377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 204/31432

CVE-2026-87854 CWE-? N/A

Subscriptions for WooCommerce < 2.0.3 - Unauthenticated Subscription Data Disclosure via REST API Secret Key Bypass

The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users to retrieve the store's full list of subs…

WPScan Unknown:Subscriptions · for · WooCommerce 16 Sep 2026
CVE-2026-87828 CWE-? N/A

Seraphinite Accelerator < 2.29.24 - Subscriber+ DoS via seraph_accel_State Update

The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJAX actions, allowing authenticated users such as subscribers to write a malformed value that ca…

WPScan Unknown:Seraphinite · Accelerator 16 Sep 2026
CVE-2026-86823 CWE-? N/A

Newsletter < 9.3.7 - Unauthenticated Open Redirect and Subscriber Token Disclosure via ncu Parameter

The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subscription action, allowing unauthenticated attackers to redirect users to arbitrary external sit…

WPScan Unknown:Newsletter 16 Sep 2026
CVE-2026-86784 CWE-? N/A

Visualizer < 4.0.8 - Contributor+ Stored XSS via JSON Data Source

The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before outputting it back in the chart editor, allowing users with the Contributor role and above to sto…

WPScan Unknown:Visualizer 16 Sep 2026
CVE-2026-86449 CWE-? N/A

LearnPress < 4.4.7 - Unauthenticated Unpublished Course Disclosure via REST API

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied post status filter in one of its REST routes, allowing unauthenticated attackers to list courses that a…

WPScan Unknown:LearnPress 16 Sep 2026
CVE-2026-86448 CWE-? N/A

LearnPress < 4.4.7 - Unauthenticated Order Data Disclosure via lp_download_order

The LearnPress WordPress plugin before 4.4.7 does not perform any authentication, capability or nonce check before serving a previously generated order export file, allowing unauthenticated attackers who can determine i…

WPScan Unknown:LearnPress 16 Sep 2026
CVE-2026-86447 CWE-? N/A

LearnPress < 4.4.7 - Unauthenticated Student Enrollment Disclosure via load_content_via_ajax

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative course tools, allowing unauthenticated attackers to list every enrolled student's display name and user id…

WPScan Unknown:LearnPress 16 Sep 2026
CVE-2026-86445 CWE-? N/A

LearnPress < 4.4.7 - Unauthenticated Question Bank Disclosure via load_content_via_ajax

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the text, identifier and type of every p…

WPScan Unknown:LearnPress 16 Sep 2026
CVE-2026-86444 CWE-? N/A

LearnPress < 4.4.7 - Reflected XSS via 'skin' Parameter

The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute on a public page, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser…

WPScan Unknown:LearnPress 16 Sep 2026
CVE-2026-85641 CWE-? N/A

Formidable Forms 6.34 - Unauthenticated Stored Content Injection via 'updated_by' Parameter

The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user last edited a form entry, and relies on that identifier when deciding whether to strip HTML from stored…

WPScan Unknown:Formidable · Forms 16 Sep 2026
CVE-2026-85572 CWE-? N/A

Tutor LMS 4.0.0 - < 4.0.8 - Subscriber+ Cross-Course Lesson Comment Disclosure

The Tutor LMS WordPress plugin before 4.0.8 does not check that a user has access to a course before returning its lesson discussion content, allowing any authenticated user, such as a subscriber, to read comments from …

WPScan Unknown:Tutor · LMS 16 Sep 2026
CVE-2026-85569 CWE-? N/A

Tutor LMS 2.7.1 - < 4.0.8 - Read-Only API Key Privilege Escalation via REST Request Misclassification

The Tutor LMS WordPress plugin before 4.0.8 does not correctly determine whether an incoming request is addressed to its own REST API, and does not enforce the permission recorded against an API credential, allowing the…

WPScan Unknown:Tutor · LMS 16 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 26 Sep 2026 06:14
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.