CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-76166 json | A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multicast da... | |
| CVE-2026-59692 json | A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Sub... | |
| CVE-2026-59691 json | A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC se... | |
| CVE-2026-18942 json | A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This co... | |
| CVE-2026-76164 json | AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-priv... | |
| CVE-2026-75900 json | An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffe... | |
| CVE-2026-75589 json | Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time compa... | |
| CVE-2026-72889 json | Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the s... | |
| CVE-2026-58088 json | The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding program header... | |
| CVE-2026-58087 json | The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protecting ... | |
| CVE-2026-58086 json | As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed root user. Tracing conf... | |
| CVE-2026-58085 json | After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether the MAC verif... | |
| CVE-2026-58084 json | To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer's cl... | |
| CVE-2026-58083 json | While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on the kqueue's... | |
| CVE-2026-58082 json | The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character output. Some ISO-2... | |
| CVE-2026-58081 json | Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output bu... | |
| CVE-2026-49425 json | The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first zero ... | |
| CVE-2026-49424 json | The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not fi... | |
| CVE-2026-72210 json | In the Linux kernel, the following vulnerability has been resolved: ntfs: fix off-by-one in mapping pairs decoding bounds ch... | |
| CVE-2026-72203 json | In the Linux kernel, the following vulnerability has been resolved: ntfs: skip extent mft records in writeback to prevent de... | |
| CVE-2026-72200 json | In the Linux kernel, the following vulnerability has been resolved: ntfs: detect mapping-pairs LCN accumulator overflow The... | |
| CVE-2026-72198 json | In the Linux kernel, the following vulnerability has been resolved: ntfs: reject non-resident records for resident-only attr... | |
| CVE-2026-18621 json | A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening ... | |
| CVE-2026-0603 json | A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability... | |
| CVE-2025-9784 json | A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse c... | |
| CVE-2024-3884 json | A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinit... | |
| CVE-2026-75981 json | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated... | |
| CVE-2026-74484 json | In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: don't let an 'F' entry pin its own instance... | |
| CVE-2026-64158 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-49423 json | When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index for e... | |
| CVE-2026-49332 json | A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forw... | |
| CVE-2026-15780 json | The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cros... | |
| CVE-2026-15446 json | The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attrib... | |
| CVE-2026-49431 json | The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is able... | |
| CVE-2026-8810 json | On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password... | |
| CVE-2026-49430 json | The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a 32-bit integer for alloc... | |
| CVE-2026-49429 json | The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit integer for the... | |
| CVE-2026-49428 json | Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage ob... | |
| CVE-2026-49427 json | Pages belonging to largepage shared memory objects were not explicitly wired. When sendfile(2) transmitted such an object wi... | |
| CVE-2026-49426 json | When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of an internal setup functi... | |
| CVE-2026-49422 json | The RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace, then reacquires the loc... | |
| CVE-2026-49421 json | The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed to pass it ... | |
| CVE-2026-49420 json | The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewritten... | |
| CVE-2026-19842 json | The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the ce... | |
| CVE-2026-19782 json | The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, allowing any au... | |
| CVE-2026-19709 json | The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been gen... | |
| CVE-2026-19417 json | The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being serv... | |
| CVE-2026-19416 json | The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified, all... | |
| CVE-2026-19406 json | The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the re... | |
| CVE-2026-19056 json | The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into a... | |
| CVE-2026-19055 json | The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting th... | |
| CVE-2026-18937 json | The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sit... | |
| CVE-2026-18779 json | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing ... | |
| CVE-2026-18778 json | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing... | |
| CVE-2026-18777 json | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing ... | |
| CVE-2026-18776 json | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing... | |
| CVE-2026-18466 json | The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX acti... | |
| CVE-2026-18231 json | The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions... | |
| CVE-2026-18202 json | The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the fi... | |
| CVE-2026-18051 json | The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file nam... | |
| CVE-2026-18031 json | The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for t... | |
| CVE-2026-17565 json | The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to ... | |
| CVE-2026-16979 json | The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of ... | |
| CVE-2026-16950 json | The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a S... | |
| CVE-2026-16617 json | The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before output... | |
| CVE-2026-16616 json | The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by ... | |
| CVE-2026-16570 json | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameter... | |
| CVE-2026-16058 json | The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-ven... | |
| CVE-2026-15253 json | The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it i... | |
| CVE-2026-14861 json | The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification ... | |
| CVE-2026-14826 json | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST ro... | |
| CVE-2026-14825 json | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving ... | |
| CVE-2026-14334 json | The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG file... | |
| CVE-2026-14287 json | The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated request h... | |
| CVE-2026-14196 json | The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allowing i... | |
| CVE-2026-13175 json | The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or dele... | |
| CVE-2026-13174 json | The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing u... | |
| CVE-2026-13173 json | The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assignin... | |
| CVE-2026-13169 json | The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified,... | |
| CVE-2026-12983 json | The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing un... | |
| CVE-2026-11565 json | The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file managemen... | |
| CVE-2026-70408 json | An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administ... | |
| CVE-2026-66358 json | A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script. | |
| CVE-2026-59849 json | A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to... | |
| CVE-2026-59846 json | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters... | |
| CVE-2026-49419 json | When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller's current p... | |
| CVE-2026-49418 json | When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping range are m... | |
| CVE-2026-49415 json | During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are updated. Du... | |
| CVE-2026-19942 json | The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is v... | |
| CVE-2026-59842 json | A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the ... | |
| CVE-2026-76050 json | A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the f... | |
| CVE-2026-76049 json | A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of ... | |
| CVE-2026-67262 json | Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this v... | |
| CVE-2026-59915 json | Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability. A low p... | |
| CVE-2026-32657 json | Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell P... | |
| CVE-2026-17106 json | The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do ... | |
| CVE-2026-73373 json | Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dang... | |
| CVE-2026-71539 json | n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation allow... | |
| CVE-2026-70415 json | Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. An unauthenticated ... | |
| CVE-2026-67271 json | Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote... |