377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 201/31432

CVE-2026-27553 CWE-497 6.5

Information Disclosure via Schema Path Manipulation

A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27552 CWE-863 8.1

Unauthorized IODD File Upload due to Improper Authorization

A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system cra…

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27551 CWE-78 8.8

Command Injection in /index.php/ajax/parameterManage

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27550 CWE-78 8.8

Command Injection in Field_Shadow_Password Class

A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27549 CWE-78 8.8

Command Injection in /index.php/attached_devices_tab/do_upload

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on t…

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27548 CWE-78 8.8

Command Injection in /index.php/ajax/get_iodd_port_info

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on …

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27547 CWE-78 8.8

Command Injection in /index.php/ajax/get_iodd_menu_info

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileg…

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-27546 CWE-288 9.8

Authentication Bypass in _account_log

An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

cve.org Pepperl+Fuchs:ICE2-8IOL1-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-G65L-V1D · Pepperl+Fuchs:ICE2-8IOL-K45P-RJ45 16 Sep 2026
CVE-2026-92091 CWE-407 5.9

Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops array

A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of key_ops is not bounded. A remote, unauth…

cve.org Red · Hat:Red · Hat 16 Sep 2026
CVE-2026-84408 CWE-782 8.8

CVE-2026-84408

QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to execute arbitrary commands with…

cve.org QualitySoft · Corporation:QND · Premium 16 Sep 2026
CVE-2026-81326 CWE-321 5.5

CVE-2026-81326

QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to obtain administrator credentials, including an ID and passwor…

cve.org QualitySoft · Corporation:QND · Premium 16 Sep 2026
CVE-2026-92355 CWE-22 N/A

CVE-2026-92355

In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead…

cve.org Octopus · Deploy:Octopus · Server 16 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 26 Sep 2026 05:33
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.