377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 48/31432

CVE-2026-84904 CWE-? N/A

King Addons for Elementor 51.1.56 - 51.1.80 - Author+ Missing Authorization via Image Optimizer

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged user…

WPScan Unknown:King · Addons · for 2 hari lalu
CVE-2026-84903 CWE-? N/A

King Addons for Elementor < 51.1.81 - Contributor+ Private Post Content Disclosure via kng_maintenance_page Shortcode

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the content of a user-supplied post, allowing users with Contributor-level a…

WPScan Unknown:King · Addons · for 2 hari lalu
CVE-2026-84902 CWE-? N/A

King Addons for Elementor < 51.1.81 - Contributor+ Stored XSS via Template Catalog Import

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to o…

WPScan Unknown:King · Addons · for 2 hari lalu
CVE-2026-84738 CWE-? N/A

AF Companion < 2.2.0 - Shop Manager+ Arbitrary File Upload to RCE

The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, inclu…

WPScan Unknown:AF · Companion 2 hari lalu
CVE-2026-81810 CWE-? N/A

All-in-One WP Migration and Backup < 7.111 - Authenticated Privilege Escalation to Admin via Import Secret Key Disclosure

The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user pe…

WPScan Unknown:All-in-One · WP · Migration 2 hari lalu
CVE-2026-81340 CWE-? N/A

MasterStudy LMS < 3.7.50 - Instructor+ Order Status Manipulation via IDOR

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify…

WPScan Unknown:MasterStudy · LMS · WordPress 2 hari lalu
CVE-2026-93485 CWE-79 7.1

WordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through …

cve.org Automattic:WordPress · Automattic:WordPress · Automattic:WordPress 2 hari lalu
CVE-2026-18912 CWE-89 7.7

CVE-2026-18912

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

cve.org Zohocorp:ManageEngine · DataSecurity · Plus 2 hari lalu
CVE-2026-18911 CWE-20 7.5

CVE-2026-18911

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

cve.org Zohocorp:ManageEngine · DataSecurity · Plus 2 hari lalu
CVE-2026-17086 CWE-502 8.8

ShortPixel Image Optimizer <= 6.5.5 - Authenticated (Author+) PHP Object Injection via Nested JSON Post Content

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This m…

Wordfence shortpixel:ShortPixel · Image · Optimizer 2 hari lalu
CVE-2026-92991 CWE-79 5.4

Biggopti Library (Various Versions) - Cross-Site Scripting via display_id from Sigmative API

The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This makes it possible for attackers who can comprom…

Wordfence bdthemes:Live · Copy · Paste 2 hari lalu
CVE-2026-14855 CWE-79 6.4

RT Mega Menu <= 1.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via rtmega_update_menu_options AJAX Action

The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. Thi…

Wordfence themewant:RT · Mega · Menu 2 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 20 Sep 2026 16:12
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.