CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-78183 json | DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the str... | |
| CVE-2026-78140 json | A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/java/co... | |
| CVE-2026-41992 json | GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared gl... | |
| CVE-2026-19565 json | Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and p... | |
| CVE-2024-11831 json | A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not prope... | |
| CVE-2026-75922 json | Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded t... | |
| CVE-2026-2100 json | A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remo... | |
| CVE-2026-10840 json | A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:a... | |
| CVE-2026-4878 json | A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in t... | |
| CVE-2025-1244 json | A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arb... | |
| CVE-2026-77116 json | Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in us... | |
| CVE-2026-77115 json | Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without esca... | |
| CVE-2026-77003 json | The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being create... | |
| CVE-2026-77002 json | The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is... | |
| CVE-2026-77001 json | The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authenticat... | |
| CVE-2026-77000 json | The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the ... | |
| CVE-2026-76793 json | The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be... | |
| CVE-2026-76789 json | The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks o... | |
| CVE-2026-19222 json | The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to regis... | |
| CVE-2026-19221 json | The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, al... | |
| CVE-2026-19093 json | The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing u... | |
| CVE-2026-18052 json | The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorise... | |
| CVE-2026-16738 json | The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhoo... | |
| CVE-2026-16612 json | The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthentic... | |
| CVE-2026-16260 json | The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post ... | |
| CVE-2026-14853 json | The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and it... | |
| CVE-2026-14187 json | The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowin... | |
| CVE-2026-77088 json | justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans ... | |
| CVE-2026-74793 json | justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler remov... | |
| CVE-2026-9769 json | justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTM... | |
| CVE-2026-8630 json | justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serializatio... | |
| CVE-2026-8445 json | justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text... | |
| CVE-2026-7808 json | justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., scrip... | |
| CVE-2026-76613 json | Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection all... | |
| CVE-2026-6827 json | justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When ... | |
| CVE-2026-5751 json | justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability when ... | |
| CVE-2026-5389 json | justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializing a... | |
| CVE-2026-5388 json | justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string)... | |
| CVE-2026-4671 json | justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Ap... | |
| CVE-2025-5318 json | A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handl... | |
| CVE-2025-2842 json | A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed b... | |
| CVE-2025-2786 json | A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploy... | |
| CVE-2026-74684 json | In the Linux kernel, the following vulnerability has been resolved: net: tap: set skb->dev before parsing virtio net header ... | |
| CVE-2026-74672 json | In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: acquire init_mm lock on huge vmap to avoid p... | |
| CVE-2026-74644 json | In the Linux kernel, the following vulnerability has been resolved: mm/damon/ops-common: putback folios on invalid migrate n... | |
| CVE-2026-74641 json | In the Linux kernel, the following vulnerability has been resolved: ALSA: usx2y: bound the hwdep mmap fault offset snd_us42... | |
| CVE-2026-74637 json | In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix group leader use-after-free after sibling... | |
| CVE-2026-74632 json | In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix huge_zero_pfn race Patch series "mm... | |
| CVE-2026-74631 json | In the Linux kernel, the following vulnerability has been resolved: net: smc: fix splice entry lifetime imbalance in smc_rx_... | |
| CVE-2026-74628 json | In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free of the socket by its timers ... | |
| CVE-2026-74626 json | In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_netdev: Preserve RX queue depth on allocation f... | |
| CVE-2026-74624 json | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: defer invalid log until after u... | |
| CVE-2026-74623 json | In the Linux kernel, the following vulnerability has been resolved: net: atlantic: free stranded TX buffers on ring deinit ... | |
| CVE-2026-74621 json | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix sk_buff leak when the header chec... | |
| CVE-2026-74620 json | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_gact, act_police: range check the fallbac... | |
| CVE-2026-74612 json | In the Linux kernel, the following vulnerability has been resolved: veth: fix skb length accounting after XDP frag adjustmen... | |
