CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-89179 json WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability...
CVE-2026-89178 json WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthent...
CVE-2026-89177 json WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to th...
CVE-2026-89176 json WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. U...
CVE-2026-89175 json Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Una...
CVE-2026-89174 json Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability....
CVE-2026-89173 json Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauth...
CVE-2026-73392 json Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-12965.
CVE-2026-6642 json The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export...
CVE-2026-6641 json The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode...
CVE-2026-6640 json The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' p...
CVE-2026-87908 json multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not includin...
CVE-2026-86815 json The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, back...
CVE-2026-86812 json The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints bec...
CVE-2026-86782 json The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing user...
CVE-2026-86781 json The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or non...
CVE-2026-86780 json The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before ...
CVE-2026-86779 json The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wid...
CVE-2026-85678 json The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it insi...
CVE-2026-85677 json The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements t...
CVE-2026-83546 json The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attri...
CVE-2026-83545 json The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inl...
CVE-2026-82305 json The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wish...
CVE-2026-74925 json The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing ...
CVE-2026-73785 json A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to...
CVE-2026-73784 json A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker t...
CVE-2026-14566 json The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check bef...
CVE-2026-14565 json The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check bef...
CVE-2026-14563 json The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated s...
CVE-2026-14562 json The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before r...
CVE-2026-14560 json The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-...
CVE-2026-14559 json The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, a...
CVE-2026-13326 json An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of se...
CVE-2025-15695 json The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundl...
CVE-2026-89169 json live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity f...
CVE-2026-85150 json A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Auth...
CVE-2026-89162 json In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the ac...
CVE-2026-89060 json A flaw was found in multicluster-observability-addon. This vulnerability allows a managed-cluster identity to reference confi...
CVE-2026-89161 json In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free...
CVE-2026-89160 json PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject...
CVE-2026-89158 json PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.
CVE-2026-89157 json PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large...
CVE-2026-89156 json PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.
CVE-2026-84960 json The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Query String in...
CVE-2026-81825 json The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Ch...
CVE-2026-8778 json The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable...
CVE-2026-81754 json The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… plugin for WordPress is vulnerable to St...
CVE-2026-78172 json The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Par...
CVE-2026-77150 json The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Pa...
CVE-2026-19991 json The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the up...
CVE-2026-19985 json The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an...
CVE-2026-18964 json The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin...
CVE-2026-18579 json The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' para...
CVE-2026-18562 json The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripti...
CVE-2026-18561 json The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in ver...
CVE-2026-15462 json The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of ...
CVE-2026-12215 json The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all v...
CVE-2026-11496 json The Woo PDF Invoice Builder plugin (also distributed as "PDF Builder for WooCommerce") for WordPress is vulnerable to Insecur...
CVE-2026-7438 json The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` ...
CVE-2026-89092 json The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns to...
CVE-2026-85217 json A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy set...
CVE-2026-82079 json A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attac...
CVE-2026-81468 json Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Comman...
CVE-2026-81467 json Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Comman...
CVE-2026-81049 json Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privilege...
CVE-2026-81048 json Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Co...
CVE-2026-81046 json Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated atta...
CVE-2026-79987 json A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating sys...
CVE-2026-73787 json A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a v...
CVE-2026-73769 json A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker...
CVE-2026-19584 json Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor resto...
CVE-2026-19583 json Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell arti...
CVE-2026-11446 json The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthorized ...
CVE-2026-0310 json A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauth...
CVE-2026-0309 json A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass sy...
CVE-2026-0307 json Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to esc...
CVE-2026-0304 json A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user ...
CVE-2026-80172 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an In...
CVE-2026-79972 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im...
CVE-2026-79963 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Dow...
CVE-2026-79945 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im...
CVE-2026-79941 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im...
CVE-2026-79741 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im...
CVE-2026-79689 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im...
CVE-2026-78493 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im...
CVE-2026-78484 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im...
CVE-2026-70425 json Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.1...
CVE-2026-23855 json Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to...
CVE-2026-79974 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im...
CVE-2026-79641 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im...
CVE-2026-79637 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im...
CVE-2026-78494 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im...
CVE-2026-78492 json Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Im...
CVE-2026-21104 json Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute...
CVE-2026-21102 json Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with ro...
CVE-2026-21101 json Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially ...
CVE-2026-21096 json Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers ...
CVE-2026-21095 json Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers t...
CVE-2026-21087 json Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with syst...
CVE-2026-86060 json RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character,...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report