CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-67283 json Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated...
CVE-2026-67282 json Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could...
CVE-2026-66915 json Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute arbitra...
CVE-2026-19566 json Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengt...
CVE-2026-19426 json POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly acc...
CVE-2026-11814 json A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to interce...
CVE-2026-11739 json A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ...
CVE-2026-11738 json Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to t...
CVE-2026-11737 json Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to ...
CVE-2026-11736 json A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unaut...
CVE-2026-11735 json A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make un...
CVE-2026-11734 json A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device ...
CVE-2026-11733 json A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the norma...
CVE-2026-9214 json Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to th...
CVE-2025-41771 json An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable t...
CVE-2025-41770 json An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote a...
CVE-2025-41769 json The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An una...
CVE-2026-56208 json A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's...
CVE-2026-49332 json A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forw...
CVE-2026-66659 json Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table...
CVE-2026-19594 json Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy p...
CVE-2026-19217 json The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag...
CVE-2026-19073 json The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its...
CVE-2026-19052 json The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX actions...
CVE-2026-19050 json The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capabil...
CVE-2026-18962 json The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the...
CVE-2026-18943 json The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing u...
CVE-2026-18789 json The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allow...
CVE-2026-18474 json The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statemen...
CVE-2026-18391 json The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores wi...
CVE-2026-18366 json The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access contr...
CVE-2026-18230 json The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statemen...
CVE-2026-18057 json The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a S...
CVE-2026-18049 json The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its publi...
CVE-2026-18048 json The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file p...
CVE-2026-18046 json The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability chec...
CVE-2026-18035 json The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing ...
CVE-2026-17013 json The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into...
CVE-2026-16977 json The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is subst...
CVE-2026-16737 json The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-...
CVE-2026-16538 json The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up b...
CVE-2026-16294 json The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL ...
CVE-2026-16253 json The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-restore fu...
CVE-2026-16066 json The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it on th...
CVE-2026-16051 json The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote ...
CVE-2026-15388 json The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability chec...
CVE-2026-15249 json The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts it int...
CVE-2026-15039 json The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing...
CVE-2026-14925 json The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file download ha...
CVE-2026-14859 json The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX action...
CVE-2026-14858 json The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing an...
CVE-2026-14857 json The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update history ...
CVE-2026-13613 json The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them ...
CVE-2026-13612 json The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, allowin...
CVE-2026-13177 json The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users wit...
CVE-2026-13171 json The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler,...
CVE-2026-13168 json The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with...
CVE-2026-12976 json The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assist...
CVE-2026-64954 json Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they re...
CVE-2026-12235 json The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/RELA relocation entries when linking a relocatable (partia...
CVE-2026-71362 json Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker...
CVE-2026-70339 json Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attac...
CVE-2026-66154 json An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Bui...
CVE-2026-66150 json Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an a...
CVE-2026-66149 json Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an a...
CVE-2026-66147 json An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier vers...
CVE-2026-66145 json An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions whi...
CVE-2026-65680 json Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate...
CVE-2026-48447 json Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in th...
CVE-2026-48441 json Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabil...
CVE-2026-48412 json Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker...
CVE-2026-18634 json An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build ...
CVE-2026-12234 json The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c snapsho...
CVE-2026-12233 json The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its credenti...
CVE-2026-12232 json The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a caller-s...
CVE-2026-71387 json ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the conte...
CVE-2026-71386 json is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the...
CVE-2026-71331 json Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unautho...
CVE-2026-70355 json Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an...
CVE-2026-70340 json Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
CVE-2026-70338 json Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a...
CVE-2026-70337 json Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
CVE-2026-70329 json Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-70326 json Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a ...
CVE-2026-70324 json Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a ...
CVE-2026-48410 json Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co...
CVE-2026-48409 json Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co...
CVE-2026-48408 json Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co...
CVE-2026-48407 json Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co...
CVE-2026-48406 json Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co...
CVE-2026-48405 json Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co...
CVE-2026-48404 json Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co...
CVE-2026-48397 json Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execut...
CVE-2026-47940 json Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code executio...
CVE-2026-20901 json Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup ...
CVE-2026-70321 json Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network...
CVE-2026-70313 json Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70307 json Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-70130 json Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-69320 json Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an un...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report