CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-84250 json IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkc...
CVE-2026-106404 json Incorrect authorization in FontAccess in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised t...
CVE-2026-106403 json Incorrect authorization in Accessibility in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromise...
CVE-2026-106386 json Uninitialized resource in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory inside th...
CVE-2026-106384 json Missing authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised ...
CVE-2026-102410 json Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constra...
CVE-2026-82334 json IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based out-of-bounds read in the TDS7 LOGIN7 protocol p...
CVE-2026-105240 json Improper Neutralization of Null Byte or NUL Character vulnerability in the OutputDebugStringAppender of Apache log4net. A NU...
CVE-2026-105239 json Improper Neutralization of Null Byte or NUL Character vulnerability in the EventLogAppender of Apache log4net. A NUL charact...
CVE-2026-105243 json Insufficient Logging vulnerability in the EventLogAppender of Apache log4net. Long messages were truncated to a fixed size t...
CVE-2026-105242 json Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading...
CVE-2026-105241 json Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net. Content that the mail fi...
CVE-2026-83450 json Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supported ver...
CVE-2026-83449 json Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported...
CVE-2026-95702 json Use-after-free vulnerability in VFS in Google gVisor prior to release 20260831.0 on all platforms allows a local attacker wit...
CVE-2026-108125 json Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in wp-post-author. This i...
CVE-2026-108124 json Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in wp-post-author. This i...
CVE-2026-108109 json PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/control...
CVE-2026-108108 json PHPNuxBill through 2025.3.20 contains an authentication bypass vulnerability in RADIUS CHAP verification because Password::ch...
CVE-2026-108107 json PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoi...
CVE-2026-108106 json Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM...
CVE-2026-108105 json Open5GS through 2.8.0 contains a reachable assertion vulnerability in mme_gn_handle_sgsn_context_request() that allows remote...
CVE-2026-108104 json Xerial snappy-java from 1.1.7.4 before 1.1.10.10 contains a double release vulnerability in SnappyFramedInputStream that retu...
CVE-2026-108103 json Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_dropped_dl_traffic_threshold() that ...
CVE-2026-108102 json Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_volume_measurement() in lib/pfcp/typ...
CVE-2026-108101 json HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows ...
CVE-2026-108100 json HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by s...
CVE-2026-107806 json Nginx UI is a web user interface for the Nginx web server. From 2.3.8 until 2.5.0, an authenticated administrator with an act...
CVE-2026-107805 json Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path per...
CVE-2026-107804 json Nginx UI is a web user interface for the Nginx web server. From 2.2.0 until 2.6.0, the bundled reverse proxy does not preserv...
CVE-2026-105278 json The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An atta...
CVE-2026-104117 json A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP m...
CVE-2026-78796 json An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless router v1.3.241114.024540 and before allows a remo...
CVE-2026-78795 json An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless router v1.3.241114.024540 and before allows a remo...
CVE-2026-39460 json Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration file. Wi...
CVE-2026-39453 json Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be automated using a tool like...
CVE-2026-33367 json SNMP can be used to perform administrative actions such as retrieving configuration files, modifying user accounts or device ...
CVE-2026-33272 json A malicious user with physical access to the device can boot the switch from factory settings without authentication, use the...
CVE-2026-32645 json Default factory credentials with administrative access are enabled and persist even after configuring other administrator acc...
CVE-2026-29797 json No authentication is required when updating firmware or bootloader, making it easy for malicious files to be pushed to the de...
CVE-2026-28745 json Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If th...
CVE-2026-15340 json lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.
CVE-2026-106097 json The Code Snippets WordPress plugin before 3.10.0 does not sanitise and escape a user-supplied parameter before using it in a ...
CVE-2026-106095 json The Code Snippets WordPress plugin before 3.10.0 does not perform a capability check on one of its snippet-management actions...
CVE-2026-104116 json A missing authorization check in the illumos zones statistics daemon (zonestatd) allows a local user in any zone to disrupt z...
CVE-2026-104115 json A stack-based buffer overflow in the illumos reparse point daemon (reparsed) allows a local user to crash the daemon. get_fs_...
CVE-2026-104114 json A NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemon. nwamd_do...
CVE-2026-104113 json A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon. When autho...
CVE-2026-104112 json A missing release of resources in the illumos name service cache daemon (nscd) allows a local user to exhaust kernel memory. ...
CVE-2026-104081 json KodExplorer before 4.55 contains a path traversal vulnerability in the unzip_pre_name() function within app/function/helper.f...
