CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-92435 json | The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capab... | |
| CVE-2026-92430 json | The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authe... | |
| CVE-2026-92425 json | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level a... | |
| CVE-2026-92421 json | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host r... | |
| CVE-2026-92420 json | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking ... | |
| CVE-2026-92404 json | The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing un... | |
| CVE-2026-92403 json | The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds ... | |
| CVE-2026-92099 json | The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query id... | |
| CVE-2026-91847 json | The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns th... | |
| CVE-2026-88926 json | The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its par... | |
| CVE-2026-88824 json | The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthentica... | |
| CVE-2026-86814 json | The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email ... | |
| CVE-2026-86591 json | The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing un... | |
| CVE-2026-85680 json | The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before o... | |
| CVE-2026-85574 json | The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configura... | |
| CVE-2026-84750 json | The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uploaded ... | |
| CVE-2026-76790 json | The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a reque... | |
| CVE-2026-76554 json | The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to crea... | |
| CVE-2026-19860 json | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP f... | |
| CVE-2026-16557 json | The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder co... | |
| CVE-2025-15698 json | The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow... | |
| CVE-2026-93741 json | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function for... | |
| CVE-2026-93382 json | Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside t... | |
| CVE-2026-93381 json | Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social e... | |
| CVE-2026-93377 json | Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execu... | |
| CVE-2026-93375 json | Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to p... | |
| CVE-2026-93374 json | Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute... | |
| CVE-2026-93373 json | Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outs... | |
| CVE-2026-93372 json | Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary... | |
| CVE-2026-87701 json | Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows ... | |
| CVE-2026-85917 json | Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-85889 json | Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a... | |
| CVE-2026-85885 json | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized atta... | |
| CVE-2026-85878 json | Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-83944 json | Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-77903 json | Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network... | |
| CVE-2026-70200 json | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized att... | |
| CVE-2026-70009 json | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker t... | |
| CVE-2026-69843 json | Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-62874 json | Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a ... | |
| CVE-2026-55946 json | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthoriz... | |
| CVE-2026-15815 json | Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin ar... | |
| CVE-2026-11381 json | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improp... | |
| CVE-2026-11378 json | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an int... | |
| CVE-2026-11375 json | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stac... | |
| CVE-2026-10858 json | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potential... | |
| CVE-2026-10853 json | IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrar... | |
| CVE-2026-10751 json | IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications d... | |
| CVE-2026-10747 json | IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a he... | |
| CVE-2026-10744 json | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potential... | |
| CVE-2026-10575 json | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap bu... | |
| CVE-2026-10027 json | IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when pro... | |
| CVE-2025-15399 json | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-si... | |
| CVE-2026-83318 json | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions that ar... | |
| CVE-2026-83315 json | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions t... | |
| CVE-2026-92967 json | The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' parameter in versions up t... | |
| CVE-2026-92807 json | The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to,... | |
| CVE-2026-92229 json | The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary... | |
| CVE-2026-89334 json | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authori... | |
| CVE-2026-89333 json | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference... | |
| CVE-2026-89274 json | The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including,... | |
| CVE-2026-89093 json | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Informa... | |
| CVE-2026-92970 json | HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated ... | |
| CVE-2026-92944 json | vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() byp... | |
| CVE-2026-92938 json | vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is pe... | |
| CVE-2026-92933 json | vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the sand... | |
| CVE-2026-89081 json | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v... | |
| CVE-2026-88944 json | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all vers... | |
| CVE-2026-87909 json | The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick... | |
| CVE-2026-84434 json | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 v... | |
| CVE-2026-78528 json | Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions. | |
| CVE-2026-52483 json | The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0... | |
| CVE-2026-15760 json | The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including, 5.8... | |
| CVE-2026-15660 json | The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.4.7. This is ... | |
| CVE-2026-13354 json | The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content i... | |
| CVE-2026-12042 json | The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio... | |
| CVE-2026-92917 json | Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and seria... | |
| CVE-2026-92912 json | AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in ... | |
| CVE-2026-92860 json | A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmt.Spr... | |
| CVE-2026-92595 json | Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` ... | |
| CVE-2026-92590 json | Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feat... | |
| CVE-2026-92585 json | AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API l... | |
| CVE-2026-92580 json | In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.js... | |
| CVE-2026-89034 json | TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy ... | |
| CVE-2026-87796 json | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and i... | |
| CVE-2026-74002 json | Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions. | |
| CVE-2026-66630 json | Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. | |
| CVE-2026-66619 json | Administrator SQL Injection in Newsletters <= 4.18 versions. | |
| CVE-2026-66579 json | Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. | |
| CVE-2026-66574 json | Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions. | |
| CVE-2026-62104 json | Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions. | |
| CVE-2026-61588 json | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to versi... | |
| CVE-2026-27553 json | A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_r... | |
| CVE-2026-77820 json | The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all versi... | |
| CVE-2026-92812 json | decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix compa... | |
| CVE-2026-92805 json | UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in Configure... | |
| CVE-2026-92800 json | Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. At... | |
| CVE-2026-92792 json | OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a tes... | |
| CVE-2026-92787 json | Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all... | |
| CVE-2026-92782 json | Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attack... |