CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-65767 json Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an...
CVE-2026-72888 json Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_requir...
CVE-2026-72887 json Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in ...
CVE-2026-65769 json Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to discl...
CVE-2026-19349 json Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow ...
CVE-2026-10840 json A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:a...
CVE-2026-9804 json A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a pa...
CVE-2025-1244 json A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arb...
CVE-2026-13201 json A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to o...
CVE-2026-74797 json OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciousl...
CVE-2026-74796 json OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers c...
CVE-2026-74795 json Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not en...
CVE-2026-74794 json Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property ...
CVE-2026-74792 json Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing...
CVE-2026-74791 json Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached te...
CVE-2026-74790 json Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused Templa...
CVE-2026-74789 json Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive...
CVE-2026-74788 json Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_...
CVE-2026-74787 json Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth...
CVE-2026-74786 json Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of-service vulnerability in which the LimitToString safet...
CVE-2026-74785 json Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing ...
CVE-2026-74784 json Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null...
CVE-2026-74783 json Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent ...
CVE-2026-73062 json Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allo...
CVE-2026-73061 json Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to wri...
CVE-2026-73060 json Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that...
CVE-2026-73059 json stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChannel pe...
CVE-2026-73058 json stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthentica...
CVE-2026-73057 json stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of...
CVE-2026-74251 json Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attrib...
CVE-2026-73056 json SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the...
CVE-2025-5318 json A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handl...
CVE-2025-5278 json A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The prog...
CVE-2025-4373 json A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the posi...
CVE-2024-58375 json OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into stat...
CVE-2024-11831 json A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not prope...
CVE-2026-13622 json A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler d...
CVE-2026-7163 json A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multiclu...
CVE-2026-4878 json A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in t...
CVE-2025-2842 json A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed b...
CVE-2025-2786 json A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploy...
CVE-2026-7374 json A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit pe...
CVE-2025-6020 json A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allow...
CVE-2024-45497 json A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount ...
CVE-2026-17107 json A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHA...
CVE-2026-16242 json A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was star...
CVE-2026-4740 json A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Impro...
CVE-2025-7425 json A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory manage...
CVE-2025-5914 json A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() fu...
CVE-2026-49332 json A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forw...
CVE-2026-1784 json The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that...
CVE-2026-74578 json In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force synchronous processing on...
CVE-2026-46579 json A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend do...
CVE-2024-13784 json The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in...
CVE-2026-2497 json The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter a...
CVE-2026-18347 json The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass ...
CVE-2026-17608 json The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2026-2357 json The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' sh...
CVE-2026-17604 json The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal i...
CVE-2026-17087 json The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization b...
CVE-2026-13424 json The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2026-12998 json The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Dire...
CVE-2026-10734 json The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all ver...
CVE-2026-9767 json The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order...
CVE-2026-19934 json A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /...
CVE-2026-19728 json The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entit...
CVE-2026-19726 json The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing...
CVE-2026-19725 json The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthent...
CVE-2026-19717 json The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its...
CVE-2026-19714 json The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, ...
CVE-2026-19712 json The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a pag...
CVE-2026-19711 json The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actu...
CVE-2026-19613 json The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater dat...
CVE-2026-2283 json The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions up to,...
CVE-2026-18653 json The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statemen...
CVE-2026-18402 json The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2026-18316 json The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability...
CVE-2026-17582 json The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7 via ...
CVE-2026-17581 json The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 'therma...
CVE-2026-17533 json The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to ...
CVE-2026-16775 json The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-16758 json The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all vers...
CVE-2026-15790 json The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0....
CVE-2026-15604 json The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2....
CVE-2026-15384 json The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authent...
CVE-2026-15351 json The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to ge...
CVE-2026-15345 json The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization by...
CVE-2026-15056 json The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulner...
CVE-2026-13712 json The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputt...
CVE-2026-10035 json The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and incl...
CVE-2026-2671 json A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionality of...
CVE-2026-19933 json A weakness has been identified in DefaultFuction Customer-Relationship-Management-In-C-Project 2.0. Impacted is the function ...
CVE-2026-19932 json A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects the function GroovyShell...
CVE-2026-18432 json The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includ...
CVE-2026-18385 json The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePre...
CVE-2026-17123 json The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including...
CVE-2026-16779 json The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2....
CVE-2026-16099 json The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val...
CVE-2026-16098 json The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2...
CVE-2026-16079 json The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content in a...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report