| CVE-2026-74607 json | In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Serialize accesses to the owner and mirror lis... | |
| CVE-2026-74602 json | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Initialise reader page order in rb_allocate... | |
| CVE-2026-74601 json | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Use current_context for safe per-CPU buffer... | |
| CVE-2026-74600 json | In the Linux kernel, the following vulnerability has been resolved: mm/page_table_check: skip special zero mappings page_ta... | |
| CVE-2026-74599 json | In the Linux kernel, the following vulnerability has been resolved: mm/ptdump: always stabilise against page table freeing u... | |
| CVE-2026-74595 json | In the Linux kernel, the following vulnerability has been resolved: fscrypt: use the mount idmap for the owner check in fscr... | |
| CVE-2026-74594 json | In the Linux kernel, the following vulnerability has been resolved: sched/psi: Shut down rtpoll_timer in psi_cgroup_free() ... | |
| CVE-2026-74593 json | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Take cgroup_lock() first in scx_cgroup_lock()... | |
| CVE-2026-74575 json | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Prevent XDomain delayed work use-after-free... | |
| CVE-2026-74531 json | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: hold conn reference in abort_conn_s... | |
| CVE-2026-74517 json | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Cancel delayed I/O APIC EOI handling before de... | |
| CVE-2026-74514 json | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix memory accounting for pinned/unpinne... | |
| CVE-2026-74510 json | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix UAF in pair command cancellation T... | |
| CVE-2026-74509 json | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix advertising data UAFs hci_find... | |
| CVE-2026-74508 json | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: reject frames without a transaction hea... | |
| CVE-2026-74494 json | In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject repeated SMB2 NEGOTIATE requests Unauthen... | |
| CVE-2026-74487 json | In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: restore write access when removing an entry... | |
| CVE-2026-74486 json | In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: use exe_file_deny_write_access() for the in... | |
| CVE-2026-74483 json | In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: don't leak the user namespace when the moun... | |
| CVE-2026-74479 json | In the Linux kernel, the following vulnerability has been resolved: net: pktgen: fix proc entry use-after-free pktgen_chang... | |
| CVE-2026-74476 json | In the Linux kernel, the following vulnerability has been resolved: veth: convert frag_list skbs before running XDP A frag_... | |
| CVE-2026-74474 json | In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() for transmit path hea... | |
| CVE-2026-74470 json | In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow O... | |
| CVE-2026-74450 json | In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: fix pptable use-after-free amdgpu_dpm_get_p... | |
| CVE-2026-74441 json | In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Fix race condition and ordering in por... | |
| CVE-2026-74436 json | In the Linux kernel, the following vulnerability has been resolved: rxrpc: serialize kernel accept preallocation with socket... | |
| CVE-2026-74432 json | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix leak of released call in recvmsg(MSG_PEEK) F... | |
| CVE-2026-72308 json | In the Linux kernel, the following vulnerability has been resolved: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() Wh... | |
| CVE-2026-72305 json | In the Linux kernel, the following vulnerability has been resolved: VDUSE: avoid leaking information to userspace The bounc... | |
| CVE-2026-72299 json | In the Linux kernel, the following vulnerability has been resolved: tipc: restrict socket queue dumps in enqueue tracepoints... | |
| CVE-2026-72262 json | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext ... | |
| CVE-2026-72260 json | In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8192: Check runtime resume during prob... | |
| CVE-2026-72255 json | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: pin bridge device while NFQUEUE hol... | |
| CVE-2026-72253 json | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: validate skb_dst() before a... | |
| CVE-2026-72252 json | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: don't leak bad clone into fut... | |
| CVE-2026-72242 json | In the Linux kernel, the following vulnerability has been resolved: selinux: avoid sk_socket dereference in selinux_sctp_bin... | |
| CVE-2026-72236 json | In the Linux kernel, the following vulnerability has been resolved: s390/perf_cpum_cf: Add missing array_index_nospec() to _... | |
| CVE-2026-72225 json | In the Linux kernel, the following vulnerability has been resolved: jbd2: fix integer underflow in jbd2_journal_initialize_f... | |
| CVE-2026-72216 json | In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom: Fix leak when custom dump_segments add... | |
| CVE-2026-72191 json | In the Linux kernel, the following vulnerability has been resolved: ntfs3: validate split-point offset in indx_insert_into_b... | |
| CVE-2026-72172 json | In the Linux kernel, the following vulnerability has been resolved: mm/mm_init: fix uninitialized struct pages for ZONE_DEVI... | |
| CVE-2026-72170 json | In the Linux kernel, the following vulnerability has been resolved: 9p: skip nlink update in cacheless mode to fix WARN_ON ... | |
| CVE-2026-72168 json | In the Linux kernel, the following vulnerability has been resolved: mtd: maps: vmu-flash: fix fault in unaligned fixup Use ... | |
| CVE-2026-72166 json | In the Linux kernel, the following vulnerability has been resolved: net/9p: fix infinite loop in p9_client_rpc on fatal sign... |