CVE Notifier
Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.
arsip 377,174 CVE • 12,754 critical • 1,713 KEV
- 1999–2026
- 395.000+ CVE
- cve.org
- NVD CVSS
- CISA KEV
- Auto-update 30m
- SQLite full-text
Feed Kerentanan
Menampilkan 12 dari 377,174 entri — halaman 308/31432
Payara Server is vulnerable to brute-force login attacks due to the absence of a limit on failed login attempts
By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For…
MotoPress Hotel Booking <= 6.2.4 - Unauthenticated Stored Cross-Site Scripting via Stripe Webhook Event Object 'id'
The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, and including, 6.2.4 due to insufficient input sanitization an…
OpenBMC IPMI Authentication Bypass via Default userKey and Stale Challenge Value
OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defa…
OpenBMC IPMI Privilege Escalation via Retargeted RAKP 1
OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity…
Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the sha…
Bridge - Creative Multipurpose WordPress Theme <= 30.8.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute
The Bridge - Creative Multipurpose WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute in all versions up to, and including, 30.8.9.1 due to insufficient…
Consulting - Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation via AJAX
The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This is due to a combination of two flaws: (1) the masterstudy_ms_stm_set_discard_transient AJAX endpoint…
Mitigation bypass in the Widget: Win32 component
Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Denial-of-service in the Security component
Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Denial-of-service in the SVG component
Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Incorrect boundary conditions in the Networking component
Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Mitigation bypass in the Networking component
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Statistik
Arsip lengkap kerentanan dari semua sumber — live dari database.
Distribusi Severity
CVSS v3- Critical 12,754 (8%)
- High 61,345 (41%)
- Medium 68,090 (45%)
- Low 8,634 (6%)
Tren CVE per Tahun
1999–2026cve.org
Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.
NVD
Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.
Wordfence
Kerentanan plugin/theme WordPress dari Wordfence Intelligence.
WPScan
Kerentanan ekosistem WordPress dari WPScan (Patchstack).
GitHub
CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).
MITRE
CNA asli yang menerbitkan dan mengelola CVE Record.
Sumber Data
cve.org
Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.
NVD
Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.
CISA KEV
Kerentanan yang aktif dieksploitasi — prioritas tinggi.
WPScan
Kerentanan ekosistem WordPress.
Wordfence
Kerentanan plugin/theme WordPress.
GitHub
Security Advisories ekosistem open source.