CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-92714 json | The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including,... | |
| CVE-2026-92619 json | The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 ... | |
| CVE-2026-92561 json | The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all ... | |
| CVE-2026-91707 json | The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.11.1.... | |
| CVE-2026-90977 json | The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty,... | |
| CVE-2026-90976 json | The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an account i... | |
| CVE-2026-89413 json | The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. Th... | |
| CVE-2026-89330 json | The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for Wor... | |
| CVE-2026-89278 json | The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vuln... | |
| CVE-2026-89138 json | The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. Th... | |
| CVE-2026-88994 json | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a files... | |
| CVE-2026-86800 json | The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disab... | |
| CVE-2026-86796 json | The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before di... | |
| CVE-2026-84909 json | The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripti... | |
| CVE-2026-79713 json | The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-cache... | |
| CVE-2026-75017 json | The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin... | |
| CVE-2026-75016 json | The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientId at... | |
| CVE-2026-18317 json | The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to author... | |
| CVE-2026-17576 json | The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, and ... | |
| CVE-2026-12106 json | The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and i... | |
| CVE-2024-38639 json | An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulne... | |
| CVE-2024-27123 json | A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit the vu... | |
| CVE-2026-93485 json | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress co... | |
| CVE-2026-90984 json | The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its ... | |
| CVE-2026-90978 json | The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce fie... | |
| CVE-2026-89008 json | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one ... | |
| CVE-2026-89007 json | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of i... | |
| CVE-2026-88993 json | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in H... | |
| CVE-2026-88844 json | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course... | |
| CVE-2026-88825 json | The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowing una... | |
| CVE-2026-88798 json | The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it a... | |
| CVE-2026-87966 json | The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthentic... | |
| CVE-2026-87965 json | The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointmen... | |
| CVE-2026-87775 json | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build... | |
| CVE-2026-87774 json | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build... | |
| CVE-2026-87771 json | The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them in S... | |
| CVE-2026-87770 json | The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them ... | |
| CVE-2026-87767 json | The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before u... | |
| CVE-2026-85350 json | The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Toget... | |
| CVE-2026-85127 json | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated ... | |
| CVE-2026-85123 json | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored co... | |
| CVE-2026-85122 json | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored co... | |
| CVE-2026-85009 json | The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a req... | |
| CVE-2026-84904 json | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of... | |
| CVE-2026-84903 json | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password chec... | |
| CVE-2026-84902 json | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when impo... | |
| CVE-2026-84738 json | The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import featur... | |
| CVE-2026-81810 json | The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its ... | |
| CVE-2026-81340 json | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability chec... | |
| CVE-2026-76781 json | A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer... | |
| CVE-2026-18912 json | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing ... | |
| CVE-2026-18911 json | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled age... | |
| CVE-2026-81480 json | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A hig... | |
| CVE-2026-81478 json | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerabilit... | |
| CVE-2026-81447 json | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. ... | |
| CVE-2026-81445 json | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A ... | |
| CVE-2026-80355 json | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability.... | |
| CVE-2026-28326 json | SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The i... | |
| CVE-2026-26950 json | Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. ... | |
| CVE-2026-17086 json | The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Inje... | |
| CVE-2026-81477 json | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high... | |
| CVE-2026-81476 json | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements use... | |
| CVE-2026-81475 json | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vul... | |
| CVE-2026-81474 json | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low ... | |
| CVE-2026-76409 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team h... | |
| CVE-2026-20361 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team h... | |
| CVE-2026-20360 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team h... | |
| CVE-2026-20350 json | A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, r... | |
| CVE-2026-20344 json | A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attac... | |
| CVE-2026-20341 json | A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated... | |
| CVE-2026-20340 json | A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at t... | |
| CVE-2026-20336 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance... | |
| CVE-2026-20335 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance... | |
| CVE-2026-20330 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance... | |
| CVE-2026-20329 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance... | |
| CVE-2026-20326 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team h... | |
| CVE-2026-20284 json | A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attac... | |
| CVE-2026-91102 json | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several softw... | |
| CVE-2026-65357 json | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvO... | |
| CVE-2026-56960 json | In multiple locations, there is a possible use-after-free due to a logic error in the code. This could lead to remote escalat... | |
| CVE-2026-20325 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering t... | |
| CVE-2026-20324 json | A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software... | |
| CVE-2026-20322 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering t... | |
| CVE-2026-20242 json | A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow... | |
| CVE-2026-20237 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and... | |
| CVE-2026-20194 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and... | |
| CVE-2026-20192 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and... | |
| CVE-2026-20130 json | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and... | |
| CVE-2026-93468 json | The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relati... | |
| CVE-2026-93467 json | The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute ar... | |
| CVE-2026-93371 json | A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGene... | |
| CVE-2026-92991 json | The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various... | |
| CVE-2026-15650 json | The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scri... | |
| CVE-2026-14855 json | The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versi... | |
| CVE-2026-93456 json | django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attac... | |
| CVE-2026-93455 json | django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account ... | |
| CVE-2026-93331 json | A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/i... | |
| CVE-2026-93314 json | A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the fi... | |
| CVE-2026-93313 json | A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg ... | |
| CVE-2026-92925 json | A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fa... |