377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 20/31432

CVE-2026-93432 CWE-79 6.1

Io.quarkus.qute:quarkus-core: cross-site scripting (xss) and json injection via qute {#eval} section in quarkus

A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content type information. This bypasses standard escaping mechanisms,…

cve.org Red · Hat:Exploit · Intelligence 1 hari lalu
CVE-2026-93753 CWE-1321 7.5

deepmerge through 4.3.1 Prototype Poisoning via mergeObject

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in me…

cve.org TehShrike:deepmerge 1 hari lalu
CVE-2026-93752 CWE-915 7.5

CSSOM through 0.5.0 Denial of Service via length Property

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to rep…

cve.org NV:CSSOM 1 hari lalu
CVE-2026-93751 CWE-176 6.5

uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars

uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads …

cve.org garycourt:uri-js 1 hari lalu
CVE-2026-93750 CWE-436 5.9

http-cache-semantics through 4.2.0 Cross-Client Cache Disclosure via Vary Wildcard

http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can requ…

cve.org kornelski:http-cache-semantics 1 hari lalu
CVE-2026-93749 CWE-1284 7.5

source-map-js through 1.2.1 Event Loop Denial of Service

source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that…

cve.org 7rulnik:source-map-js 1 hari lalu
CVE-2026-93748 CWE-524 7.5

http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other …

cve.org kornelski:http-cache-semantics 1 hari lalu
CVE-2026-81181 CWE-384 3.7

SysReptor: Session Fixation in Password-Protected Shared Notes

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication, allowing…

cve.org Syslifters:sysreptor 1 hari lalu
CVE-2026-81182 CWE-639 4.2

SysReptor: Unauthorized file disclosure by broken access control in writable shared notes

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an uploaded file or image from the same project by up…

cve.org Syslifters:sysreptor 1 hari lalu
CVE-2026-81180 CWE-20 8.8

SysReptor: Authenticated RCE by insecure image processing

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing em…

cve.org Syslifters:sysreptor 1 hari lalu
CVE-2026-81179 CWE-807 8.1

SysReptor: Host header injection might allow account takeover

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header …

cve.org Syslifters:sysreptor 1 hari lalu
CVE-2026-81178 CWE-863 3.5

SysReptor: Anonymous note-share link discloses project member identities and non-shared note activity

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public note share link receives project-wide collaborative editing metadata because the public share consumer…

cve.org Syslifters:sysreptor 1 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 20 Sep 2026 00:36
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.