CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-97853 json Memory Allocation with Excessive Size Value vulnerability in ericmj decimal allows Denial of Service. Decimal.round/3 builds...
CVE-2026-81797 json Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme <= 1.0.2 versions.
CVE-2026-78535 json Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.
CVE-2026-78534 json Unauthenticated Cross Site Scripting (XSS) in Educavo <= 3.4.2 versions.
CVE-2026-78533 json Unauthenticated PHP Object Injection in Qwery <= 3.6.1 versions.
CVE-2026-78532 json Unauthenticated Cross Site Scripting (XSS) in LMS <= 8.3 versions.
CVE-2026-78531 json Unauthenticated PHP Object Injection in Jacqueline <= 2.22 versions.
CVE-2026-78530 json Subscriber Arbitrary File Deletion in FoodBakery <= 4.6 versions.
CVE-2026-78529 json Unauthenticated PHP Object Injection in Alliance <= 3.11 versions.
CVE-2026-66569 json Unauthenticated PHP Object Injection in Kicker <= 2.2.1 versions.
CVE-2026-66568 json Unauthenticated PHP Object Injection in Original <= 1.9.0 versions.
CVE-2026-66567 json Unauthenticated PHP Object Injection in Anesta <= 1.5.3 versions.
CVE-2026-66566 json Unauthenticated Local File Inclusion in Ambient <= 1.7 versions.
CVE-2026-66565 json Unauthenticated PHP Object Injection in FC United <= 1.1.1 versions.
CVE-2026-66564 json Unauthenticated PHP Object Injection in ShiftCV <= 3.0.14 versions.
CVE-2026-66563 json Unauthenticated PHP Object Injection in Windsor <= 2.10 versions.
CVE-2026-66483 json Unauthenticated PHP Object Injection in Education Center <= 3.6.12 versions.
CVE-2026-66482 json Unauthenticated PHP Object Injection in Drone Media <= 2.2.0 versions.
CVE-2026-66481 json Author Arbitrary File Deletion in Presto Player Pro <= 3.0.1 versions.
CVE-2026-66480 json Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in YITH YITH WooCommerce Product Add...
CVE-2026-65459 json Unauthenticated Arbitrary Content Deletion in Forminator <= 1.57.3 versions.
CVE-2026-62130 json Shop manager PHP Object Injection in WooCommerce Multilingual & Multicurrency <= 5.5.8 versions.
CVE-2026-62129 json Contributor Arbitrary File Upload in Creator LMS <= 1.2.21 versions.
CVE-2026-62125 json Unauthenticated PHP Object Injection in Asia Garden <= 1.3.1 versions.
CVE-2026-62124 json Unauthenticated PHP Object Injection in N7 | Golf Club Sports & Events <= 2.21 versions.
CVE-2026-62123 json Unauthenticated PHP Object Injection in Invetex <= 2.18 versions.
CVE-2026-62120 json Unauthenticated PHP Object Injection in Law Office <= 3.20 versions.
CVE-2026-62118 json Unauthenticated Broken Access Control in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.
CVE-2026-62117 json Subscriber SQL Injection in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.
CVE-2026-62116 json Unauthenticated Cross Site Scripting (XSS) in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.
CVE-2026-62115 json Unauthenticated Local File Inclusion in KuteShop <= 4.2.9 versions.
CVE-2026-62100 json Unauthenticated Cross Site Scripting (XSS) in KuteShop <= 4.2.9 versions.
CVE-2026-62099 json Unauthenticated Local File Inclusion in Boutique <= 2.3.3 versions.
CVE-2026-62098 json Unauthenticated Content Injection in Boutique <= 2.3.3 versions.
CVE-2026-62096 json Unauthenticated Local File Inclusion in Biolife <= 3.2.3 versions.
CVE-2026-62095 json Unauthenticated Cross Site Scripting (XSS) in Biolife <= 3.2.3 versions.
CVE-2026-62094 json Unauthenticated Local File Inclusion in TechOne <= 3.0.3 versions.
CVE-2026-62093 json Unauthenticated Cross Site Scripting (XSS) in TechOne <= 3.0.3 versions.
CVE-2026-62092 json Unauthenticated Local File Inclusion in Armania <= 1.4.8 versions.
CVE-2026-62091 json Unauthenticated Cross Site Scripting (XSS) in Armania <= 1.4.8 versions.
CVE-2026-62090 json Unauthenticated PHP Object Injection in WineShop <= 3.20 versions.
CVE-2026-62087 json Unauthenticated PHP Object Injection in Equadio <= 1.1.4 versions.
CVE-2026-62086 json Unauthenticated PHP Object Injection in Juno <= 2.25 versions.
CVE-2026-62082 json Unauthenticated Cross Site Scripting (XSS) in Pin WP <= 7.0 versions.
CVE-2026-62077 json Unauthenticated PHP Object Injection in Avala <= 1.1.4 versions.
CVE-2026-62076 json Unauthenticated PHP Object Injection in Kalles <= 1.1.7.1 versions.
CVE-2026-62075 json Unauthenticated Local File Inclusion in Backhoe <= 2.0 versions.
CVE-2026-62074 json Unauthenticated Local File Inclusion in Ozeum <= 1.3.0 versions.
CVE-2026-62070 json Unauthenticated Local File Inclusion in Flipmart <= 2.8 versions.
CVE-2026-62069 json Unauthenticated Local File Inclusion in Fabius <= 1.0 versions.
CVE-2026-62068 json Unauthenticated Local File Inclusion in Teoro <= 1.1 versions.
CVE-2026-62067 json Unauthenticated Local File Inclusion in Kaven <= 1.2 versions.
