CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-86475 json The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against ...
CVE-2026-84906 json The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to...
CVE-2026-79708 json GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 befo...
CVE-2026-78252 json GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 b...
CVE-2026-73447 json A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full devic...
CVE-2026-19857 json The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortc...
CVE-2026-19619 json GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 b...
CVE-2026-19248 json QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input.
CVE-2026-16794 json GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19.3 bef...
CVE-2026-13407 json The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through it...
CVE-2026-8030 json GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 b...
CVE-2026-7514 json GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 19.3 b...
CVE-2026-3855 json GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, and 19.3...
CVE-2026-1168 json GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3...
CVE-2025-14871 json GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3...
CVE-2026-19387 json A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI AD...
CVE-2024-11222 json GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 b...
CVE-2026-92358 json A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different...
CVE-2026-89328 json The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before p...
CVE-2026-89327 json The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user the com...
CVE-2026-88910 json The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthentic...
CVE-2026-87959 json The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI prov...
CVE-2026-87907 json The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that ret...
CVE-2026-87896 json The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that retu...
CVE-2026-87860 json The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancel...
CVE-2026-87854 json The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one ...
CVE-2026-87828 json The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJ...
CVE-2026-86823 json The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subs...
CVE-2026-86784 json The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before ou...
CVE-2026-86449 json The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied post sta...
CVE-2026-86448 json The LearnPress WordPress plugin before 4.4.7 does not perform any authentication, capability or nonce check before serving a...
CVE-2026-86447 json The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative course tool...
CVE-2026-86445 json The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template ha...
CVE-2026-86444 json The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute on a...
CVE-2026-85641 json The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user last edi...
CVE-2026-85572 json The Tutor LMS WordPress plugin before 4.0.8 does not check that a user has access to a course before returning its lesson di...
CVE-2026-85569 json The Tutor LMS WordPress plugin before 4.0.8 does not correctly determine whether an incoming request is addressed to its own...
CVE-2026-85530 json The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value it st...
CVE-2026-85349 json The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a u...
CVE-2026-85131 json The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk action...
CVE-2026-84907 json The Eventin WordPress plugin before 4.1.24 does not properly authorise order finalisation when its offline (local) payment m...
CVE-2026-84905 json The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, all...
CVE-2026-84829 json The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an image...
CVE-2026-84088 json The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link sett...
CVE-2026-82126 json The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit the spec...
CVE-2026-82125 json The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderat...
CVE-2026-82124 json The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected be...
CVE-2026-78474 json The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on on...
CVE-2026-78472 json The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it in a ...
CVE-2026-77702 json The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to chang...
CVE-2026-76559 json The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during the im...
CVE-2026-76558 json The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database befor...
CVE-2026-76557 json The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration valu...
CVE-2026-76556 json The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter values befo...
CVE-2026-76555 json The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it and co...
CVE-2026-76553 json The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data befor...
CVE-2026-76552 json The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it retriev...
CVE-2026-76551 json The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported fiel...
CVE-2026-76550 json The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing export fi...
CVE-2026-74926 json The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one of its ...
CVE-2026-61396 json Rejected reason: Did not need CVE ID
CVE-2026-71269 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-89063 json The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object ...
CVE-2026-18555 json The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Reflect...
CVE-2026-5920 json The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter...
CVE-2026-92180 json pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerab...
CVE-2026-92179 json pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows re...
CVE-2026-92178 json pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remo...
CVE-2026-92177 json pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows re...
CVE-2026-92176 json pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote at...
CVE-2026-78088 json The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthen...
CVE-2026-73467 json On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access...
CVE-2026-73466 json On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log fil...
CVE-2026-73465 json On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to ...
CVE-2026-58773 json In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could l...
CVE-2026-58767 json In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This co...
CVE-2026-18595 json The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJAX Cron Handler Request P...
CVE-2026-16588 json The WP Directory Kit plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in all versions u...
CVE-2026-14349 json The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all...
CVE-2026-12793 json The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions...
CVE-2026-11996 json The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Field in...
CVE-2026-11984 json The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to...
CVE-2026-58766 json In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This co...
CVE-2026-58765 json In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privil...
CVE-2026-58755 json In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. Th...
CVE-2026-58751 json In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead ...
CVE-2026-58747 json In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead ...
CVE-2026-58744 json In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local...
CVE-2026-58739 json In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This co...
CVE-2026-58734 json In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead...
CVE-2026-58728 json In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of...
CVE-2026-58726 json In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local ...
CVE-2026-58724 json In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of pri...
CVE-2026-58718 json In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. Thi...
CVE-2026-58716 json In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local esc...
CVE-2026-58710 json In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. This co...
CVE-2026-58704 json In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proxima...
CVE-2026-58701 json In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lead t...
CVE-2026-58698 json In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could lead...
CVE-2026-58683 json In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to remo...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report