CVE Notifier
Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.
arsip 377,174 CVE • 12,754 critical • 1,713 KEV
- 1999–2026
- 395.000+ CVE
- cve.org
- NVD CVSS
- CISA KEV
- Auto-update 30m
- SQLite full-text
Feed Kerentanan
Menampilkan 12 dari 377,174 entri — halaman 144/31432
Rundeck through 6.2.1 Authorization Bypass via Project Import
Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files i…
Pelican Panel before 1.0.0-beta35 Authorization Bypass via Startup
Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft Livewire sta…
WebVirtCloud Missing Authorization on Instance Control Actions
WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions. Attackers with read-only grants can power off virtual machines, reset root password…
Shlink through 5.1.6 Mercure Token Authorization Bypass
Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with author-only or domain-only keys can access the…
SecObserve before 1.59.1 Information Disclosure via API Configuration
SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product me…
PatrowlManager through 1.8.4 Improper Access Control via users API
PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can …
PatrowlManager through 1.8.4 Authorization Bypass via Events API
PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary …
metasfresh Unauthorized Access via Document Attachments and Comments Endpoints
metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions. Attackers can enumerate sequential document identifiers …
CMAK through 3.0.0.6 Cross-Site Request Forgery via Missing CSRF Filter
CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft hidden forms that submit to destru…
Harness through 3.3.0 Missing Access Control via infraproviders endpoint
Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces they do not belong to. Attackers can query …
SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret
SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who can bound the i…
BC Security Empire before 6.7.1 Path Traversal File Upload RCE
BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server. Attackers can use path traversa…
Statistik
Arsip lengkap kerentanan dari semua sumber — live dari database.
Distribusi Severity
CVSS v3- Critical 12,754 (8%)
- High 61,345 (41%)
- Medium 68,090 (45%)
- Low 8,634 (6%)
Tren CVE per Tahun
1999–2026cve.org
Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.
NVD
Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.
Wordfence
Kerentanan plugin/theme WordPress dari Wordfence Intelligence.
WPScan
Kerentanan ekosistem WordPress dari WPScan (Patchstack).
GitHub
CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).
MITRE
CNA asli yang menerbitkan dan mengelola CVE Record.
Sumber Data
cve.org
Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.
NVD
Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.
CISA KEV
Kerentanan yang aktif dieksploitasi — prioritas tinggi.
WPScan
Kerentanan ekosistem WordPress.
Wordfence
Kerentanan plugin/theme WordPress.
GitHub
Security Advisories ekosistem open source.