CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-89276 json | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that c... | |
| CVE-2026-89275 json | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that c... | |
| CVE-2026-84412 json | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that c... | |
| CVE-2026-83660 json | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege... | |
| CVE-2026-82443 json | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege... | |
| CVE-2026-82013 json | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege... | |
| CVE-2026-82009 json | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injec... | |
| CVE-2026-82008 json | Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code ex... | |
| CVE-2026-82003 json | Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code ex... | |
| CVE-2026-88015 json | rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1... | |
| CVE-2026-88014 json | rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.72.0 unt... | |
| CVE-2026-83530 json | A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL e... | |
| CVE-2026-70915 json | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that ... | |
| CVE-2026-70913 json | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that ... | |
| CVE-2026-88013 json | rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 unt... | |
| CVE-2026-82010 json | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injec... | |
| CVE-2026-75723 json | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code exec... | |
| CVE-2026-75721 json | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that c... | |
| CVE-2026-75703 json | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that c... | |
| CVE-2026-75699 json | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that c... | |
| CVE-2026-21113 json | Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to i... | |
| CVE-2026-21112 json | Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsun... | |
| CVE-2026-21108 json | Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access ... | |
| CVE-2026-96889 json | A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate enti... | |
| CVE-2026-96826 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shazzad Hossain Khan W4... | |
| CVE-2026-96552 json | A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is... | |
| CVE-2026-96551 json | A vulnerability was determined in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Impacted is an unknown ... | |
| CVE-2026-96550 json | A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This issue affects the funct... | |
| CVE-2026-94183 json | Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode w... | |
| CVE-2026-87900 json | Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary file... | |
| CVE-2026-87899 json | Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privile... | |
| CVE-2026-87898 json | OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges. | |
| CVE-2026-86065 json | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoi... | |
| CVE-2026-86064 json | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket ro... | |
| CVE-2026-85475 json | A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is ge... | |
| CVE-2026-84724 json | An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The syste... | |
| CVE-2026-96872 json | Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda ... | |
| CVE-2026-96770 json | All published s2s-proxy versions through 0.2.2 are affected. In versions 0.1.16 through 0.2.2, TLS server listeners use Go's ... | |
| CVE-2026-96549 json | A vulnerability has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This vulnerability affe... | |
| CVE-2026-96545 json | An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes ... | |
| CVE-2026-96541 json | A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections witho... | |
| CVE-2026-95603 json | Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions. | |
| CVE-2026-95600 json | Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions. | |
| CVE-2026-95592 json | Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions. | |
| CVE-2026-95530 json | Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions. | |
| CVE-2026-95528 json | Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions. | |
| CVE-2026-95524 json | Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. | |
| CVE-2026-95522 json | Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. | |
| CVE-2026-95513 json | Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions. | |
| CVE-2026-94682 json | Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions. | |
| CVE-2026-94671 json | Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. | |
| CVE-2026-94498 json | Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions. | |
| CVE-2026-94457 json | Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions. | |
| CVE-2026-84721 json | A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification back... | |
| CVE-2026-84720 json | A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database co... | |
| CVE-2026-84719 json | A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-cop... | |
| CVE-2026-84718 json | A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Contr... | |
| CVE-2026-84717 json | A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook ... | |
| CVE-2026-84716 json | A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator... | |
| CVE-2026-84714 json | A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses tw... | |
| CVE-2026-84713 json | A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notific... | |
| CVE-2026-84712 json | A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ ... | |
| CVE-2026-84706 json | A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable inje... | |
| CVE-2026-84691 json | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message em... | |
| CVE-2026-84683 json | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, proje... | |
| CVE-2026-82409 json | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpd... | |
| CVE-2026-82407 json | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, core/kapp/validators/validators.go Reg... | |
| CVE-2026-82406 json | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/k... | |
| CVE-2026-82405 json | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the KleverUpdateAccountPermission buil... | |
| CVE-2026-75884 json | A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automou... | |
| CVE-2026-68492 json | An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote auth... | |
| CVE-2026-68490 json | Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts... | |
| CVE-2026-67238 json | RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, rabbit_pid_codec:decompose_from_binary/1 par... | |
| CVE-2026-66079 json | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, parse_array_primitive/2 f... | |
| CVE-2026-66076 json | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, is_authorized/2 ca... | |
| CVE-2026-66070 json | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 returned t... | |
| CVE-2026-94181 json | An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <sel... | |
| CVE-2026-94179 json | Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions. | |
| CVE-2026-94168 json | Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. | |
| CVE-2026-94118 json | Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions. | |
| CVE-2026-93774 json | Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions. | |
| CVE-2026-93772 json | Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions. | |
| CVE-2026-93620 json | Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions. | |
| CVE-2026-93529 json | Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions. | |
| CVE-2026-93526 json | Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions. | |
| CVE-2026-93513 json | Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions. | |
| CVE-2026-93421 json | Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp_... | |
| CVE-2026-92730 json | LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-part... | |
| CVE-2026-92700 json | Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/fileserv... | |
| CVE-2026-92692 json | Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected ... | |
| CVE-2026-92284 json | Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/replacer... | |
| CVE-2026-90905 json | Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.... | |
| CVE-2026-90904 json | Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extensio... | |
| CVE-2026-90903 json | Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store ext... | |
| CVE-2026-90902 json | Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0... | |
| CVE-2026-90901 json | Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1... | |
| CVE-2026-90900 json | Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store ext... | |
| CVE-2026-90899 json | Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0... | |
| CVE-2026-84502 json | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated ... | |
| CVE-2026-84486 json | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal ... |