377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 26/31432

CVE-2026-81321 CWE-312 9.8

CareCam CM2507 Cleartext Storage of Sensitive Information

CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerabilit…

cve.org CareCam:HMT.CM2507 · Firmware 1 hari lalu
CVE-2026-93338 CWE-1188 5.3

Grandstream GWN7660ELR < 1.0.27.6 Information Disclosure via SNMP Default Community String

Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unauthenticated remote attackers to obtain sensitive system information by querying the SNMP v2c servic…

cve.org Grandstream · Networks:GWN7660ELR 1 hari lalu
CVE-2026-81505 CWE-639 N/A

Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials

Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.F…

cve.org frain-dev:convoy 1 hari lalu
CVE-2026-73863 CWE-125 N/A

NanoMQ: Heap-Buffer-Overflow in `nmq_subinfo_decode()` During MQTT v5 SUBSCRIBE Parsing

NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/protocol/mqtt/mqtt_parser.c reuses len_of_varint from the outer Properties Length while parsing each SU…

cve.org nanomq:nanomq 1 hari lalu
CVE-2026-85497 CWE-916 9.8

CareCam CM2507 Use of Password Hash With Insufficient Computational Effort

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password data…

cve.org CareCam:HMT.CM2507 · Firmware 1 hari lalu
CVE-2026-61633 CWE-835 2.0

NanoMQ: Infinite Loop in UNSUBSCRIBE Decoder Leading to Remote DoS

NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nng/src/supplemental/mqtt/mqtt_codec.c does not handle a failed read_uint16() while counting topics in a malform…

cve.org nanomq:nanomq 1 hari lalu
CVE-2026-44639 CWE-407 3.7

NanoMQ: O(N²) Denial of Service in MQTT v5 Property Parsing

NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c uses property_append() to walk the entire linked list for each property added by decode_buf_properti…

cve.org nanomq:nanomq 1 hari lalu
CVE-2026-85478 CWE-306 3.5

CareCam CM2507 Missing Authentication for Critical Function

A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication. An attacker with physical access could interrupt …

cve.org CareCam:HMT.CM2507 · Firmware 1 hari lalu
CVE-2026-93533 CWE-78 6.3

spatie Scotty Doctor DoctorCommand.php checkRemoteTools os command injection

A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Docto…

cve.org spatie:Scotty 1 hari lalu
CVE-2026-81305 CWE-829 6.8

CareCam CM2507 Inclusion of Functionality from Untrusted Control Sphere

CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and exec…

cve.org CareCam:HMT.CM2507 · Firmware 1 hari lalu
CVE-2026-61682 CWE-290 9.9

kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X…

cve.org kcp-dev:kcp 1 hari lalu
CVE-2026-54147 CWE-327 6.5

http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Di…

cve.org http4k:http4k 1 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 20 Sep 2026 03:33
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.