CVE Notifier
Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.
arsip 377,174 CVE • 12,754 critical • 1,713 KEV
- 1999–2026
- 395.000+ CVE
- cve.org
- NVD CVSS
- CISA KEV
- Auto-update 30m
- SQLite full-text
Feed Kerentanan
Menampilkan 12 dari 377,174 entri — halaman 279/31432
In Concrete CMS 8.5.3 to 9,5,2, OAuth 2.0 Refresh-Token Grant Bypasses Account Status
Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, which issued new access tokens from a valid refresh token without re-checking the associated account'…
Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders t…
Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Dashboard SEO Excluded Words Reset Endpoint
Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The reset() controller action cleared the administrator-configured reserved-word list (concrete.seo.exclude_…
On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers
On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers
Concrete CMS 9.0.0 to 9.5.2 is vunerable to CSRF in Concrete CMS Group Type Deletion Dashboard Action
Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote unauthenticated attacker could cause an authenticated user with …
Http4s: Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages containing both Transfer-Encoding and Content-Length, so an intermediary and Ember can select differe…
On affected platforms running Arista EOS, under certain circumstances plaintext user passwords
On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enable…
On affected platforms running Arista EOS, under certain circumstances plaintext private keys
On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly…
CVE-2026-58773
In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction …
CVE-2026-58767
In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interac…
CVE-2026-58766
In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User …
CVE-2026-58765
In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Statistik
Arsip lengkap kerentanan dari semua sumber — live dari database.
Distribusi Severity
CVSS v3- Critical 12,754 (8%)
- High 61,345 (41%)
- Medium 68,090 (45%)
- Low 8,634 (6%)
Tren CVE per Tahun
1999–2026cve.org
Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.
NVD
Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.
Wordfence
Kerentanan plugin/theme WordPress dari Wordfence Intelligence.
WPScan
Kerentanan ekosistem WordPress dari WPScan (Patchstack).
GitHub
CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).
MITRE
CNA asli yang menerbitkan dan mengelola CVE Record.
Sumber Data
cve.org
Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.
NVD
Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.
CISA KEV
Kerentanan yang aktif dieksploitasi — prioritas tinggi.
WPScan
Kerentanan ekosistem WordPress.
Wordfence
Kerentanan plugin/theme WordPress.
GitHub
Security Advisories ekosistem open source.