | |
| CVE-2026-33021 json | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-after-f... | |
| CVE-2026-32649 json | A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras. | |
| CVE-2026-32644 json | Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys. | |
| CVE-2026-28747 json | A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be... | |
| CVE-2026-27785 json | Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials. | |
| CVE-2026-25243 json | Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly va... | |
| CVE-2026-23773 json | Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A lo... | |
| CVE-2026-23631 json | Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can... | |
| CVE-2026-23479 json | Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle a... | |
| CVE-2026-1460 json | A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyx... | |
| CVE-2026-0711 json | A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions throu... | |
| CVE-2026-33020 json | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer ov... | |
| CVE-2026-27307 json | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could... | |
| CVE-2026-27301 json | Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to me... | |
| CVE-2026-27300 json | Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could lead... | |
| CVE-2026-27299 json | Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead to ar... | |
| CVE-2026-27298 json | Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion')... | |
| CVE-2026-27297 json | Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that cou... | |
| CVE-2026-27296 json | Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that cou... | |
| CVE-2026-27295 json | Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitr... | |
| CVE-2026-27294 json | Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file,... | |
| CVE-2026-27293 json | Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in ... | |
| CVE-2026-27292 json | Adobe Framemaker versions 2022.8 and earlier are affected by a Use After Free vulnerability that could result in arbitrary co... | |
| CVE-2026-27290 json | Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow attacker... | |
| CVE-2026-27306 json | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result ... | |
| CVE-2026-27305 json | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Director... | |
| CVE-2026-27304 json | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result ... | |
| CVE-2026-27289 json | Photoshop Desktop versions 27.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, ... | |
| CVE-2026-27282 json | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result ... | |
| CVE-2026-25133 json | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-sit... | |
| CVE-2026-24893 json | openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior... | |
| CVE-2025-15565 json | The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on ... | |
| CVE-2026-32225 json | Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | |
| CVE-2026-32224 json | Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-32223 json | Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical ... | |
| CVE-2026-32222 json | Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-32221 json | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. | |
| CVE-2026-32220 json | Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a secu... | |
| CVE-2026-3199 json | A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authen... | |
| CVE-2026-40025 json | The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wra... | |
| CVE-2026-40024 json | The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files t... | |
| CVE-2026-30818 json | An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent atta... | |
| CVE-2026-30817 json | An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent... | |
| CVE-2026-30816 json | An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjac... | |
| CVE-2026-30815 json | An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent att... | |
| CVE-2026-30814 json | A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker ... | |
| CVE-2026-27806 json | Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation fl... | |
| CVE-2026-23869 json | A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parce... | |
| CVE-2026-2942 json | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in... | |
| CVE-2026-20709 json | Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Pr... | |
| CVE-2026-0814 json | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ... | |
| CVE-2026-0811 json | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... | |
| CVE-2025-50673 json | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in... | |
| CVE-2025-50672 json | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink... | |
| CVE-2025-50671 json | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_ref.a... | |
| CVE-2025-50670 json | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_bwr.a... | |
| CVE-2025-50669 json | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of the w... | |
| CVE-2025-50668 json | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the s parameter in the /web_l... | |
| CVE-2025-50667 json | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the iface parameter in the /w... | |
| CVE-2025-50666 json | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /w... |