CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-77846 json | Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attacker wh... | |
| CVE-2026-75759 json | Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersona... | |
| CVE-2026-82562 json | ### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a... | |
| CVE-2026-81346 json | The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actio... | |
| CVE-2026-81342 json | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during u... | |
| CVE-2026-81200 json | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information,... | |
| CVE-2026-81026 json | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status... | |
| CVE-2026-80488 json | The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before ... | |
| CVE-2026-80311 json | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the cus... | |
| CVE-2026-77970 json | Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access t... | |
| CVE-2026-77831 json | Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array at... | |
| CVE-2026-77786 json | The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the cap... | |
| CVE-2026-77704 json | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required... | |
| CVE-2026-77012 json | The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its ... | |
| CVE-2026-77010 json | The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation checks o... | |
| CVE-2026-77008 json | The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or auth... | |
| CVE-2026-77007 json | The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation chec... | |
| CVE-2026-76586 json | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actua... | |
| CVE-2026-76548 json | The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, grantin... | |
| CVE-2026-76547 json | The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing ... | |
| CVE-2026-76546 json | The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowin... | |
| CVE-2026-75847 json | Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access t... | |
| CVE-2026-19430 json | The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the tok... | |
| CVE-2026-18234 json | The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs... | |
| CVE-2026-18233 json | The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belon... | |
| CVE-2026-17522 json | The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings s... | |
| CVE-2026-72984 json | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attac... | |
| CVE-2026-66323 json | Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker t... | |
| CVE-2026-17520 json | The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it fr... | |
| CVE-2026-16947 json | The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before... | |
| CVE-2026-16600 json | The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not v... | |
| CVE-2026-16259 json | The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated ... | |
| CVE-2026-16061 json | The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its publi... | |
| CVE-2026-82417 json | ### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy... | |
| CVE-2026-76197 json | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command... | |
| CVE-2026-76195 json | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command... | |
| CVE-2026-76193 json | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary... | |
| CVE-2026-82424 json | A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknown fun... | |
| CVE-2026-82423 json | A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order... | |
| CVE-2026-78002 json | A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `repla... | |
| CVE-2026-14676 json | Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating syst... | |
| CVE-2026-82422 json | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the fi... | |
| CVE-2026-82421 json | A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of ... | |
| CVE-2026-15369 json | The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up... | |
| CVE-2026-75807 json | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and incl... | |
| CVE-2026-82476 json | Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetche... | |
| CVE-2026-82475 json | iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to vali... | |
| CVE-2026-82474 json | Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. User... | |
| CVE-2026-82473 json | KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. A... | |
| CVE-2026-82472 json | Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, sess... | |
| CVE-2026-82470 json | Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the ... | |
| CVE-2026-82469 json | Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tok... | |
| CVE-2026-82468 json | Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type ... | |
| CVE-2026-82467 json | Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_loca... | |
| CVE-2026-82466 json | Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users... | |
| CVE-2026-82465 json | pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.validate... | |
| CVE-2026-82464 json | pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefix... | |
| CVE-2026-82463 json | pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profi... | |
| CVE-2026-82462 json | pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validatio... | |
| CVE-2026-82461 json | pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm... | |
| CVE-2026-82460 json | Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints tha... | |
| CVE-2026-68821 json | Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-82481 json | The cohttp package before 6.3.0 for OCaml allows directory traversal. | |
| CVE-2026-82477 json | In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network r... | |
| CVE-2026-82457 json | su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid... | |
| CVE-2026-82456 json | argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller creden... | |
| CVE-2026-82455 json | RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing... | |
| CVE-2026-82454 json | The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token ver... | |
| CVE-2026-82453 json | rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can... | |
| CVE-2026-82452 json | rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack aut... | |
| CVE-2026-82451 json | Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer heade... | |
| CVE-2026-82450 json | BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows ... | |
| CVE-2026-82252 json | gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repos... | |
| CVE-2026-82251 json | gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when derivin... | |
| CVE-2026-11404 json | Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), w... | |
| CVE-2024-58315 json | Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to potential... | |
| CVE-2026-82449 json | Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancie... | |
| CVE-2026-82448 json | Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated atta... | |
| CVE-2026-82447 json | Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a ... | |
| CVE-2026-14494 json | The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 v... | |
| CVE-2026-81733 json | WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live... | |
| CVE-2026-81732 json | WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, al... | |
| CVE-2026-81678 json | AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract e... | |
| CVE-2026-80192 json | @better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains... | |
| CVE-2026-79775 json | rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archiv... | |
| CVE-2026-79671 json | Ech0 before 4.4.3 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setting_se... | |
| CVE-2026-79658 json | Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware, whi... | |
| CVE-2026-78209 json | exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Atta... | |
| CVE-2026-78208 json | exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file... | |
| CVE-2026-78207 json | exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, co... | |
| CVE-2026-77915 json | rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers to sel... | |
| CVE-2026-72699 json | The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() met... | |
| CVE-2026-56100 json | SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authen... | |
| CVE-2026-78206 json | exceljs through 4.4.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total si... | |
| CVE-2026-77088 json | justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans ... | |
| CVE-2026-6827 json | justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When ... | |
| CVE-2026-82364 json | A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /orde... | |
| CVE-2026-80725 json | In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation criteria... | |
| CVE-2026-80724 json | In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becoming w... | |
| CVE-2026-80723 json | In the Linux kernel, the following vulnerability has been resolved: of: reserved_mem: prevent OOB when too many dynamic regi... |