377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 8/31432

CVE-2026-77820 CWE-79 6.4

WPComplete <= 2.9.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'empty' Shortcode Attribute

The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all versions up to, and including, 2.9.9.0 due to insufficient input sanitization and output escaping. T…

cve.org stellarwp:WPComplete 17 jam lalu
CVE-2026-77875 CWE-922 N/A

Hide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet records in shared external storage

The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an auth…

cve.org QUANTUMTECH · LTD:Hide · Photos 19 jam lalu
CVE-2026-93923 CWE-79 8.8

SiYuan through 3.8.4 Stored XSS via Heading Style Attribute

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints t…

cve.org siyuan-note:siyuan 19 jam lalu
CVE-2026-93922 CWE-79 8.8

SiYuan through 3.8.4 Stored XSS via notebook names

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads i…

cve.org siyuan-note:siyuan 19 jam lalu
CVE-2026-93921 CWE-862 4.3

SiYuan through 3.8.4 Access Control Bypass via Dynamic Icon Endpoint

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted c…

cve.org siyuan-note:siyuan 19 jam lalu
CVE-2026-75885 CWE-918 9.3

Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Reque…

cve.org Red · Hat:Red · Hat 20 jam lalu
CVE-2026-93740 CWE-120 10.0

Totolink A3002MU formWlEncrypt buffer overflow

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is …

cve.org Totolink:A3002MU 21 jam lalu
CVE-2026-93739 CWE-120 9.9

Totolink A3002MU formWlAc buffer overflow

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The …

cve.org Totolink:A3002MU 21 jam lalu
CVE-2026-93738 CWE-120 9.9

Totolink A3002MU formSchedule buffer overflow

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The …

cve.org Totolink:A3002MU 21 jam lalu
CVE-2026-88097 CWE-416 8.1

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

cve.org Microsoft:Microsoft · Edge · (Chromium-based) 22 jam lalu
CVE-2026-61670 CWE-214 6.5

microsandbox: Secret values exposed in world-readable process arguments

microsandbox is an easy, fast, local-first microVM runtime and library. Prior to 0.5.10, sdk/rust/lib/runtime/spawn.rs serializes NetworkConfig secret values into the --network-config argument and passes per-sandbox secr…

cve.org superradcompany:microsandbox 22 jam lalu
CVE-2026-68928 CWE-749 8.6

Acode: Exported TerminalService (bundled terminal plugin) lets any installed app execute arbitrary shell commands as Acode

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding …

cve.org Acode-Foundation:Acode 22 jam lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 19 Sep 2026 18:53
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.