CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-85414 json The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode At...
CVE-2026-83625 json The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all ...
CVE-2026-81543 json The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and ...
CVE-2026-75586 json The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[id]' ...
CVE-2026-75018 json The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.1...
CVE-2026-84937 json The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before ...
CVE-2026-84936 json The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing ...
CVE-2026-84935 json The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation m...
CVE-2026-84934 json The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions a...
CVE-2026-84931 json The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outpu...
CVE-2026-84930 json The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute befo...
CVE-2026-84927 json The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews ...
CVE-2026-84926 json The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to ...
CVE-2026-84901 json The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST rou...
CVE-2026-84899 json The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it insid...
CVE-2026-84898 json The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a loc...
CVE-2026-84896 json The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputti...
CVE-2026-84745 json The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on...
CVE-2026-84225 json The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before chang...
CVE-2026-84221 json The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing ...
CVE-2026-84022 json The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputti...
CVE-2026-84021 json The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML att...
CVE-2026-83544 json The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it with...
CVE-2026-83543 json The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing...
CVE-2026-82846 json The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in ...
CVE-2026-82304 json The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, le...
CVE-2026-81424 json The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is comple...
CVE-2026-81423 json The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect,...
CVE-2026-81404 json The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the ...
CVE-2026-81348 json The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated ...
CVE-2026-78438 json The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Backgro...
CVE-2026-78362 json The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API req...
CVE-2026-78150 json The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplica...
CVE-2026-78149 json The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its conten...
CVE-2026-77830 json The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via C...
CVE-2026-77826 json The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued t...
CVE-2026-19887 json The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12....
CVE-2026-19861 json The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a fo...
CVE-2026-19858 json The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when...
CVE-2026-4361 json The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This ...
CVE-2026-3853 json The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_...
CVE-2026-19769 json The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2026-18843 json The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_resu...
CVE-2026-18406 json The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cr...
CVE-2026-16649 json The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions...
CVE-2026-15984 json The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up...
CVE-2026-15247 json The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a setting...
CVE-2026-14975 json The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 vi...
CVE-2025-15694 json The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting ...
CVE-2025-15693 json The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrat...
CVE-2026-8625 json The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Sit...
CVE-2026-86145 json PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA...
CVE-2026-83628 json The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Mu...
CVE-2026-83627 json The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Exe...
CVE-2026-77263 json The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-...
CVE-2026-77233 json The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-...
CVE-2026-18404 json The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_m...
CVE-2026-13447 json The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, ...
CVE-2026-8623 json The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Sit...
CVE-2025-14945 json The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2026-86144 json In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has sec...
CVE-2026-86143 json In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach ...
CVE-2026-86142 json In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length...
CVE-2026-86141 json xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it doe...
CVE-2026-86140 json In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
CVE-2026-86139 json In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
CVE-2026-86138 json In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
CVE-2026-86137 json In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xml...
CVE-2026-85046 json Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the s...
CVE-2026-83711 json Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to e...
CVE-2026-80098 json Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over...
CVE-2026-70352 json Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over ...
CVE-2026-70178 json Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
CVE-2026-65818 json Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
CVE-2026-62916 json Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate pri...
CVE-2026-62196 json OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisf...
CVE-2026-85444 json MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that...
CVE-2026-85439 json MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() ...
CVE-2026-85434 json MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attack...
CVE-2026-85429 json MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from th...
CVE-2026-85424 json MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with ful...
CVE-2026-85225 json A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the...
CVE-2026-9736 json IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due t...
CVE-2026-85395 json UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin ...
CVE-2026-85390 json Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion ro...
CVE-2026-85207 json A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the fi...
CVE-2026-63376 json toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a t...
CVE-2026-33630 json c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-com...
CVE-2026-85309 json Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access C...
CVE-2026-85305 json Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress...
CVE-2026-85236 json A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a sta...
CVE-2026-85137 json A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_n...
CVE-2026-84847 json Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
CVE-2026-84812 json Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.
CVE-2026-84774 json Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.
CVE-2026-84766 json Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
CVE-2026-84758 json Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.
CVE-2026-84753 json Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
CVE-2026-82023 json LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated...
CVE-2026-81773 json Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report