CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-91017 json The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming paym...
CVE-2026-90982 json @fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on ...
CVE-2026-87963 json The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using ...
CVE-2026-86801 json The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and the...
CVE-2026-44940 json The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure lo...
CVE-2026-1878 json An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege ...
CVE-2026-91019 json The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment ga...
CVE-2026-91016 json The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listi...
CVE-2026-91015 json The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action tha...
CVE-2026-91014 json The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its para...
CVE-2026-91011 json The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page ...
CVE-2026-91010 json The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the us...
CVE-2026-91009 json The Active Woot Products Tables for WooCommerce. 100% FREE  WordPress plugin before 2.1.3 does not have authorisation and CS...
CVE-2026-91008 json The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check...
CVE-2026-90923 json The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenti...
CVE-2026-90922 json The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the...
CVE-2026-88904 json The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the call...
CVE-2026-88795 json The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriv...
CVE-2026-88792 json The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or upd...
CVE-2026-87836 json The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate com...
CVE-2026-87786 json The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting t...
CVE-2026-86824 json The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and si...
CVE-2026-86788 json The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the sectio...
CVE-2026-86710 json The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matchi...
CVE-2026-86709 json The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails...
CVE-2026-86707 json The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it ...
CVE-2026-86446 json The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checke...
CVE-2026-85130 json The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the Ja...
CVE-2026-85128 json The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration again...
CVE-2026-56096 json The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax s...
CVE-2026-56095 json The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function wh...
CVE-2026-56094 json The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's o...
CVE-2026-56093 json The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user acces...
CVE-2026-56092 json The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests,...
CVE-2025-15697 json The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several ...
CVE-2024-9355 json A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer...
CVE-2026-87935 json The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via...
CVE-2026-87796 json The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and i...
CVE-2026-50604 json A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socke...
CVE-2026-25294 json Transient DOS while parsing frame during channel usage.
CVE-2026-25290 json Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
CVE-2026-25284 json Information Disclosure when a pointer is reused after being deallocated.
CVE-2026-25283 json Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
CVE-2026-25282 json Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
CVE-2026-25281 json Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
CVE-2026-25280 json Memory corruption when processing escape handling flow with insufficient user buffer sizes.
CVE-2026-25278 json Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
CVE-2026-25275 json Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-25261 json Memory corruption while processing rear sensor IOCTL calls.
CVE-2026-24081 json Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
CVE-2026-24075 json Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchro...
CVE-2026-24074 json Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
CVE-2026-24073 json Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
CVE-2025-59607 json Memory Corruption when copying large input data exceeds normal allocation limits.
CVE-2026-92839 json Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application t...
CVE-2026-86311 json The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2026-76460 json A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass a...
CVE-2026-50603 json A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulne...
CVE-2026-91106 json HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several softw...
CVE-2026-91105 json HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several softw...
CVE-2026-91104 json HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several softw...
CVE-2026-91098 json HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several softw...
CVE-2026-76424 json A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files ...
CVE-2026-76423 json A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain admini...
CVE-2026-76412 json A vulnerability in the remote diagnostics debugger of Cisco Secure FMC Software could allow an authenticated, remote attacker...
CVE-2026-20334 json As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance...
CVE-2026-20333 json As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance...
CVE-2026-20332 json As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance...
CVE-2026-20323 json A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Softwar...
CVE-2026-20287 json As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and...
CVE-2026-20284 json A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attac...
CVE-2026-20283 json A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary...
CVE-2026-20211 json A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying op...
CVE-2026-20176 json A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying op...
CVE-2026-91843 json A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root priv...
CVE-2026-86359 json Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged a...
CVE-2026-86358 json Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthent...
CVE-2026-76420 json A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Software...
CVE-2026-73464 json On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request c...
CVE-2026-73461 json On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to...
CVE-2026-73456 json Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enab...
CVE-2026-73453 json An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code e...
CVE-2026-71180 json Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged...
CVE-2026-71179 json Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an...
CVE-2026-20331 json As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance...
CVE-2026-20307 json A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute a...
CVE-2026-20306 json A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command inj...
CVE-2026-20305 json A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform com...
CVE-2026-20234 json As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and...
CVE-2025-43936 json Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticate...
CVE-2026-91749 json Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary ...
CVE-2026-91748 json Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised ...
CVE-2026-91745 json Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the s...
CVE-2026-91743 json Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer pro...
CVE-2026-91741 json Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code in...
CVE-2026-91738 json Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute a...
CVE-2026-91737 json Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the ...
CVE-2026-91736 json Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the ...
CVE-2026-91735 json Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the re...
CVE-2026-91734 json Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arb...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report