377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 301/31432

CVE-2026-91970 CWE-770 6.5

Vikunja before 2.6.0 Resource Exhaustion via Planka Migration

Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated attackers can submit migration requests…

cve.org go-vikunja:vikunja 15 Sep 2026
CVE-2026-91969 CWE-400 6.5

vikunja before 2.6.0 Resource Exhaustion via CSV Migration

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV fi…

cve.org go-vikunja:vikunja 15 Sep 2026
CVE-2026-91968 CWE-674 6.5

vikunja before 2.6.0 Denial of Service via unbounded filter recursion

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thous…

cve.org go-vikunja:vikunja 15 Sep 2026
CVE-2026-91967 CWE-918 5.0

AVideo through 29.0 Blind SSRF via getHeaderContentTypeFromURL

AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format validation. Authenticated users with canUp…

cve.org WWBN:AVideo 15 Sep 2026
CVE-2026-91966 CWE-918 5.8

AVideo through 29.0 Unauthenticated SSRF via Host Header

AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitI…

cve.org WWBN:AVideo 15 Sep 2026
CVE-2026-91965 CWE-200 7.5

WWBN AVideo through 29.0 Broken Access Control via Live Endpoints

WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details…

cve.org WWBN:AVideo 15 Sep 2026
CVE-2026-91964 CWE-122 8.8

FreeRDP 2.0.0 through 3.30.0 Heap Buffer Overflow via RoutingToken

FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server…

cve.org FreeRDP:FreeRDP · FreeRDP:FreeRDP 15 Sep 2026
CVE-2026-91963 CWE-457 6.5

FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memor…

cve.org FreeRDP:FreeRDP · FreeRDP:FreeRDP 15 Sep 2026
CVE-2026-91962 CWE-131 6.3

FreeRDP before 3.31.0 Integer Overflow via audin Apple backends

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueu…

cve.org FreeRDP:FreeRDP 15 Sep 2026
CVE-2026-91961 CWE-617 6.5

FreeRDP before 3.31.0 Denial of Service via URBDRC

FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend. A malicious RDP server can sen…

cve.org FreeRDP:FreeRDP 15 Sep 2026
CVE-2026-91960 CWE-190 6.5

FreeRDP before 3.31.0 Integer Overflow Double Free

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping…

cve.org FreeRDP:FreeRDP 15 Sep 2026
CVE-2026-91959 CWE-125 6.5

FreeRDP before 3.31.0 Buffer Over-read via RTS Gateway

FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigge…

cve.org FreeRDP:FreeRDP 15 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 30 Sep 2026 07:51
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.