CVE-2026-103329 json The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incoming payment webhook notif...
CVE-2026-102916 json A reachable assertion in the illumos bhyve instruction emulator allows a guest to panic the host. When emulating a REP-prefix...
CVE-2026-96207 json Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a netw...
CVE-2026-94510 json Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges ...
CVE-2026-93548 json The FooSales WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitled to act as the user a re...
CVE-2026-92990 json The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the s...
CVE-2026-92989 json The SendPress Newsletters WordPress plugin through 1.26.1.20 does not check the user's capability on several newsletter-manag...
CVE-2026-89235 json The Testimonials by BestWebSoft WordPress plugin through 1.0.8 does not sanitise and escape a parameter before using it in a ...
CVE-2026-88931 json The Social Web Suite WordPress plugin through 4.1.12 does not restrict which of its settings may be written through an unaut...
CVE-2026-87846 json The Shipping for Nova Poshta WordPress plugin through 1.19.8 does not perform any authorisation, nonce or ownership checks on...
CVE-2026-87841 json The UnitechPay WordPress plugin through 1.0.6.3 does not verify the authenticity of the payment notifications it receives, a...
CVE-2026-86851 json The Livees Checkout WordPress plugin through 7.0.2 does not perform any capability, nonce or order-key check before acting on...
CVE-2026-86850 json The SKU Error Fixer for WooCommerce WordPress plugin through 1.0 does not perform any capability or nonce checks on two of it...
CVE-2026-85348 json The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when updating one of its settings, al...
CVE-2026-84224 json The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users wi...
CVE-2026-84220 json The Kirki WordPress plugin before 6.3.2 does not prevent shortcodes held in comments from being executed when it renders them...
CVE-2026-78027 json Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF)...
CVE-2026-78022 json Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Not Failing Securely ('Failing Ope...
CVE-2026-78017 json Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Check for Unusual or Exc...
CVE-2026-76769 json Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authorization vulnerabilit...
CVE-2025-15700 json The AWP Classifieds WordPress plugin before 4.4.9 does not validate the type of files extracted from an uploaded ZIP archive ...
CVE-2026-107828 json Jivejdon through 5.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access Weibo-cr...
CVE-2026-107800 json Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject scrip...
CVE-2026-107797 json Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability in application/message/postThread.jsp that allow...
CVE-2026-107793 json Jivejdon through 5.0 contains an authorization bypass vulnerability in SubscriptionServiceImp.deleteSubscription that allows ...
CVE-2026-107725 json Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, an...
CVE-2026-107720 json fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.1, fast-jwt createVerifier accepts an unsigned JWT w...
CVE-2026-105269 json Satel Netco Design versions prior to v2.1.7 contains a stored cross site scripting vulnerability. An authenticated user with ...
CVE-2026-88131 json Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network.
CVE-2026-87980 json IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a local attacker to obtain sensitive information due to clearte...
CVE-2026-84891 json IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to obtain sensitive information due to use o...
CVE-2026-84875 json IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer ov...
CVE-2026-84249 json IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to...
CVE-2026-84247 json IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to cause a denial of service due to a path trav...
CVE-2026-84246 json IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer ov...
CVE-2026-84230 json IBM Guardium Data Protection 12.2.2 could allow a remote attacker to cause a denial of service due to a race condition result...
CVE-2026-84198 json IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer ov...
CVE-2026-84058 json IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOG...
CVE-2026-84057 json IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neu...
CVE-2026-84035 json IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a stack-bas...
CVE-2026-84032 json IBM Guardium Data Protection 12.2.2 could allow a remote attacker to conduct a man-in-the-middle attack due to improper certi...
CVE-2026-83947 json Missing authorization in Azure Event Grid allows an authorized attacker to perform spoofing over a network.
CVE-2026-83943 json Exposure of sensitive information to an unauthorized actor in Azure API Center allows an unauthorized attacker to disclose in...
CVE-2026-82895 json IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer ov...
CVE-2026-80381 json IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute unauthorized SQL statements due t...
CVE-2026-77900 json Missing authentication for critical function in Azure App Service allows an unauthorized attacker to execute code over a netw...
CVE-2026-75875 json IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to path traver...
CVE-2026-69435 json Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
CVE-2026-107781 json Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing aut...
CVE-2026-107707 json Intego Antivirus for Windows through 3.0.0.1 contains a link following vulnerability in its optimization module that allows l...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report