377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 127/31432

CVE-2026-62108 CWE-290 9.8

WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vulnerability

Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.

cve.org miniOrange:Headless · Single · Sign 5 hari lalu
CVE-2026-62104 CWE-94 10.0

WordPress Migratico Lite plugin <= 2.6.8 - Remote Code Execution (RCE) vulnerability

Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.

cve.org superweby:Migratico · Lite 5 hari lalu
CVE-2026-62101 CWE-288 9.8

WordPress EduAdmin Booking plugin <= 5.4.2 - Broken Authentication vulnerability

Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

cve.org Chris · Åkerfeldt · Wendel:EduAdmin 5 hari lalu
CVE-2026-90986 CWE-79 7.1

WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.21 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions.

cve.org CODEPRESS · IT · Solutions 5 hari lalu
CVE-2026-85500 CWE-305 N/A

`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication

Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.…

cve.org team-alembic:ash_authentication · team-alembic:ash_authentication 5 hari lalu
CVE-2026-86533 CWE-613 N/A

Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti an…

cve.org team-alembic:ash_authentication · team-alembic:ash_authentication · team-alembic:ash_authentication_phoenix 5 hari lalu
CVE-2026-81632 CWE-598 N/A

Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix

Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and auth…

cve.org team-alembic:ash_authentication_phoenix · team-alembic:ash_authentication_phoenix · team-alembic:ash_authentication 5 hari lalu
CVE-2026-80218 CWE-287 N/A

Sign-in token minted for one resource accepted by another in AshAuthentication

Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource. AshAuthentication.Stra…

cve.org team-alembic:ash_authentication · team-alembic:ash_authentication 5 hari lalu
CVE-2026-78223 CWE-347 N/A

Token revocation record built from unverified JWT claims in AshAuthentication

Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource. …

cve.org team-alembic:ash_authentication · team-alembic:ash_authentication 5 hari lalu
CVE-2026-86522 CWE-117 N/A

Log injection via an unescaped password reset identity in AshAuthentication

Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or c…

cve.org team-alembic:ash_authentication · team-alembic:ash_authentication 5 hari lalu
CVE-2026-81637 CWE-613 N/A

Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attacker-controlled account…

cve.org team-alembic:ash_authentication · team-alembic:ash_authentication 5 hari lalu
CVE-2026-82761 CWE-367 N/A

Magic link single-use tokens replayable via TOCTOU race in AshAuthentication

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as the target subject. A ma…

cve.org team-alembic:ash_authentication · team-alembic:ash_authentication 5 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 23 Sep 2026 03:32
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.