377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 305/31432

CVE-2026-59973 CWE-918 8.5

mcp-from-openapi: Bypass of OpenAPI external $ref SSRF fix in latest FrontMCP and mcp-from-openapi

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter…

cve.org agentfront:frontmcp · agentfront:mcp-from-openapi · @frontmcp:adapters 15 Sep 2026
CVE-2026-87791 CWE-22 N/A

Path traversal vulnerability in WordPress theme design-scuole-wordpress-theme

A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary …

cve.org Developers · Italia:design-scuole-wordpress-theme 15 Sep 2026
CVE-2026-85013 CWE-78 7.3

Environment-modules: command injection in environment-modules bash completion via malicious module names containing shell metacharacters

A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion …

cve.org Red · Hat:Red · Hat 15 Sep 2026
CVE-2026-47215 CWE-22 4.8

Singularity: Incorrect path matching for 'limit container paths' directive

SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14, incorrect path-string matching in the singularity.conf limit container paths directi…

cve.org sylabs:singularity · sylabs:SingularityPRO 15 Sep 2026
CVE-2026-55701 CWE-863 N/A

OpenTelemetry githubreceiver silently ignores configured required_headers authentication

The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders configuration at st…

cve.org open-telemetry:opentelemetry-collector-contrib · open-telemetry:github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver 15 Sep 2026
CVE-2026-50024 CWE-22 5.3

GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via a malicious .git server

GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and joins unvalidated path segments onto t…

cve.org WangYihang:GitHacker 15 Sep 2026
CVE-2026-91842 CWE-502 4.1

OpenBankProject OBP-API Kryo Redis.scala KryoInjection.invert deserialization

A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. Such man…

cve.org OpenBankProject:OBP-API 15 Sep 2026
CVE-2026-55178 CWE-200 7.5

GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.2.3, multiple read and link endpoints authorize only the resource named in the request URL and fail …

cve.org geolens-io:geolens 15 Sep 2026
CVE-2026-61549 CWE-269 N/A

Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend

Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.g…

cve.org woodpecker-ci:woodpecker 15 Sep 2026
CVE-2026-50166 CWE-295 N/A

Kuma: kumactl connects to control plane without verifying TLS certificate when no CA is configured

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plan…

cve.org kumahq:kuma 15 Sep 2026
CVE-2026-63696 CWE-494 9.1

CVE-2026-63696

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, l…

cve.org Dell:SmartFabric · OS10 · Software 15 Sep 2026
CVE-2026-52724 CWE-295 N/A

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane di…

cve.org kumahq:kuma 15 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 30 Sep 2026 09:21
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.