377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 308/31432

CVE-2026-92082 CWE-307 N/A

Payara Server is vulnerable to brute-force login attacks due to the absence of a limit on failed login attempts

By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For…

cve.org Payara:Payara · Server 15 Sep 2026
CVE-2026-90650 CWE-79 7.2

MotoPress Hotel Booking <= 6.2.4 - Unauthenticated Stored Cross-Site Scripting via Stripe Webhook Event Object 'id'

The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, and including, 6.2.4 due to insufficient input sanitization an…

Wordfence jetmonsters:MotoPress · Hotel · Booking 15 Sep 2026
CVE-2026-16141 CWE-798 8.1

OpenBMC IPMI Authentication Bypass via Default userKey and Stale Challenge Value

OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defa…

cve.org OpenBMC:phosphor-net-ipmid 15 Sep 2026
CVE-2026-16140 CWE-863 8.8

OpenBMC IPMI Privilege Escalation via Retargeted RAKP 1

OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity…

cve.org OpenBMC:phosphor-net-ipmid 15 Sep 2026
CVE-2026-77179 CWE-59 N/A

Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the sha…

cve.org Docker:Docker · Sandboxes 15 Sep 2026
CVE-2026-15609 CWE-79 6.4

Bridge - Creative Multipurpose WordPress Theme <= 30.8.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute

The Bridge - Creative Multipurpose WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute in all versions up to, and including, 30.8.9.1 due to insufficient…

Wordfence QODE:Bridge · - · Creative 15 Sep 2026
CVE-2026-14805 CWE-269 8.8

Consulting - Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation via AJAX

The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This is due to a combination of two flaws: (1) the masterstudy_ms_stm_set_discard_transient AJAX endpoint…

Wordfence StylemixThemes:Consulting · - · Business, 15 Sep 2026
CVE-2026-92079 CWE-? N/A

Mitigation bypass in the Widget: Win32 component

Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

cve.org Mozilla:Firefox · Mozilla:Thunderbird 15 Sep 2026
CVE-2026-92078 CWE-? N/A

Denial-of-service in the Security component

Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

cve.org Mozilla:Firefox · Mozilla:Thunderbird 15 Sep 2026
CVE-2026-92077 CWE-? N/A

Denial-of-service in the SVG component

Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

cve.org Mozilla:Firefox · Mozilla:Thunderbird 15 Sep 2026
CVE-2026-92076 CWE-? N/A

Incorrect boundary conditions in the Networking component

Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

cve.org Mozilla:Firefox · Mozilla:Thunderbird 15 Sep 2026
CVE-2026-92075 CWE-? N/A

Mitigation bypass in the Networking component

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

cve.org Mozilla:Firefox · Mozilla:Thunderbird 15 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 30 Sep 2026 10:38
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.