CVE-2026-62066 json Unauthenticated Local File Inclusion in Volos <= 1.2 versions.
CVE-2026-62065 json Unauthenticated Local File Inclusion in Cardea <= 2.3 versions.
CVE-2026-62064 json Unauthenticated Cross Site Scripting (XSS) in Ambed <= 1.0.0 versions.
CVE-2026-62054 json Unauthenticated PHP Object Injection in Yacht Rental <= 2.6 versions.
CVE-2026-62053 json Unauthenticated PHP Object Injection in Wine House <= 3.20 versions.
CVE-2026-62052 json Unauthenticated PHP Object Injection in Tipsy <= 1.6 versions.
CVE-2026-62051 json Unauthenticated PHP Object Injection in Stargaze <= 1.10 versions.
CVE-2026-62050 json Unauthenticated PHP Object Injection in Splendour <= 1.23 versions.
CVE-2026-62043 json Unauthenticated Sensitive Data Exposure in Contact Form 7 – Dynamic Text Extension <= 5.0.7 versions.
CVE-2026-62038 json Unauthenticated Broken Authentication in eRoom <= 1.7.1 versions.
CVE-2026-62037 json Unauthenticated Cross Site Scripting (XSS) in Document Embedder <= 2.4.0 versions.
CVE-2026-62035 json Subscriber Broken Access Control in AWS S3 for WordPress Plugin – Upcasted <= 3.1.0 versions.
CVE-2026-62034 json Unauthenticated Cross Site Scripting (XSS) in Before After Image Comparison – Image comparison for WP <= 1.1.21 versions.
CVE-2026-62033 json Subscriber Settings Change in uListing <= 2.2.0 versions.
CVE-2026-62032 json Unauthenticated Local File Inclusion in DirectoryPress <= 3.6.27 versions.
CVE-2026-62031 json Unauthenticated SQL Injection in uListing <= 2.2.0 versions.
CVE-2026-62030 json Unauthenticated Server Side Request Forgery (SSRF) in StreamCast <= 2.4.5 versions.
CVE-2026-62027 json Unauthenticated Cross Site Scripting (XSS) in Team Section Block <= 2.0.4 versions.
CVE-2026-62025 json Unauthenticated Arbitrary File Upload in Tailored Tools <= 3.0.3 versions.
CVE-2026-62024 json Subscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions.
CVE-2026-62022 json Unauthenticated Privilege Escalation in Tonda Membership <= 1.0.1 versions.
CVE-2026-62021 json Subscriber PHP Object Injection in Angio <= 1.1.1 versions.
CVE-2026-62020 json Unauthenticated Local File Inclusion in TouchUp < 1.4 versions.
CVE-2026-57742 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group Kids Pla...
CVE-2026-48194 json Unauthenticated Local File Inclusion in DukaMarket <= 1.3.0 versions.
CVE-2026-48193 json Unauthenticated Local File Inclusion in Uminex <= 1.0.9 versions.
CVE-2026-45440 json Administrator SQL Injection in WP Ultimate CSV Importer <= 9.2 versions.
CVE-2026-42777 json Unauthenticated Local File Inclusion in Aalto <= 1.8 versions.
CVE-2026-42724 json Unauthenticated Local File Inclusion in CleanSkin <= 1.5.0 versions.
CVE-2026-42723 json Unauthenticated PHP Object Injection in CleanSkin <= 1.5.0 versions.
CVE-2026-42722 json Administrator SQL Injection in Frontend Admin by DynamiApps <= 3.29.13 versions.
CVE-2026-42719 json Subscriber PHP Object Injection in Dynamic User Directory <= 2.4 versions.
CVE-2026-42718 json Unauthenticated PHP Object Injection in Booster for WooCommerce <= 8.4.0 versions.
CVE-2026-42717 json Administrator SQL Injection in Leyka <= 3.32.3 versions.
CVE-2026-42716 json Unauthenticated PHP Object Injection in Payever - WooCommerce Gateway <= 4.8.2 versions.
CVE-2026-42715 json Unauthenticated Cross Site Scripting (XSS) in Photo Gallery by 10Web <= 1.8.47 versions.
CVE-2026-42712 json Subscriber SQL Injection in Qode Tours <= 3.1.3.2 versions.
CVE-2026-42711 json Unauthenticated Cross Site Scripting (XSS) in Slider by 10Web <= 1.2.63 versions.
CVE-2026-42709 json Unauthenticated Cross Site Scripting (XSS) in Food Menu – Restaurant Menu & Online Ordering for WooCommerce <= 6.0.5 versio...
CVE-2026-42706 json Unauthenticated Broken Access Control in DK <= 3.2.1 versions.
CVE-2026-42705 json Unauthenticated Broken Access Control in Grand News <= 3.4 versions.
CVE-2026-42704 json Unauthenticated Local File Inclusion in Kids Care <= 3.2.4 versions.
CVE-2026-42702 json Unauthenticated Cross Site Scripting (XSS) in Tutor LMS <= 4.1.0 versions.
CVE-2026-42699 json Unauthenticated Cross Site Scripting (XSS) in FV Player 8 <= 8.1.8 versions.
CVE-2026-42697 json Unauthenticated Cross Site Scripting (XSS) in Social Share Icons & Social Share Buttons <= 3.7.5 versions.
CVE-2026-42696 json Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.19 versions.
CVE-2026-42693 json Unauthenticated Cross Site Scripting (XSS) in Jannah <= 7.6.5 versions.
CVE-2026-42633 json Subscriber SQL Injection in Events Manager <= 7.4.6 versions.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report