CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-17953 json | Insufficient policy enforcement in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to by... | |
| CVE-2026-61174 json | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). Th... | |
| CVE-2026-59913 json | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical F... | |
| CVE-2026-59912 json | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerabilit... | |
| CVE-2026-38447 json | osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predi... | |
| CVE-2026-69153 json | PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Synta... | |
| CVE-2026-61524 json | WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that al... | |
| CVE-2026-61523 json | WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated admi... | |
| CVE-2026-41453 json | Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users wi... | |
| CVE-2026-38446 json | A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry ... | |
| CVE-2026-38444 json | osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extr... | |
| CVE-2026-18616 json | A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the ... | |
| CVE-2026-18615 json | A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publ... | |
| CVE-2026-18614 json | A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-... | |
| CVE-2026-18610 json | A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.aspx. Th... | |
| CVE-2026-18243 json | Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HT... | |
| CVE-2025-15631 json | A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorit... | |
| CVE-2025-15630 json | A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the ad... | |
| CVE-2025-15629 json | A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications b... | |
| CVE-2025-15628 json | Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controller... | |
| CVE-2025-15627 json | A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to est... | |
| CVE-2025-15544 json | A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associate... | |
| CVE-2025-9291 json | A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate... | |
| CVE-2026-67354 json | guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the opti... | |
| CVE-2026-67353 json | guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Se... | |
| CVE-2026-67344 json | ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYPE ...... | |
| CVE-2026-67342 json | ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Promet... | |
| CVE-2026-67341 json | ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANG... | |
| CVE-2026-67339 json | guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL han... | |
| CVE-2026-67337 json | better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enable... | |
| CVE-2026-67334 json | better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints... | |
| CVE-2026-58062 json | In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue ... | |
| CVE-2026-54894 json | Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creati... | |
| CVE-2026-20496 json | In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disc... | |
| CVE-2026-20495 json | In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escala... | |
| CVE-2026-20494 json | In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosur... | |
| CVE-2026-20491 json | In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service ... | |
| CVE-2026-20490 json | In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if ... | |
| CVE-2026-16540 json | The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to... | |
| CVE-2026-16064 json | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object... | |
| CVE-2026-8457 json | The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and includin... | |
| CVE-2026-67332 json | @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clie... | |
| CVE-2026-67329 json | @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass... | |
| CVE-2026-67327 json | better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to a... | |
| CVE-2026-67324 json | GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) whe... | |
| CVE-2026-67322 json | GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote U... | |
| CVE-2026-67319 json | axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the Java... | |
| CVE-2026-67317 json | axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapte... | |
| CVE-2026-67314 json | axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapte... | |
| CVE-2026-67312 json | axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (expos... | |
| CVE-2026-67307 json | Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-... | |
| CVE-2026-67304 json | FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when read... | |
| CVE-2026-67302 json | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redirection... | |
| CVE-2026-67301 json | FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and Pol... | |
| CVE-2026-67297 json | FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in h... | |
| CVE-2026-67294 json | FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side se... | |
| CVE-2026-67289 json | FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RD... | |
| CVE-2026-66402 json | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_v... | |
| CVE-2026-10773 json | The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char *... | |
| CVE-2026-2411 json | Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose perm... | |
| CVE-2026-18059 json | The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exposu... | |
| CVE-2026-17555 json | The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in versions ... | |
| CVE-2026-16614 json | The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQL Inj... | |
| CVE-2026-16091 json | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vul... | |
| CVE-2026-15964 json | The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in ... | |
| CVE-2026-15951 json | The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and incl... | |
| CVE-2026-15649 json | The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortc... | |
| CVE-2026-15601 json | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zip S... | |
| CVE-2026-15262 json | The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputti... | |
| CVE-2026-15234 json | The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it ... | |
| CVE-2026-15052 json | The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-S... | |
| CVE-2026-15018 json | The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algorithm'... | |
| CVE-2026-14839 json | The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public REST e... | |
| CVE-2026-14561 json | The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential,... | |
| CVE-2026-14315 json | The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJ... | |
| CVE-2026-14292 json | The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the fr... | |
| CVE-2026-13596 json | The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter bef... | |
| CVE-2026-11995 json | The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is ... | |
| CVE-2026-6453 json | The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. This is ... | |
| CVE-2025-71403 json | better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs ... | |
| CVE-2026-68770 json | sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execut... | |
| CVE-2026-66759 json | A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin ... | |
| CVE-2026-57476 json | Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional p... | |
| CVE-2026-57475 json | Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a rem... | |
| CVE-2026-48449 json | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code exec... | |
| CVE-2026-48448 json | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injec... | |
| CVE-2026-13329 json | The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validat... | |
| CVE-2026-12966 json | The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCo... | |
| CVE-2026-12696 json | The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside ... | |
| CVE-2025-15669 json | The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before renderin... | |
| CVE-2026-61175 json | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). Th... | |
| CVE-2026-61012 json | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported ve... | |
| CVE-2026-17965 json | Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform U... | |
| CVE-2026-17941 json | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to sp... | |
| CVE-2026-17917 json | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to... | |
| CVE-2026-17874 json | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to pe... | |
| CVE-2026-17842 json | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who c... | |
| CVE-2026-17841 json | Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a ... | |
| CVE-2026-17840 json | Incorrect security UI in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofi... | |
| CVE-2026-17839 json | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to pe... |