377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 200/31432

CVE-2026-27565 CWE-78 9.8

Remote code execution via uploading a malicious IODD file

An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27564 CWE-78 7.2

Command Injection via PUT in /api/datastorage/data

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on…

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27563 CWE-78 7.2

Command Injection via GET in /api/datastorage/data

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privi…

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27562 CWE-78 7.2

Command Injection via PUT in /api/iodd/config

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges…

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27561 CWE-78 7.2

Command Injection via GET in /api/iodd/config

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges…

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27560 CWE-78 7.2

Command Injection via DELETE in /api/status/data

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privile…

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27559 CWE-78 8.8

Command Injection via GET in /api/status/data

A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges o…

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27558 CWE-78 8.8

Command Injection in /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands wit…

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27557 CWE-35 7.5

Path Traversal in /index.php/view_uploaded_iodd_file

An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27556 CWE-98 8.8

Local File Inclusion in /index.php/ajax/save_iodd_parameters

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27555 CWE-98 8.8

Local File Inclusion in /index.php/ajax/get_iodd_port_info

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27554 CWE-78 8.8

Command Injection in /index.php/ajax/save_iodd_parameters

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the de…

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 26 Sep 2026 05:02
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.