377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 203/31432

CVE-2026-86475 CWE-? 5.3

Appointment Hour Booking < 1.5.95 - Unauthenticated Booking Capacity Bypass via Multi-Appointment Submission

The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unauthenticated visitors to take slots that …

WPScan Unknown:Appointment · Hour · Booking 16 Sep 2026
CVE-2026-84906 CWE-? 5.3

Eventin < 4.1.24 - Unauthenticated Payment Bypass via Stripe and PayPal Cross-Order Transaction Replay

The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amoun…

WPScan Unknown:Eventin 16 Sep 2026
CVE-2026-19857 CWE-? 4.8

Formidable Forms < 6.35 - Unauthenticated Arbitrary Shortcode Execution via [entry_key] Custom HTML Token

The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML, allowing unauthenti…

WPScan Unknown:Formidable · Forms 16 Sep 2026
CVE-2026-13407 CWE-? 6.1

Royal Elementor Addons < 1.7.1067 - Unauthenticated Stored HTML Injection in Form Notification Emails

The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing …

WPScan Unknown:Royal · Addons · for 16 Sep 2026
CVE-2026-73447 CWE-78 9.1

Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request

A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz se…

cve.org Arista · Networks:EOS 16 Sep 2026
CVE-2026-89328 CWE-? N/A

FluentBoards < 2.0.15 - Board Member+ Board Membership and Public Access Modification

The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any …

WPScan Unknown:FluentBoards 16 Sep 2026
CVE-2026-89327 CWE-? N/A

FluentBoards < 2.0.15 - Board Member+ Comment Author Spoofing via 'comment_by' Parameter

The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user the comment is attributed to, allowing any board member to post comments that appear to be authored by…

WPScan Unknown:FluentBoards 16 Sep 2026
CVE-2026-88910 CWE-? N/A

KBoard < 6.7 - Unauthenticated Board Media Deletion via IDOR

The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media files and their database records by ite…

WPScan Unknown:kboard 16 Sep 2026
CVE-2026-87959 CWE-? N/A

WPBot 8.7.2 - 8.7.5 - Subscriber+ Claude AI Settings Update

The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI provider settings, allowing users with subscriber-level access to overwrite those settings, includi…

WPScan Unknown:WPBot 16 Sep 2026
CVE-2026-87907 CWE-? N/A

Rox Appointment Booking < 1.2.8 - Unauthenticated Internal Notes Disclosure via Service and Category REST Routes

The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing unauthenticated attackers to read the privat…

WPScan Unknown:Rox · Appointment · Booking 16 Sep 2026
CVE-2026-87896 CWE-? N/A

Rox Appointment Booking < 1.2.8 - Unauthenticated Staff PII Disclosure via Agent REST Route

The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that returns booking agent (staff) records, allowing unauthenticated attackers to read staff email addre…

WPScan Unknown:Rox · Appointment · Booking 16 Sep 2026
CVE-2026-87860 CWE-? N/A

Subscriptions for WooCommerce < 2.0.3 - Subscription Cancellation via CSRF

The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make a logged-in customer cancel their own active subsc…

WPScan Unknown:Subscriptions · for · WooCommerce 16 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 26 Sep 2026 06:06
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.