377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 292/31432

CVE-2026-53459 CWE-636 N/A

Bambuddy's authentication fails open on database errors, allowing unauthenticated access to all endpoints

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open in the authentication code allows any attacker to bypass authen…

cve.org maziggy:bambuddy 15 Sep 2026
CVE-2026-45579 CWE-95 9.9

DIRAC: RCE in RequestManager due to eval on untrusted input

DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the RequestManagementSystem/Service/ReqManagerHandler.py export_getRequestCountersWeb function …

cve.org DIRACGrid:DIRAC 15 Sep 2026
CVE-2026-11926 CWE-400 N/A

Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

cve.org IBM:Verify · Identity · Access 15 Sep 2026
CVE-2026-11927 CWE-74 N/A

Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access

IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.

cve.org IBM:Verify · Identity · Access 15 Sep 2026
CVE-2026-53954 CWE-400 4.3

Bugsink: DOS using large numbers of event tags

Bugsink is a self-hosted error tracking tool. Prior to version 2.2.2, Bugsink stores every set of custom tags supplied with an incoming event, allowing a caller with a valid project DSN to submit an unusually large tag s…

cve.org bugsink:bugsink 15 Sep 2026
CVE-2026-11928 CWE-787 N/A

Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access

IBM Verify Identity Access is vulnerable to a buffer overflow attack.

cve.org IBM:Verify · Identity · Access 15 Sep 2026
CVE-2026-48785 CWE-22 4.8

Apptainer: Incorrect path matching for 'limit container paths' directive

Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix matching to the limit container paths directive in apptainer.conf, so an allowed path such as /data…

cve.org apptainer:apptainer 15 Sep 2026
CVE-2026-11929 CWE-? N/A

Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access

IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.

cve.org IBM:Verify · Identity · Access 15 Sep 2026
CVE-2026-54549 CWE-918 8.3

Meta Ads MCP: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, the upload_ad_image tool in meta_ads_mcp/core/ads.py passes an attacker-controlled image_url to try_mu…

cve.org pipeboard-co:meta-ads-mcp 15 Sep 2026
CVE-2026-54547 CWE-287 7.4

Meta Ads MCP: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, AuthInjectionMiddleware in meta_ads_mcp/core/http_auth_integration.py rejects HTTP MCP requests only w…

cve.org pipeboard-co:meta-ads-mcp 15 Sep 2026
CVE-2026-11934 CWE-285 N/A

Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access

IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.

cve.org IBM:Verify · Identity · Access 15 Sep 2026
CVE-2026-12101 CWE-289 N/A

Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access

IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests.

cve.org IBM:Verify · Identity · Access 15 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 30 Sep 2026 04:54
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.