377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 297/31432

CVE-2026-58200 CWE-347 7.1

@jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Signing

Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, @jhb.software/payload-cloudinary-plugin deployments with clientUploads enabled expose POST /api/cloudinary-generate-sign…

cve.org jhb-software:payload-plugins 15 Sep 2026
CVE-2026-79699 CWE-59 4.4

Podman: buildah: skopeo: containers/storage: malicious tar whiteout header allows replacement of extraction destination directory

A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file whe…

cve.org Red · Hat:Red · Hat 15 Sep 2026
CVE-2026-79705 CWE-22 4.5

Podman: buildah: buildah/copier: directory escape via crafted tar symlinks when used outside buildah by non-root callers

A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outsid…

cve.org Red · Hat:Red · Hat 15 Sep 2026
CVE-2026-91853 CWE-78 7.4

TOTOLINK X5000R Export Ovpn cstecgi.cgi exportOvpn os command injection

A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvpn of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user of the component Export Ovpn Handler.…

cve.org TOTOLINK:X5000R 15 Sep 2026
CVE-2026-89022 CWE-290 7.4

BookStack < 26.05.5 Authentication Bypass via Social Login Provider Confusion

BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social…

cve.org bookstackapp:bookstack 15 Sep 2026
CVE-2026-19780 CWE-95 8.8

Koha Eval Code Injection Remote Code Execution Vulnerability

Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerabili…

cve.org Koha:Koha 15 Sep 2026
CVE-2026-59965 CWE-863 7.1

@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission

Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default gua…

cve.org jhb-software:payload-plugins · @jhb.software:payload-alt-text-plugin 15 Sep 2026
CVE-2026-58196 CWE-918 4.7

ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.31.0, remote.Handler.Authenticate in pkg/auth/remote/handler.go invokes discovery.DetectAuthent…

cve.org stacklok:toolhive 15 Sep 2026
CVE-2026-54450 CWE-918 N/A

ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.29.1, networking.IsPrivateIP in pkg/networking/utilities.go omits the IPv6 NAT64 prefixes 64:ff…

cve.org stacklok:toolhive 15 Sep 2026
CVE-2026-59157 CWE-290 6.5

webhookd: Unrestricted HTTP Header to Shell Variable Injection

webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded all incoming HTTP headers …

cve.org ncarlier:webhookd 15 Sep 2026
CVE-2026-55887 CWE-88 N/A

MCP Gateway: Argument injection via OCI image label YAML in Docker MCP Gateway

MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad ca…

cve.org docker:mcp-gateway 15 Sep 2026
CVE-2026-55770 CWE-90 6.8

OpenBao: LDAPi ldaputil (wrong escape func)

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required …

cve.org openbao:openbao 15 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 30 Sep 2026 06:18
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.