377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 166/31432

CVE-2026-89029 CWE-639 4.3

Blog2Social WordPress Plugin < 9.1.0 User Enumeration via AJAX Handler

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. The b2s_get_select_mandant_user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs su…

cve.org Adenion:Blog2Social 16 Sep 2026
CVE-2026-61598 CWE-915 N/A

Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.mixins.model_binding.ModelBindingMixin` provides a default `update_model` even…

cve.org djust-org:djust 16 Sep 2026
CVE-2026-78301 CWE-349 5.8

Out-of-zone database nodes can become authoritative zone cuts

A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names…

cve.org ISC:BIND · 9 16 Sep 2026
CVE-2026-77692 CWE-476 7.5

Unauthenticated remote crash of named via a single DoH SIG(0) request

An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue affects BIND 9 versions…

cve.org ISC:BIND · 9 16 Sep 2026
CVE-2026-92141 CWE-? N/A

CVE-2026-92141

Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

cve.org Jenkins · Project:Jenkins · Keycloak 16 Sep 2026
CVE-2026-92140 CWE-? N/A

CVE-2026-92140

Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attacker…

cve.org Jenkins · Project:Jenkins · Gitee 16 Sep 2026
CVE-2026-92139 CWE-? N/A

CVE-2026-92139

Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attacke…

cve.org Jenkins · Project:Jenkins · Bitbucket 16 Sep 2026
CVE-2026-92138 CWE-? N/A

CVE-2026-92138

The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the server-side stored request token, allowing att…

cve.org Jenkins · Project:Jenkins · Bitbucket 16 Sep 2026
CVE-2026-92137 CWE-? N/A

CVE-2026-92137

Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller, allowing attackers…

cve.org Jenkins · Project:Jenkins · Robot 16 Sep 2026
CVE-2026-92136 CWE-? N/A

CVE-2026-92136

Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers …

cve.org Jenkins · Project:Jenkins · OWASP 16 Sep 2026
CVE-2026-92135 CWE-? N/A

CVE-2026-92135

Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a ja…

cve.org Jenkins · Project:Jenkins · Coverage 16 Sep 2026
CVE-2026-92134 CWE-? N/A

CVE-2026-92134

Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use…

cve.org Jenkins · Project:Jenkins · Warnings 16 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 25 Sep 2026 18:40
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.