CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-88770 json | A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue oc... | |
| CVE-2026-88763 json | A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communicati... | |
| CVE-2026-85546 json | MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, re... | |
| CVE-2026-81624 json | Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocke... | |
| CVE-2026-80354 json | Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom... | |
| CVE-2026-80352 json | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability ... | |
| CVE-2026-80351 json | Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An... | |
| CVE-2026-7188 json | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Tech... | |
| CVE-2026-87804 json | Rejected reason: no security impact | |
| CVE-2026-82925 json | The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key pro... | |
| CVE-2026-82582 json | An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may allow an unauthorized atta... | |
| CVE-2026-81635 json | A cross-site scripting vulnerability exists in SHIRASAGI, which may allow an attacker to execute an arbitrary script in the w... | |
| CVE-2026-81431 json | The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced during registr... | |
| CVE-2026-78361 json | The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks ... | |
| CVE-2026-77771 json | The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-fac... | |
| CVE-2026-77770 json | The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated ... | |
| CVE-2026-19840 json | The Notiqoo WordPress plugin before 1.4.14 does not have capability checks on several of its AJAX actions and builds the nam... | |
| CVE-2026-19439 json | The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying ... | |
| CVE-2026-19436 json | The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value of the gift card coupon i... | |
| CVE-2026-0304 json | A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user ... | |
| CVE-2026-0303 json | A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checko... | |
| CVE-2026-0302 json | An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitra... | |
| CVE-2026-85645 json | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected ... | |
| CVE-2026-84939 json | Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malfor... | |
| CVE-2026-82079 json | A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attac... | |
| CVE-2026-75880 json | An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive e... | |
| CVE-2026-67593 json | A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker... | |
| CVE-2026-57967 json | An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ... | |
| CVE-2026-57822 json | When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized... | |
| CVE-2026-49364 json | An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the ... | |
| CVE-2026-0310 json | A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauth... | |
| CVE-2026-0309 json | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass sy... | |
| CVE-2026-0308 json | A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated a... | |
| CVE-2026-0307 json | Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to esc... | |
| CVE-2026-0306 json | A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a ... | |
| CVE-2026-0305 json | An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to acce... | |
| CVE-2026-87931 json | A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacte... | |
| CVE-2026-80924 json | In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - use kfree_sensitive() for derived key buf... | |
| CVE-2026-80921 json | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing ... | |
| CVE-2026-80914 json | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix use-after-free of listener socket in... | |
| CVE-2026-49363 json | An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE... | |
| CVE-2026-49362 json | An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker ... | |
| CVE-2026-17523 json | In the Linux kernel, the following vulnerability has been resolved: can: bcm: switch timer to HRTIMER_MODE_SOFT and remove h... | |
| CVE-2024-22373 json | An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Gr... | |
| CVE-2026-76562 json | The Sidebar Manager Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sbm_description' paramet... | |
| CVE-2026-18594 json | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin... | |
| CVE-2026-4657 json | The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the control_selectors meta field ... | |
| CVE-2026-85103 json | A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitr... | |
| CVE-2026-85102 json | Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthentic... | |
| CVE-2026-67401 json | A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack c... | |
| CVE-2026-18386 json | The WP BackItUp Community Edition plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includ... | |
| CVE-2026-15823 json | The Builderall Cheetah For Wp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... | |
| CVE-2026-15820 json | The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attributes' ... | |
| CVE-2026-15796 json | The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bg_video_service_url' Set... | |
| CVE-2026-15019 json | The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl... | |
| CVE-2026-14873 json | The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to... | |
| CVE-2026-87654 json | Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary... | |
| CVE-2026-87650 json | Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrar... | |
| CVE-2026-87648 json | Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised t... | |
| CVE-2026-87646 json | Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary c... | |
| CVE-2026-87644 json | Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had comp... | |
| CVE-2026-87643 json | Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execut... | |
| CVE-2026-87639 json | Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the rend... | |
| CVE-2026-87638 json | Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitra... | |
| CVE-2026-87637 json | Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary... | |
| CVE-2026-87636 json | Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code... | |
| CVE-2026-87634 json | Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbit... | |
| CVE-2026-87633 json | Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside th... | |
| CVE-2026-87628 json | Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary ... | |
| CVE-2026-87625 json | Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execu... | |
| CVE-2026-87621 json | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially e... | |
| CVE-2026-87618 json | Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who... | |
| CVE-2026-87617 json | Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to... | |
| CVE-2026-87616 json | Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had comp... | |
| CVE-2026-87613 json | Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially... | |
| CVE-2026-87612 json | Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the s... | |
| CVE-2026-87609 json | Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary co... | |
| CVE-2026-87607 json | Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute a... | |
| CVE-2026-87604 json | Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the rendere... | |
| CVE-2026-87601 json | Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the s... | |
| CVE-2026-87588 json | Use after free in Chromecast in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code insi... | |
| CVE-2026-87587 json | Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the s... | |
| CVE-2026-87585 json | Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute ... | |
| CVE-2026-87582 json | Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the ren... | |
| CVE-2026-87581 json | Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to... | |
| CVE-2026-87579 json | Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside ... | |
| CVE-2026-87578 json | Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to execute arbitrary code out... | |
| CVE-2026-87572 json | Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer proc... | |
| CVE-2026-87558 json | Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary c... | |
| CVE-2026-87554 json | Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitr... | |
| CVE-2026-87553 json | Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromi... | |
| CVE-2026-87547 json | Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging soc... | |
| CVE-2026-87542 json | Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside th... | |
| CVE-2026-87537 json | Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the... | |
| CVE-2026-87536 json | Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the s... | |
| CVE-2026-87533 json | Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside... | |
| CVE-2026-87530 json | Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local ... | |
| CVE-2026-87529 json | Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute ar... | |
| CVE-2026-87528 json | Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute... | |
| CVE-2026-87527 json | Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside ... |