377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 172/31432

CVE-2026-92457 CWE-862 6.5

yshop-crm through 2.1.3 Missing Authorization via CrmInvoiceController issueInvoice

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call the PUT…

cve.org guchengwuyue:yshop-crm 16 Sep 2026
CVE-2026-92456 CWE-862 7.1

yshop-crm through 2.1.3 Missing Authorization via CRM Customer Rule-Configuration Endpoints

yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocat…

cve.org guchengwuyue:yshop-crm 16 Sep 2026
CVE-2026-92455 CWE-862 4.3

yshop-crm through 2.1.3 Missing Authorization via CRM Customer Messaging Endpoints

yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers. Attackers c…

cve.org guchengwuyue:yshop-crm 16 Sep 2026
CVE-2026-92357 CWE-200 4.3

a2ui-project a2ui Model Processor model-processor.ts information disclosure

A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-processor.ts of the component Model Processor. The manipulation of the argument current[segment] leads to…

cve.org a2ui-project:a2ui 16 Sep 2026
CVE-2026-86107 CWE-787 5.9

Security Advisory 0180

The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors. This vulnerability impacts the VeloCloud VCMP tunnel protocol onl…

cve.org Arista · Networks:VeloCloud · Arista 16 Sep 2026
CVE-2026-90049 CWE-? 9.3

net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() skb_zerocopy() copies frags from @from into @to. On an skb_orphan_frags() failure i…

cve.org Linux:Linux · Linux:Linux 16 Sep 2026
CVE-2026-90048 CWE-? 9.8

fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list()

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() ni_create_attr_list() allocates a fixed buffer of al_aligned(record_size) (== record_s…

cve.org Linux:Linux · Linux:Linux 16 Sep 2026
CVE-2026-90047 CWE-? 7.8

drm/xe: Don't hand out the flat CCS storage as usable VRAM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Don't hand out the flat CCS storage as usable VRAM get_flat_ccs_offset() reads the base of the flat CCS storage from the hardware, scales it b…

cve.org Linux:Linux · Linux:Linux 16 Sep 2026
CVE-2026-90046 CWE-? 7.8

mm/page_alloc: don't spin_trylock() in NMI on UP

In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't spin_trylock() in NMI on UP Patch series "mm/page_alloc: fixes for free_pages_nolock() on RT/UP". Pre-existing bugs found by Sas…

cve.org Linux:Linux · Linux:Linux 16 Sep 2026
CVE-2026-90045 CWE-? 7.8

USB: gadget: ffs: fix mm lifetime handling

In the Linux kernel, the following vulnerability has been resolved: USB: gadget: ffs: fix mm lifetime handling io_data stores a pointer to the submitting task's mm_struct, but does not currently hold a reference to it …

cve.org Linux:Linux · Linux:Linux 16 Sep 2026
CVE-2026-90044 CWE-? 7.8

usb: gadget: f_fs: Fix Use-After-Free in AIO error path

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix Use-After-Free in AIO error path In ffs_epfile_write_iter() and ffs_epfile_read_iter(), when ffs_epfile_io() fails with an erro…

cve.org Linux:Linux · Linux:Linux 16 Sep 2026
CVE-2026-90043 CWE-? 7.8

zram: fix slot lock bit position on big-endian 64-bit

In the Linux kernel, the following vulnerability has been resolved: zram: fix slot lock bit position on big-endian 64-bit The slot lock is a bit operation on the whole __lock word, which flags and ac_time alias as two …

cve.org Linux:Linux · Linux:Linux 16 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 25 Sep 2026 13:51
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.