CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-86180 json | A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unkno... | |
| CVE-2026-86179 json | A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-... | |
| CVE-2026-86172 json | A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/del... | |
| CVE-2026-86171 json | A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules... | |
| CVE-2026-85038 json | The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin b... | |
| CVE-2026-84219 json | The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, al... | |
| CVE-2026-84028 json | The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it i... | |
| CVE-2026-75793 json | The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress a... | |
| CVE-2026-18480 json | The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same accoun... | |
| CVE-2026-13159 json | The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, all... | |
| CVE-2026-86170 json | A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/... | |
| CVE-2026-86168 json | A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown functi... | |
| CVE-2026-86167 json | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/form... | |
| CVE-2025-7195 json | Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a ra... | |
| CVE-2026-86166 json | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/... | |
| CVE-2026-86165 json | A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin... | |
| CVE-2026-86164 json | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the fi... | |
| CVE-2026-86163 json | A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /... | |
| CVE-2026-2100 json | A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remo... | |
| CVE-2025-49796 json | A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corru... | |
| CVE-2025-49794 json | A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstance... | |
| CVE-2025-7425 json | A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory manage... | |
| CVE-2025-5914 json | A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() fu... | |
| CVE-2025-5278 json | A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The prog... | |
| CVE-2026-86218 json | N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. | |
| CVE-2026-86162 json | A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax... | |
| CVE-2026-86161 json | A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file... | |
| CVE-2026-86160 json | A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the... | |
| CVE-2026-86159 json | A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?actio... | |
| CVE-2026-75816 json | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versi... | |
| CVE-2026-18056 json | The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in al... | |
| CVE-2026-16310 json | The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1... | |
| CVE-2026-86153 json | A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the fil... | |
| CVE-2026-86152 json | A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Fun... | |
| CVE-2026-85046 json | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the s... | |
| CVE-2026-10840 json | A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:a... | |
| CVE-2026-4878 json | A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in t... | |
| CVE-2025-1244 json | A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arb... | |
| CVE-2026-86151 json | A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/syste... | |
| CVE-2026-86150 json | A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/sof... | |
| CVE-2026-76161 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-76160 json | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-86149 json | A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckP... | |
| CVE-2026-86148 json | A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file A... | |
| CVE-2026-7163 json | A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multiclu... | |
| CVE-2026-86060 json | RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character,... | |
| CVE-2026-67281 json | RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session reta... | |
| CVE-2026-67279 json | RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempte... | |
| CVE-2026-67278 json | MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e... | |
| CVE-2026-67277 json | RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unaut... | |
| CVE-2026-67276 json | RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, ... | |
| CVE-2026-86206 json | A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixe... | |
| CVE-2026-86207 json | An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs | |
| CVE-2026-31912 json | libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor... | |
| CVE-2026-31911 json | libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon ... | |
| CVE-2026-18313 json | rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the... | |
| CVE-2026-18238 json | The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. ... | |
| CVE-2026-6554 json | libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward... | |
| CVE-2026-6244 json | libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. I... | |
| CVE-2026-0799 json | In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit intege... | |
| CVE-2026-82752 json | Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of ar... | |
| CVE-2026-76827 json | A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with o... | |
| CVE-2026-75485 json | A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object... | |
| CVE-2026-73834 json | A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Cust... | |
| CVE-2026-71846 json | A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets g... | |
| CVE-2026-71845 json | A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, inc... | |
| CVE-2026-71475 json | A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into ... | |
| CVE-2026-71474 json | A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can... | |
| CVE-2026-71468 json | A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuse... | |
| CVE-2026-64927 json | A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to... | |
| CVE-2025-2842 json | A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed b... | |
| CVE-2025-2786 json | A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploy... | |
| CVE-2024-11831 json | A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not prope... | |
| CVE-2026-18874 json | A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Mar... | |
| CVE-2025-5318 json | A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handl... | |
| CVE-2025-4373 json | A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the posi... | |
| CVE-2026-54100 json | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH... | |
| CVE-2026-54099 json | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-ap... | |
| CVE-2025-6020 json | A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allow... | |
| CVE-2026-76139 json | A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote sourc... | |
| CVE-2026-73267 json | A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions t... | |
| CVE-2026-73266 json | A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit ... | |
| CVE-2026-66795 json | A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperl... | |
| CVE-2026-66794 json | A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an u... | |
| CVE-2026-19130 json | A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific perm... | |
| CVE-2026-73269 json | A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a spec... | |
| CVE-2026-73268 json | A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update per... | |
| CVE-2026-17107 json | A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHA... | |
| CVE-2026-16242 json | A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was star... | |
| CVE-2026-10090 json | A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster... | |
| CVE-2026-10059 json | A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-s... | |
| CVE-2026-86145 json | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA... | |
| CVE-2026-78408 json | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later... | |
| CVE-2026-4740 json | A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Impro... | |
| CVE-2026-86197 json | Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss ... | |
| CVE-2026-86196 json | Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpo... | |
| CVE-2026-86195 json | grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the st... | |
| CVE-2026-86194 json | Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymo... | |
| CVE-2026-86193 json | grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-sup... | |
| CVE-2026-86192 json | SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint... |