377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 295/31432

CVE-2026-58201 CWE-918 N/A

Lokka: Azure Resource Manager URL path validation issue

Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the…

cve.org merill:lokka 15 Sep 2026
CVE-2026-53710 CWE-94 10.0

MCP Context Forge: RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server

MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py…

cve.org IBM:mcp-context-forge 15 Sep 2026
CVE-2026-81897 CWE-352 N/A

Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via Express form Text control save_control

In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token. By causing an authenticated administrator to submit a forged cross-site re…

cve.org Concrete · CMS:Concrete · CMS 15 Sep 2026
CVE-2026-55863 CWE-862 5.3

motionEye: Missing authentication on ActionHandler allows unauthenticated camera action execution

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, the ActionHandler.post() method in motioneye/handlers/action.…

cve.org motioneye-project:motioneye 15 Sep 2026
CVE-2026-46488 CWE-256 N/A

motionEye: Authentication possible via password hash

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and mey…

cve.org motioneye-project:motioneye 15 Sep 2026
CVE-2026-91855 CWE-404 5.3

Open5GS PFCP Message handler.c denial of service

A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality of the file lib/pfcp/handler.c of the component PFCP Message Handler. Performing a manipulation resul…

cve.org n/a:Open5GS 15 Sep 2026
CVE-2026-81896 CWE-79 N/A

Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissions Report via Unescaped Question Label

Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering them as column headers in the Dashboard Form Submissions report (concrete/single_pages/dashboard/rep…

cve.org Concrete · CMS:Concrete · CMS 15 Sep 2026
CVE-2026-63443 CWE-863 8.3

Coder: Workspace agent API insecure redirect handling allowed cross-agent file read and write

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host fr…

cve.org coder:coder 15 Sep 2026
CVE-2024-58385 CWE-89 9.8

Yonyou U8 CRM SQL Injection via fillbacksettingedit.php

Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporate…

cve.org Yonyou:U8 · CRM 15 Sep 2026
CVE-2023-54398 CWE-502 9.8

Yonyou U8 Cloud Java Deserialization RCE via FileManageServlet

Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by se…

cve.org Yonyou:U8 · Cloud 15 Sep 2026
CVE-2026-18111 CWE-306 N/A

Concrete CMS below 9.5.4 allows privilege escalation because adding users and assigning groups do not require additional identity verification

Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external l…

cve.org Concrete · CMS:Concrete · CMS 15 Sep 2026
CVE-2026-89026 CWE-321 9.8

Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowi…

cve.org Issabel · Foundation:Issabel · Framework 15 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 30 Sep 2026 05:37
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.