CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-105105 json CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NAS...
CVE-2026-104313 json The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ...
CVE-2026-103519 json The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc...
CVE-2026-103421 json The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'R...
CVE-2026-103342 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unli...
CVE-2026-103065 json Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Pr...
CVE-2026-100157 json The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc...
CVE-2026-97660 json The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpcpo-* Array K...
CVE-2026-97344 json The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar ...
CVE-2026-97343 json The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Impr...
CVE-2026-97341 json The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'X-R...
CVE-2026-97337 json The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information discl...
CVE-2026-96962 json The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenti...
CVE-2026-96650 json The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Fi...
CVE-2026-96575 json The Transliterator – Multilingual and Multi-script Text Conversion plugin for WordPress is vulnerable to Stored Cross-Site ...
CVE-2026-96564 json The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Dis...
CVE-2026-96451 json Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Priv...
CVE-2026-96267 json The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' p...
CVE-2026-94505 json The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypa...
CVE-2026-94239 json The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputt...
CVE-2026-94238 json The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, al...
CVE-2026-93896 json The WPFront Notification Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl...
CVE-2026-93889 json The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail...
CVE-2026-92974 json The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scrip...
CVE-2026-92767 json The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'offset' Shortcode Attr...
CVE-2026-92084 json The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortco...
CVE-2026-87115 json The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficie...
CVE-2026-75028 json The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File ...
CVE-2026-18443 json The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL...
CVE-2026-15795 json The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2026-11601 json The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorizati...
CVE-2026-103913 json The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listi...
CVE-2026-103909 json The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is...
CVE-2026-103888 json The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woosq-...
CVE-2026-103514 json The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing ...
CVE-2026-103293 json The MPG WordPress plugin before 4.2.3 does not validate that the dataset source supplied when importing a project is a remot...
CVE-2026-101928 json The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' para...
CVE-2026-101923 json The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and inc...
CVE-2026-101357 json The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'seopr...
CVE-2026-101162 json The WP Ultimate Review WordPress plugin before 2.4.4 does not escape some of its review overview settings before outputting t...
CVE-2026-101161 json The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review conte...
CVE-2026-101160 json The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before stori...
CVE-2026-101159 json The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its publ...
CVE-2026-100152 json The The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin f...
CVE-2026-100149 json The WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons plugin for WordPress is vulnerable to Sensitive Info...
CVE-2026-100148 json The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reviews[].tex...
CVE-2026-97644 json The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via ...
CVE-2026-93430 json The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title' and 'url' Render Args in g...
CVE-2026-92977 json The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2026-92923 json The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it ...
CVE-2026-92437 json The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check befo...
CVE-2026-91108 json The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to aut...
CVE-2026-91078 json The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account i...
CVE-2026-89236 json The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDE...
CVE-2026-88783 json The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the edito...
CVE-2026-88782 json The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outp...
CVE-2026-87091 json The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Settlement Notification Paramete...
CVE-2026-86834 json The MetForm WordPress plugin before 4.3.1 does not properly restrict access to a debug file it writes to the web root on eve...
CVE-2026-86832 json The MetForm WordPress plugin before 4.3.1 does not properly restrict access to form submission data, allowing unauthenticate...
CVE-2026-85568 json The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not correctly handle a search value before rewriting...
CVE-2026-85015 json The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise file paths inside uploaded archives bef...
CVE-2026-80518 json The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when deriving the storage locat...
CVE-2026-80517 json The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded ...
CVE-2026-11399 json The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in ...
CVE-2025-12828 json The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Type Out widget...
CVE-2026-104912 json MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute ...
CVE-2026-104910 json MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events co...
CVE-2026-104055 json The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" ...
CVE-2026-103648 json Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response dat...
CVE-2026-103629 json Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a cr...
CVE-2026-103626 json Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leverag...
CVE-2026-103624 json Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had co...
CVE-2026-103621 json Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data v...
CVE-2026-101104 json The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipu...
CVE-2026-100180 json The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulner...
CVE-2026-97652 json The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Reflected C...
CVE-2026-97363 json The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of ...
CVE-2026-97212 json The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to conne...
CVE-2026-96613 json The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access...
CVE-2026-96270 json The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin f...
CVE-2026-95865 json The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection v...
CVE-2026-95102 json WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, ...
CVE-2026-94594 json Armatura One's message broker logs client connection credentials and the associated password in plain text during normal oper...
CVE-2026-94593 json Armatura One's backup and restore routine records the full database connection command, including the superuser password, in ...
CVE-2026-94592 json Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at ...
CVE-2026-94591 json Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CB...
CVE-2026-94539 json The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to time-based ...
CVE-2026-94378 json The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cros...
CVE-2026-93474 json Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-93428 json The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin f...
CVE-2026-92826 json The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Parameter Key i...
CVE-2026-92727 json The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for Wor...
CVE-2026-92551 json The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress p...
CVE-2026-92538 json The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Reflected DO...
CVE-2026-92536 json The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress p...
CVE-2026-92243 json The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's'...
CVE-2026-87920 json The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Output-Buffer Re...
CVE-2026-85492 json The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for W...
CVE-2026-84411 json The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that...
CVE-2026-75937 json A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbit...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report