CVE Notifier
Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.
arsip 377,174 CVE • 12,754 critical • 1,713 KEV
- 1999–2026
- 395.000+ CVE
- cve.org
- NVD CVSS
- CISA KEV
- Auto-update 30m
- SQLite full-text
Feed Kerentanan
Menampilkan 12 dari 377,174 entri — halaman 46/31432
All Bootstrap Blocks 1.3.20 - 1.3.31 - Contributor+ LFI via lightspeed Block Attributes
The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and ab…
WP Ghost (Hide My WP Ghost) < 7.0.11 - Unauthenticated URL Hiding Bypass via Loopback Compatibility Check
The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, dropping that protection precisely when the request's…
WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request Parameters
The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere pres…
Breeze Cache 1.2.5 - 2.5.14 - Unauthenticated Cache Poisoning via Unkeyed Tracking Parameters
The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have …
Generate PDF using Contact Form 7 < 4.2.2 - Unauthenticated Server-Side Request Forgery via Array-Valued Form Field
The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on submitted form content, allowing unauthenticated users to make the ser…
Filter Gallery < 1.1.5 - Subscriber+ Arbitrary Post Overwrite and Plugin Option Deletion via Fail-Open Nonce Check
The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce field is omitted, and applies no capability check, allowing low-privileged users to overwrite the …
Bookit < 2.6.0.5 - Bookit Staff+ Appointment PII Disclosure
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appo…
Bookit < 2.6.0.5 - Bookit Staff+ Arbitrary Appointment Deletion via Missing Authorization
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to de…
All Bootstrap Blocks <= 1.3.31 - Contributor+ Stored XSS via areoi/button type Attribute
The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitra…
MasterStudy LMS 3.6.2 - < 3.7.50 - Instructor+ Student PII Disclosure via IDOR
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course before returning its enrolled-student data, allowing users with the MasterStudy LMS WordPress …
iGMS Direct Booking < 2.0 - Unauthenticated Stored XSS via Widget Settings
The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowing unauthenticated users to store arbitrary web scripts that execute in the context of an administrat…
Really Simple Security (Free) < 9.8.3 - Unauthenticated Unbounded Option Growth via Spoofed Client IP Header
The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that opti…
Statistik
Arsip lengkap kerentanan dari semua sumber — live dari database.
Distribusi Severity
CVSS v3- Critical 12,754 (8%)
- High 61,345 (41%)
- Medium 68,090 (45%)
- Low 8,634 (6%)
Tren CVE per Tahun
1999–2026cve.org
Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.
NVD
Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.
Wordfence
Kerentanan plugin/theme WordPress dari Wordfence Intelligence.
WPScan
Kerentanan ekosistem WordPress dari WPScan (Patchstack).
GitHub
CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).
MITRE
CNA asli yang menerbitkan dan mengelola CVE Record.
Sumber Data
cve.org
Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.
NVD
Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.
CISA KEV
Kerentanan yang aktif dieksploitasi — prioritas tinggi.
WPScan
Kerentanan ekosistem WordPress.
Wordfence
Kerentanan plugin/theme WordPress.
GitHub
Security Advisories ekosistem open source.