377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 298/31432

CVE-2026-55776 CWE-617 6.5

OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while …

cve.org openbao:openbao 15 Sep 2026
CVE-2026-55774 CWE-863 N/A

OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign l…

cve.org openbao:openbao 15 Sep 2026
CVE-2026-55775 CWE-285 N/A

OpenBao's System Backend allows Unauthorized Management of the containing Namespace

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities on /sys/namespaces/root within a non-root namespace could exploit special handling of the literal roo…

cve.org openbao:openbao 15 Sep 2026
CVE-2026-44163 CWE-409 5.3

fluent-plugin-opentelemetry: Denial of Service (DoS) via Large Payloads and Decompression Bombs in `in_opentelemetry`

fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.5.3, the in_opentelemetry HTTP input read the entire incoming request body and decompressed payloads…

cve.org fluent-plugins-nursery:fluent-plugin-opentelemetry 15 Sep 2026
CVE-2026-77866 CWE-918 N/A

SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts

Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured to block. Only IPv4 addresses are matched…

cve.org Slab:safeurl · Slab:safeurl 15 Sep 2026
CVE-2026-55591 CWE-918 5.8

Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints

Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, port, useTLS, and selfsignedcert parameters fro…

cve.org SignalK:signalk-server 15 Sep 2026
CVE-2026-77972 CWE-367 N/A

safeurl validated address is not bound to the request, allowing DNS rebinding

Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS responses to reach internal network destinations that validation rejected. Validation returns a verdict …

cve.org Slab:safeurl · Slab:safeurl 15 Sep 2026
CVE-2026-55864 CWE-918 N/A

GeoNetwork: Unauthenticaded Server-Side Request Forgery in SLD Tool

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/tools/ogc/sld accepted a caller-supplied WMS server URL and performed a server-side HTTP GET without des…

cve.org geonetwork:core-geonetwork 15 Sep 2026
CVE-2026-55630 CWE-79 0.0

Kiwi TCMS: Stored XSS via javascript: URI in extra_link field (TestPlan & TestCase)

Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site s…

cve.org kiwitcms:Kiwi 15 Sep 2026
CVE-2026-54724 CWE-601 6.1

Kiwi TCMS: Open Redirect via unvalidated next parameter in account confirmation endpoint

Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hos…

cve.org kiwitcms:Kiwi 15 Sep 2026
CVE-2026-91849 CWE-434 6.3

WuzhiCMS Avatar Upload index.php setAvatar unrestricted upload

A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument…

cve.org n/a:WuzhiCMS 15 Sep 2026
CVE-2026-55211 CWE-125 9.8

surfio IRAP header size fields cause out-of-bounds reads

Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes…

cve.org equinor:surfio 15 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 30 Sep 2026 06:55
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.