CVE.report

CVE.report is the most up-to-date database of common vulnerabilities and exposures. Information is pulled in from several sources and processed in to a mobile friendly, easy to use page. Use the site to quickly check for vulnerabilities in products such as operating systems, applications, hardware, networks, databases, browsers, e-mail clients and more.

CVEs provide a unique and common naming scheme for publicly known cyber security vulnerabilities in order to quickly identify and share these vulnerabilities. You can use the search below to look for vulnerabilities based on product, vendor, or common tags


The form you will see after following this link allows you to fill out the various variables in the CVSS scoring system and receive the corresponding score. The description of each of the variables is also included for additional information.

cve.report now provides a free read-only JSON API for CVE details. Each record combines the CVE Program JSON record, NVD enrichment, KEV, and EPSS when available.

Read the API docs

[rss] [api]

Recent CVEs

Recently updated CVE records
CVE Description Updated
CVE-2026-105219 json Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in li...
CVE-2026-105218 json gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-mid...
CVE-2026-105217 json Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing n...
CVE-2026-105216 json go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate ...
CVE-2026-105161 json A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component ...
CVE-2026-105224 json YesWiki before 4.6.7 contains a cross-site scripting vulnerability in the Bazar valeur action that allows page editors to inj...
CVE-2026-105089 json WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to i...
CVE-2026-105086 json WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to i...
CVE-2026-104402 json Insertion of Sensitive Information Into Sent Data vulnerability in farvisun Mindio Magic MCP mindio-magic-mcp allows Retrieve...
CVE-2026-88779 json Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 1...
CVE-2026-12392 json An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an u...
CVE-2026-104470 json YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows page editors to make the server fetch a...
CVE-2026-105215 json ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external...
CVE-2026-105214 json Zitadel before 4.16.2 contains a server-side request forgery vulnerability that allows attackers to make the server request i...
CVE-2026-105213 json ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the ...
CVE-2026-105212 json ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs tha...
CVE-2026-105211 json ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to ta...
CVE-2026-105210 json ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose secon...
CVE-2026-105209 json ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or pas...
CVE-2026-105208 json ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allow...
CVE-2026-105207 json ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers with...
CVE-2026-105206 json ZITADEL 3.0.0 through 3.4.15 and 4.x before 4.17.3 contains an incorrect authorization flaw in the User Service API, which ve...
CVE-2026-105205 json SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish-mode readers to learn backlink block...
CVE-2026-105158 json A vulnerability was detected in RainyGao DocSys up to 2.02.85. The impacted element is the function BaseController.createDBFo...
CVE-2026-105157 json A security vulnerability has been detected in RainyGao DocSys up to 2.02.85. The affected element is the function DocControll...
CVE-2026-105156 json A weakness has been identified in YzmCMS up to 7.6. Impacted is the function Password of the file /common/function/system.fun...
CVE-2026-105149 json A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects some unknown processing of the file /stores/...
CVE-2026-105148 json A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/ab...
CVE-2026-105147 json A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler...
CVE-2026-105146 json A vulnerability was found in Comsenz Discuz! X5.0-20260801/X5.0-20260820/X5.0-20260910. Affected by this issue is the functio...
CVE-2026-105145 json A vulnerability has been found in Weaviate Verba up to 2.1.3. Affected by this vulnerability is the function get_environment ...
CVE-2026-97307 json Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-bui...
CVE-2026-105144 json A flaw has been found in Drogon up to 1.9.13-1/10.0-beta.3 on Windows. Affected is the function StaticFileRouter::route of th...
CVE-2026-97276 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistic...
CVE-2026-105141 json A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_em...
CVE-2026-105137 json A vulnerability was found in Laradock up to 20.4. Impacted is an unknown function of the file workspace/Dockerfile of the com...
CVE-2026-103355 json Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unli...
CVE-2026-103354 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP ...
CVE-2026-103344 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unli...
CVE-2026-103062 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs TranslatePre...
CVE-2026-97332 json The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite install...
CVE-2026-93549 json The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disab...
CVE-2026-86817 json The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to reso...
CVE-2026-105135 json A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file ...
CVE-2026-105134 json A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/Updat...
CVE-2026-105133 json A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/...
CVE-2026-104119 json The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting th...
CVE-2026-104118 json The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API r...
CVE-2026-17005 json The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement sett...
CVE-2026-105099 json A weakness has been identified in Omega Solution CoinEx Crypto 2025. Affected by this vulnerability is an unknown functionali...
CVE-2026-105098 json A security flaw has been discovered in Omega Solution CoinEx Crypto 2025. Affected is an unknown function of the file /ticket...
CVE-2026-105097 json A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-c...
CVE-2026-105131 json ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to ...
CVE-2026-105096 json A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ ...
CVE-2026-105130 json LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows una...
CVE-2026-105129 json LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settin...
CVE-2026-105128 json LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplyin...
CVE-2026-105127 json LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requ...
CVE-2026-105126 json LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to e...
CVE-2026-105125 json LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files b...
CVE-2026-105124 json W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated atta...
CVE-2026-105123 json W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to w...
CVE-2026-103111 json PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bound...
CVE-2026-100630 json AVideo before 29.1.0 contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized wi...
CVE-2026-105105 json CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NAS...
CVE-2026-104313 json The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ...
CVE-2026-103519 json The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc...
CVE-2026-103421 json The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'R...
CVE-2026-103342 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unli...
CVE-2026-103065 json Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Pr...
CVE-2026-100157 json The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc...
CVE-2026-97660 json The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpcpo-* Array K...
CVE-2026-97344 json The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar ...
CVE-2026-97343 json The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Impr...
CVE-2026-97341 json The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'X-R...
CVE-2026-97337 json The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information discl...
CVE-2026-96962 json The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenti...
CVE-2026-96650 json The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Fi...
CVE-2026-96575 json The Transliterator – Multilingual and Multi-script Text Conversion plugin for WordPress is vulnerable to Stored Cross-Site ...
CVE-2026-96564 json The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Dis...
CVE-2026-96451 json Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Priv...
CVE-2026-96267 json The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' p...
CVE-2026-94505 json The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypa...
CVE-2026-94239 json The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputt...
CVE-2026-94238 json The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, al...
CVE-2026-93896 json The WPFront Notification Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl...
CVE-2026-93889 json The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail...
CVE-2026-92974 json The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scrip...
CVE-2026-92767 json The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'offset' Shortcode Attr...
CVE-2026-92084 json The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortco...
CVE-2026-87115 json The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficie...
CVE-2026-75028 json The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File ...
CVE-2026-18443 json The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL...
CVE-2026-15795 json The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2026-11601 json The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorizati...
CVE-2026-103913 json The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listi...
CVE-2026-103909 json The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is...
CVE-2026-103888 json The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woosq-...
CVE-2026-103514 json The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing ...
CVE-2026-103293 json The MPG WordPress plugin before 4.2.3 does not validate that the dataset source supplied when importing a project is a remot...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report