CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-90668 json | The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows ... | |
| CVE-2026-90492 json | A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0. The affected element is the function contro... | |
| CVE-2026-90491 json | A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the file ren... | |
| CVE-2026-90490 json | A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the component Ma... | |
| CVE-2026-9800 json | A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization po... | |
| CVE-2026-90651 json | Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates ... | |
| CVE-2026-90648 json | wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, a... | |
| CVE-2026-90489 json | A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobinfo/i... | |
| CVE-2026-90488 json | A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the ... | |
| CVE-2026-24332 json | Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually of... | |
| CVE-2026-90647 json | ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vuln... | |
| CVE-2026-90487 json | A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xx... | |
| CVE-2026-90486 json | A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vu... | |
| CVE-2026-79300 json | SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an ... | |
| CVE-2026-90485 json | A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IURegistry... | |
| CVE-2026-90616 json | In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which ca... | |
| CVE-2026-90560 json | zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor be... | |
| CVE-2026-90559 json | snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) becau... | |
| CVE-2026-90558 json | sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values e... | |
| CVE-2026-90557 json | Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing sav... | |
| CVE-2026-90556 json | Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared ... | |
| CVE-2026-87919 json | The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product... | |
| CVE-2026-87918 json | The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay... | |
| CVE-2026-87916 json | The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored ... | |
| CVE-2026-87894 json | The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that retu... | |
| CVE-2026-87892 json | The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method aga... | |
| CVE-2026-87891 json | The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving... | |
| CVE-2026-87888 json | The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing ... | |
| CVE-2026-87842 json | The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's... | |
| CVE-2026-87797 json | The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a priva... | |
| CVE-2026-87759 json | The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pendin... | |
| CVE-2026-86790 json | The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page ... | |
| CVE-2026-85681 json | The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes a... | |
| CVE-2026-84171 json | The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writ... | |
| CVE-2026-84099 json | The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deser... | |
| CVE-2026-84047 json | The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a ... | |
| CVE-2026-84025 json | The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a u... | |
| CVE-2026-84024 json | The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an ... | |
| CVE-2026-84023 json | The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy term... | |
| CVE-2026-83532 json | The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before... | |
| CVE-2026-82851 json | The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user re... | |
| CVE-2026-82847 json | The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it b... | |
| CVE-2026-82845 json | The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserializ... | |
| CVE-2026-81742 json | The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be r... | |
| CVE-2026-81429 json | The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-impo... | |
| CVE-2026-81402 json | The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type valida... | |
| CVE-2026-81090 json | The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type... | |
| CVE-2026-80494 json | The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read... | |
| CVE-2026-80491 json | The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries... | |
| CVE-2026-78152 json | The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structur... | |
| CVE-2026-77753 json | The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Applica... | |
| CVE-2026-77752 json | The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login... | |
| CVE-2026-77705 json | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a cust... | |
| CVE-2026-77689 json | The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually t... | |
| CVE-2026-84889 json | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper l... | |
| CVE-2026-79724 json | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutrali... | |
| CVE-2026-78569 json | IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete de... | |
| CVE-2026-77006 json | The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capabilit... | |
| CVE-2026-77005 json | The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file... | |
| CVE-2026-75800 json | The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses... | |
| CVE-2026-70341 json | Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | |
| CVE-2026-90555 json | vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated ... | |
| CVE-2026-90554 json | vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video inpu... | |
| CVE-2026-90553 json | vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the tr... | |
| CVE-2026-90552 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_sch... | |
| CVE-2026-90551 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_pr... | |
| CVE-2026-90550 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins medi... | |
| CVE-2026-90549 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.j... | |
| CVE-2026-90548 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery li... | |
| CVE-2026-90547 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin... | |
| CVE-2026-90546 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.js... | |
| CVE-2026-90545 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the comment... | |
| CVE-2026-90544 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAd... | |
| CVE-2026-90543 json | WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing ... | |
| CVE-2026-90542 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live sc... | |
| CVE-2026-90541 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/men... | |
| CVE-2026-90540 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVid... | |
| CVE-2026-90539 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the pl... | |
| CVE-2026-90538 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlis... | |
| CVE-2026-90537 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/... | |
| CVE-2026-90536 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, al... | |
| CVE-2026-90535 json | Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort ... | |
| CVE-2026-90534 json | Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-lo... | |
| CVE-2026-90533 json | Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authentic... | |
| CVE-2026-15451 json | The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and includin... | |
| CVE-2026-10148 json | The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multip... | |
| CVE-2026-90474 json | MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where cli... | |
| CVE-2026-90473 json | msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 c... | |
| CVE-2026-90472 json | msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deseria... | |
| CVE-2026-85706 json | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 b... | |
| CVE-2026-89172 json | Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052. Th... | |
| CVE-2026-85200 json | The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via th... | |
| CVE-2026-85198 json | The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL ... | |
| CVE-2026-78175 json | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all vers... | |
| CVE-2026-78159 json | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.1... | |
| CVE-2026-78006 json | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.1... | |
| CVE-2026-77161 json | The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name ... | |
| CVE-2026-17585 json | The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Inf... | |
| CVE-2026-16482 json | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via th... | |
| CVE-2026-11355 json | The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a miss... |