CVE.report
CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.
CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags
The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.
cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.
Recent CVEs
| CVE | Description | Updated |
|---|---|---|
| CVE-2026-2497 json | The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter a... | |
| CVE-2026-18347 json | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass ... | |
| CVE-2026-17608 json | The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery... | |
| CVE-2026-2357 json | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' sh... | |
| CVE-2026-17604 json | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal i... | |
| CVE-2026-17087 json | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization b... | |
| CVE-2026-13424 json | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scrip... | |
| CVE-2026-12998 json | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Dire... | |
| CVE-2026-10734 json | The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all ver... | |
| CVE-2026-9767 json | The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order... | |
| CVE-2026-19934 json | A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /... | |
| CVE-2026-19728 json | The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entit... | |
| CVE-2026-19726 json | The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing... | |
| CVE-2026-19725 json | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthent... | |
| CVE-2026-19717 json | The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its... | |
| CVE-2026-19714 json | The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, ... | |
| CVE-2026-19712 json | The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a pag... | |
| CVE-2026-19711 json | The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actu... | |
| CVE-2026-19613 json | The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater dat... | |
| CVE-2026-2283 json | The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions up to,... | |
| CVE-2026-18653 json | The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statemen... | |
| CVE-2026-18402 json | The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... | |
| CVE-2026-18316 json | The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability... | |
| CVE-2026-17582 json | The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7 via ... | |
| CVE-2026-17581 json | The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 'therma... | |
| CVE-2026-17533 json | The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to ... | |
| CVE-2026-16775 json | The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-S... | |
| CVE-2026-16758 json | The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all vers... | |
| CVE-2026-15790 json | The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.... | |
| CVE-2026-15604 json | The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.... | |
| CVE-2026-15384 json | The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authent... | |
| CVE-2026-15351 json | The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to ge... | |
| CVE-2026-15345 json | The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization by... | |
| CVE-2026-15056 json | The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulner... | |
| CVE-2026-13712 json | The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputt... | |
| CVE-2026-10035 json | The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and incl... | |
| CVE-2026-2671 json | A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionality of... | |
| CVE-2026-19933 json | A weakness has been identified in DefaultFuction Customer-Relationship-Management-In-C-Project 2.0. Impacted is the function ... | |
| CVE-2026-19932 json | A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects the function GroovyShell... | |
| CVE-2026-18432 json | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includ... | |
| CVE-2026-18385 json | The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePre... | |
| CVE-2026-17123 json | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including... | |
| CVE-2026-16779 json | The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.... | |
| CVE-2026-16099 json | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val... | |
| CVE-2026-16098 json | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2... | |
| CVE-2026-16079 json | The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content in a... | |
| CVE-2026-15963 json | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection v... | |
| CVE-2026-15726 json | The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all v... | |
| CVE-2026-15602 json | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'ad... | |
| CVE-2026-15441 json | The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 via the... | |
| CVE-2026-15066 json | The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all ve... | |
| CVE-2026-15009 json | The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulne... | |
| CVE-2026-15002 json | The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to... | |
| CVE-2026-14524 json | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat... | |
| CVE-2026-14498 json | The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 v... | |
| CVE-2026-13358 json | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecu... | |
| CVE-2026-13167 json | The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerab... | |
| CVE-2026-12905 json | The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via ... | |
| CVE-2026-12477 json | The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... | |
| CVE-2026-11780 json | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scrip... | |
| CVE-2025-10005 json | The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure Dir... | |
| CVE-2026-19930 json | A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.ph... | |
| CVE-2026-2487 json | The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u... | |
| CVE-2026-19926 json | A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown funct... | |
| CVE-2026-19925 json | A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the... | |
| CVE-2026-19924 json | A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7W... | |
| CVE-2026-19923 json | A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkou... | |
| CVE-2026-19922 json | A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown funct... | |
| CVE-2026-19921 json | A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown func... | |
| CVE-2026-19920 json | A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /acti... | |
| CVE-2026-19919 json | A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.ph... | |
| CVE-2026-19918 json | A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of ... | |
| CVE-2026-9165 json | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL que... | |
| CVE-2025-49796 json | A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corru... | |
| CVE-2025-49794 json | A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstance... | |
| CVE-2025-7425 json | A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory manage... | |
| CVE-2025-7195 json | Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a ra... | |
| CVE-2025-5914 json | A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() fu... | |
| CVE-2026-32590 json | A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediat... | |
| CVE-2026-19917 json | A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file ... | |
| CVE-2026-2100 json | A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remo... | |
| CVE-2025-5278 json | A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The prog... | |
| CVE-2024-5042 json | A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker c... | |
| CVE-2026-74767 json | Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the ... | |
| CVE-2026-74764 json | Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR ... | |
| CVE-2026-73055 json | Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix ... | |
| CVE-2026-73054 json | SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential... | |
| CVE-2026-73053 json | SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to saniti... | |
| CVE-2026-73052 json | SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option eleme... | |
| CVE-2026-73050 json | SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cr... | |
| CVE-2026-73047 json | siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view Templ... | |
| CVE-2026-73046 json | SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Aut... | |
| CVE-2026-73045 json | SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublis... | |
| CVE-2026-73044 json | SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting inje... | |
| CVE-2026-73043 json | SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which rende... | |
| CVE-2026-73042 json | SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute... | |
| CVE-2026-73041 json | SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint.... | |
| CVE-2026-32591 json | A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstre... | |
| CVE-2026-19916 json | A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function of th... | |
| CVE-2026-15927 json | A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/... |