CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-55735 json Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim'...
CVE-2026-55734 json Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows...
CVE-2026-55733 json Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creati...
CVE-2026-54894 json Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creati...
CVE-2025-52936 json Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh.This issue affects sslh: befor...
CVE-2024-10918 json Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus respons...
CVE-2026-18536 json Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::Rand...
CVE-2026-15105 json A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file...
CVE-2026-67355 json guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain fiel...
CVE-2026-67354 json guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the opti...
CVE-2026-67353 json guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Se...
CVE-2026-67352 json luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authe...
CVE-2026-67344 json ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYPE ......
CVE-2026-67343 json ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authen...
CVE-2026-67342 json ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Promet...
CVE-2026-67341 json ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANG...
CVE-2026-67340 json ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) becaus...
CVE-2026-67339 json guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL han...
CVE-2026-67338 json JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate ...
CVE-2026-67337 json better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enable...
CVE-2026-67336 json better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise...
CVE-2026-67335 json better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backe...
CVE-2026-67334 json better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints...
CVE-2026-67333 json better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_...
CVE-2026-67332 json @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clie...
CVE-2026-67331 json better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by def...
CVE-2026-67330 json @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-bet...
CVE-2026-67329 json @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass...
CVE-2026-67328 json @better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that ...
CVE-2026-67327 json better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to a...
CVE-2026-67326 json GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers ...
CVE-2026-67325 json GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix...
CVE-2026-67324 json GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) whe...
CVE-2026-67323 json GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls...
CVE-2026-67322 json GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote U...
CVE-2026-67321 json axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys e...
CVE-2026-67320 json axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens m...
CVE-2026-67319 json axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the Java...
CVE-2026-67318 json axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies ...
CVE-2026-67317 json axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapte...
CVE-2026-67316 json axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has al...
CVE-2026-67315 json axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing request...
CVE-2026-67314 json axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapte...
CVE-2026-67313 json axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with de...
CVE-2026-67312 json axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (expos...
CVE-2026-67311 json Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to ...
CVE-2026-67310 json OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the se...
CVE-2026-67309 json Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's Re...
CVE-2026-67308 json Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arb...
CVE-2026-67307 json Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-...
CVE-2026-67306 json FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder functio...
CVE-2026-67305 json FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when proc...
CVE-2026-67304 json FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when read...
CVE-2026-67303 json FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == BytesReturned)) in serial_process_ir...
CVE-2026-67302 json FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redirection...
CVE-2026-67301 json FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and Pol...
CVE-2026-67300 json FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WIN...
CVE-2026-67299 json FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when...
CVE-2026-67298 json FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handl...
CVE-2026-67297 json FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in h...
CVE-2026-67296 json FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate m...
CVE-2026-67295 json FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to acce...
CVE-2026-67294 json FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side se...
CVE-2026-67293 json FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The T...
CVE-2026-67292 json FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gat...
CVE-2026-67291 json FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/gl...
CVE-2026-67290 json FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDE...
CVE-2026-67289 json FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RD...
CVE-2026-67288 json FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL ...
CVE-2026-66402 json FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_v...
CVE-2026-66401 json FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to ...
CVE-2026-10773 json The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char *...
CVE-2026-10772 json Rejected reason: ** DUPLICATE ** This CVE Record has been rejected by the Zephyr Project CNA. CVE-2026-10772 was assigned to ...
CVE-2026-2411 json Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose perm...
CVE-2025-71404 json better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/...
CVE-2025-71403 json better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs ...
CVE-2025-71402 json better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-out aft...
CVE-2026-6453 json The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. This is ...
CVE-2026-18435 json The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2026-18344 json The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' paramete...
CVE-2026-18062 json The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2026-18059 json The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exposu...
CVE-2026-17605 json The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion...
CVE-2026-17580 json The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Element...
CVE-2026-17571 json The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerab...
CVE-2026-17555 json The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in versions ...
CVE-2026-16685 json The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all ...
CVE-2026-16684 json The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact Meth...
CVE-2026-16635 json The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This...
CVE-2026-16614 json The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQL Inj...
CVE-2026-16144 json The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all ve...
CVE-2026-16091 json The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vul...
CVE-2026-16090 json The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vul...
CVE-2026-16087 json The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Injectio...
CVE-2026-15964 json The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in ...
CVE-2026-15951 json The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and incl...
CVE-2026-15950 json The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is...
CVE-2026-15662 json The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-15649 json The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortc...
CVE-2026-15645 json The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'nav' ...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report