CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-73671 json | Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/p... | |
| CVE-2026-73670 json | A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inj... | |
| CVE-2026-73576 json | In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integ... | |
| CVE-2026-73575 json | In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Se... | |
| CVE-2026-73574 json | In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client du... | |
| CVE-2026-73573 json | In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing ... | |
| CVE-2026-73572 json | In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic ... | |
| CVE-2026-73571 json | An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization valid... | |
| CVE-2026-73570 json | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp packa... | |
| CVE-2026-73559 json | vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRe... | |
| CVE-2026-73533 json | Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served throu... | |
| CVE-2026-73532 json | Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served throug... | |
| CVE-2026-73515 json | PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a ... | |
| CVE-2026-73514 json | The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulner... | |
| CVE-2026-73558 json | vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d... | |
| CVE-2026-73509 json | OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler i... | |
| CVE-2026-73505 json | Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() fu... | |
| CVE-2026-70462 json | rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows atta... | |
| CVE-2026-70458 json | rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering ... | |
| CVE-2026-70454 json | rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vuln... | |
| CVE-2026-66256 json | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache... | |
| CVE-2026-65936 json | A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information. S... | |
| CVE-2026-65935 json | Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.... | |
| CVE-2026-65934 json | An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module. See vulnerability B-E10 i... | |
| CVE-2026-63426 json | During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an a... | |
| CVE-2026-63425 json | During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager ... | |
| CVE-2026-63424 json | During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a ... | |
| CVE-2026-55401 json | CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57.... | |
| CVE-2026-55400 json | CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated sess... | |
| CVE-2026-19744 json | Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitr... | |
| CVE-2026-19710 json | A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown f... | |
| CVE-2026-19487 json | Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the ... | |
| CVE-2026-6387 json | A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated u... | |
| CVE-2026-73403 json | Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions. | |
| CVE-2026-73401 json | Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions. | |
| CVE-2026-73357 json | Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions. | |
| CVE-2026-73353 json | Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. | |
| CVE-2026-73349 json | Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. | |
| CVE-2026-73346 json | Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. | |
| CVE-2026-73344 json | Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. | |
| CVE-2026-73340 json | Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. | |
| CVE-2026-63423 json | During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager fo... | |
| CVE-2026-53802 json | rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync ... | |
| CVE-2026-53798 json | rsync tbefore 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allow... | |
| CVE-2026-53794 json | rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=... | |
| CVE-2026-53790 json | rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrar... | |
| CVE-2026-53785 json | rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intend... | |
| CVE-2026-15994 json | During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo ... | |
| CVE-2026-14256 json | ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, ... | |
| CVE-2026-12036 json | An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantag... | |
| CVE-2026-73188 json | Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions. | |
| CVE-2026-67991 json | crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-ser... | |
| CVE-2026-67990 json | basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and P... | |
| CVE-2026-67986 json | amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in Aw... | |
| CVE-2026-66704 json | Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. | |
| CVE-2026-66700 json | Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions. | |
| CVE-2026-66698 json | Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions. | |
| CVE-2026-66697 json | Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions... | |
| CVE-2026-66693 json | Subscriber Broken Access Control in Motors <= 1.4.113 versions. | |
| CVE-2026-66691 json | Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. | |
| CVE-2026-66689 json | Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker <= 2.0.0 versions. | |
| CVE-2026-66687 json | Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions. | |
| CVE-2026-66661 json | Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions. | |
| CVE-2026-66660 json | Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions. | |
| CVE-2026-66658 json | Subscriber SQL Injection in Reviewer <= 3.14.2 versions. | |
| CVE-2026-66657 json | Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. | |
| CVE-2026-66656 json | Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. | |
| CVE-2026-66655 json | Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions. | |
| CVE-2026-66654 json | Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions. | |
| CVE-2026-66653 json | Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. | |
| CVE-2026-66478 json | Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. | |
| CVE-2026-66472 json | Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. | |
| CVE-2026-66471 json | Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions. | |
| CVE-2026-66469 json | Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions. | |
| CVE-2026-66468 json | Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions. | |
| CVE-2026-66467 json | Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. | |
| CVE-2026-66466 json | Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Q... | |
| CVE-2026-66465 json | Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. | |
| CVE-2026-66464 json | Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions. | |
| CVE-2026-66463 json | Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions. | |
| CVE-2026-66462 json | Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions. | |
| CVE-2026-66461 json | Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. | |
| CVE-2026-66460 json | Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions. | |
| CVE-2026-66459 json | Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions. | |
| CVE-2026-66458 json | Unauthenticated SQL Injection in RealPress <= 1.1.2 versions. | |
| CVE-2026-66456 json | Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. | |
| CVE-2026-66455 json | Subscriber Broken Access Control in ReactPress <= 3.4.0 versions. | |
| CVE-2026-66454 json | Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions. | |
| CVE-2026-66453 json | Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. | |
| CVE-2026-66450 json | Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions. | |
| CVE-2026-66449 json | Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions. | |
| CVE-2026-66446 json | Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. | |
| CVE-2026-66444 json | Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions. | |
| CVE-2026-66443 json | Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions. | |
| CVE-2026-66441 json | Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions. | |
| CVE-2026-66436 json | Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. | |
| CVE-2026-66432 json | Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions. | |
| CVE-2026-66431 json | Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. | |
| CVE-2026-66430 json | Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | |
| CVE-2026-66429 json | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. |