CVE Notifier
Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.
arsip 377,174 CVE • 12,754 critical • 1,713 KEV
- 1999–2026
- 395.000+ CVE
- cve.org
- NVD CVSS
- CISA KEV
- Auto-update 30m
- SQLite full-text
Feed Kerentanan
Menampilkan 12 dari 377,174 entri — halaman 44/31432
WCFM Marketplace <= 3.8.2 - Unauthenticated SQL Injection via 'wcfmmp_user_location_lat' / 'wcfmmp_user_location_lng' Parameter
The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'wcfmmp_user_location_lng' parameter in all versions up to, and including, 3.8.2 due to i…
WP Inventory Manager <= 2.5.1 - Authenticated (Contributor+) SQL Injection via 'where' Shortcode Attribute
The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient escapin…
VK All in One Expansion Unit <= 9.118.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'vkExUnit_cta_img_position' Post Meta
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_img_position' Post Meta in all versions up to, and including, 9.118.0 due to insufficient input sanitiz…
Io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body is never terminated
A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to a…
Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard config
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Crede…
Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos)
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can se…
QTS
An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system. QTS is not affected. We have already fixed …
QcalAgent
A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the …
Booking Calendar <= 11.8.2 - Reflected Cross-Site Scripting via 'options' Parameter
The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due to insufficient input sanitization and output escapin…
EmbedPress <= 4.6.5 - Reflected Cross-Site Scripting via 'hash' and 'unique' Parameters
The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'unique' parameter in all versions…
GPTranslate <= 2.34.6 - Unauthenticated Sensitive Information Exposure in Public Frontend Inline Script
The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.34.6 via the enq…
Custom Twitter Feeds <= 2.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute
The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute in all versions up to, and including, 2.8.0 due to insuf…
Statistik
Arsip lengkap kerentanan dari semua sumber — live dari database.
Distribusi Severity
CVSS v3- Critical 12,754 (8%)
- High 61,345 (41%)
- Medium 68,090 (45%)
- Low 8,634 (6%)
Tren CVE per Tahun
1999–2026cve.org
Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.
NVD
Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.
Wordfence
Kerentanan plugin/theme WordPress dari Wordfence Intelligence.
WPScan
Kerentanan ekosistem WordPress dari WPScan (Patchstack).
GitHub
CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).
MITRE
CNA asli yang menerbitkan dan mengelola CVE Record.
Sumber Data
cve.org
Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.
NVD
Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.
CISA KEV
Kerentanan yang aktif dieksploitasi — prioritas tinggi.
WPScan
Kerentanan ekosistem WordPress.
Wordfence
Kerentanan plugin/theme WordPress.
GitHub
Security Advisories ekosistem open source.