CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-84820 json Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 ve...
CVE-2026-84818 json Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.
CVE-2026-84817 json Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.
CVE-2026-81806 json Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This is...
CVE-2026-81802 json Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.
CVE-2026-81798 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allow...
CVE-2026-81792 json Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions.
CVE-2026-81790 json Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting...
CVE-2026-81781 json Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Acce...
CVE-2026-76561 json A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import function...
CVE-2026-76560 json A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's e...
CVE-2026-71375 json Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Co...
CVE-2026-71374 json Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component C...
CVE-2026-63622 json A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a s...
CVE-2026-48888 json Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue aff...
CVE-2026-19843 json A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP ...
CVE-2026-18922 json A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliar...
CVE-2026-18453 json A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allo...
CVE-2026-18355 json A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(),...
CVE-2026-16118 json A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmi...
CVE-2026-9165 json A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL que...
CVE-2026-7867 json A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking ...
CVE-2026-78701 json A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication ...
CVE-2026-76958 json SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal compon...
CVE-2026-16279 json An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DE...
CVE-2026-86519 json A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_act...
CVE-2026-86518 json A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edi...
CVE-2026-86517 json A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of th...
CVE-2026-86516 json A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function...
CVE-2026-77699 json Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loadi...
CVE-2026-77698 json Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent...
CVE-2026-20517 json In geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privi...
CVE-2026-20512 json In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalati...
CVE-2026-20511 json In SurfaceFlinger, there is a possible memory corruption due to use after free. This could lead to local escalation of privil...
CVE-2026-20510 json In camera middleware, there is a possible escalation of privilege due to double free. This could lead to local escalation of ...
CVE-2026-20509 json In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p...
CVE-2026-20508 json In Power HAL, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privi...
CVE-2026-86218 json N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
CVE-2026-20507 json In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privi...
CVE-2026-20506 json In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privi...
CVE-2026-20502 json In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privil...
CVE-2026-20501 json In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privil...
CVE-2026-86515 json A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/...
CVE-2026-86514 json A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c o...
CVE-2026-86513 json A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePoi...
CVE-2026-86512 json A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOp...
CVE-2026-86511 json A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal...
CVE-2026-75811 json Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardwar...
CVE-2026-75810 json Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing dri...
CVE-2026-75809 json Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disab...
CVE-2026-75808 json Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service ...
CVE-2026-19397 json Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to ...
CVE-2026-18023 json Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensi...
CVE-2026-16006 json Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to ob...
CVE-2026-16005 json Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IO...
CVE-2026-16004 json Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PC...
CVE-2026-16003 json Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identi...
CVE-2026-12962 json A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user...
CVE-2026-86510 json A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Con...
CVE-2026-75538 json An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow...
CVE-2026-74994 json The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple dir...
CVE-2026-86509 json A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpac...
CVE-2026-82710 json Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious pac...
CVE-2026-76977 json SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacke...
CVE-2026-76971 json Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker coul...
CVE-2026-76969 json @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications wi...
CVE-2026-76968 json SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to ...
CVE-2026-76967 json SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during appli...
CVE-2026-76963 json Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker...
CVE-2026-76962 json SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. ...
CVE-2026-76961 json SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certai...
CVE-2026-76960 json SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certai...
CVE-2026-76959 json SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certai...
CVE-2026-66768 json SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend sys...
CVE-2026-66767 json SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet...
CVE-2026-58240 json SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during...
CVE-2026-58234 json SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested e...
CVE-2026-44766 json SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input i...
CVE-2026-44756 json A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, a...
CVE-2026-74835 json The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects...
CVE-2026-73812 json httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presenc...
CVE-2026-73276 json Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities. This is...
CVE-2026-73270 json Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to rea...
CVE-2026-71562 json Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP inets httpc allows a malicious or compromised ...
CVE-2026-71380 json Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote...
CVE-2026-70409 json Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP s...
CVE-2026-70405 json Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade avail...
CVE-2026-70399 json Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote...
CVE-2026-69664 json Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote...
CVE-2026-66835 json Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_...
CVE-2026-66357 json httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a ...
CVE-2026-59696 json Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP stdlib allows a remote attacker to degrade ava...
CVE-2026-59250 json Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt th...
CVE-2026-59247 json Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute forged ...
CVE-2026-55951 json The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The m...
CVE-2026-48859 json Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote u...
CVE-2026-43965 json Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/package...
CVE-2026-42795 json Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the gen...
CVE-2026-32685 json Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write outs...
CVE-2026-32146 json Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modi...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report