377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 131/31432

CVE-2026-92893 CWE-863 4.3

Rubygem-foreman_ansible: ansible inventory api ignores view_hosts permission filters, exposes hidden parameters

A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not enforce the search filter associated with the caller's view_hos…

cve.org Red · Hat:Red · Hat 6 hari lalu
CVE-2026-92894 CWE-863 4.3

Rubygem-foreman_ansible: unscoped lookupvalue deletion allows cross-model override value destruction

A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying it belongs to an AnsibleVariable the caller is authorized to…

cve.org Red · Hat:Red · Hat 6 hari lalu
CVE-2026-78427 CWE-807 4.3

Admission Control Bypass via Hardcoded Sidecar Image Exemption

The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the wor…

cve.org go:github.com/neuvector/neuvector 6 hari lalu
CVE-2026-78425 CWE-287 N/A

SAML Audience Confusion Allows Cross-SP Authentication

Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their s…

cve.org go:github.com/neuvector/neuvector 6 hari lalu
CVE-2026-78426 CWE-863 3.7

Logout bypass via alternate JWT spelling

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expir…

cve.org go:neuvector 6 hari lalu
CVE-2026-78428 CWE-? 8.0

Flaw in Nuevector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

cve.org go:neuvector 6 hari lalu
CVE-2026-50610 CWE-284 N/A

Improper Access control Vulnerability in NitroSense and PredatorSense Software

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service. An authenticated local user may be able …

cve.org Acer:System · Monitoring 6 hari lalu
CVE-2026-50609 CWE-284 N/A

Unauthorized Registry Modification Vulnerability in NitroSense and PredatorSense Software

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. Insufficient access controls within a privileged Named Pipe service may allow an authenticated local…

cve.org Acer:System · Monitoring 6 hari lalu
CVE-2026-15688 CWE-303 N/A

Password Authentication Bypass Vulnerability in GX Works3 and Motion Control Setting

Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by e…

cve.org Mitsubishi · Electric · Corporation:GX 6 hari lalu
CVE-2026-50608 CWE-306 N/A

Authentication Vulnerability in NitroSense and PredatorSense Software

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections…

cve.org Acer:System · Monitoring 6 hari lalu
CVE-2026-50607 CWE-668 N/A

WebSocket Exposure Vulnerability in NitroSense and PredatorSense Software

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was configured to listen on all network interfaces, which may expose the service…

cve.org Acer:System · Monitoring 6 hari lalu
CVE-2026-50606 CWE-321 N/A

Hard-coded Encryption Key Vulnerability in Acer System Monitoring for NitroSense and PredatorSense Software

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under…

cve.org Acer:System · Monitoring 6 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 23 Sep 2026 23:10
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.