377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 306/31432

CVE-2026-63695 CWE-284 9.8

CVE-2026-63695

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft…

cve.org Dell:SmartFabric · OS10 · Software 15 Sep 2026
CVE-2026-55158 CWE-78 9.1

Conflibot: Command injection via crafted pull request branch names under pull_request_target

Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by interpolating the att…

cve.org wktk:conflibot 15 Sep 2026
CVE-2026-91836 CWE-1023 2.8

OpenClaw ClawScan Static Scanner static_scanner.go incomplete comparison with missing factors

A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. This manipulation causes incomplete comparison with …

cve.org OpenClaw:ClawScan 15 Sep 2026
CVE-2026-55617 CWE-613 N/A

Hydro: Insufficient session expiration when recreating sessions

Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a replacement session token without deleting…

cve.org hydro-dev:Hydro 15 Sep 2026
CVE-2026-47780 CWE-20 N/A

free5GC: UDR Improper ueId validation in free5GC EE subscription handlers allows arbitrary identifier persistence

free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HandleQueryeesubscriptions in free5gc/udr internal/sbi/api_datarepository.go validate the ueId path v…

cve.org free5gc:free5gc 15 Sep 2026
CVE-2026-48987 CWE-400 6.5

pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload/core/managers/event_manager.py appends a Client object to the clients list for each unique uuid sub…

cve.org pyload:pyload 15 Sep 2026
CVE-2026-48737 CWE-918 4.9

pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPs

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in src/pyload/core/utils/web/check.py relies on Python's global-address classification without examining IPv…

cve.org pyload:pyload 15 Sep 2026
CVE-2026-53966 CWE-862 N/A

XWiki Platform: Privilege escalation from edit to script right through Live Data editing

XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Data edit REST API allows a user who can edit a page to change that page's rights without executing th…

cve.org xwiki:xwiki-platform 15 Sep 2026
CVE-2026-55650 CWE-79 4.4

Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure

Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget conten…

cve.org outerbase:studio 15 Sep 2026
CVE-2026-53957 CWE-918 7.7

Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint

Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/…

cve.org contentful:contentful-mcp-server · @contentful:mcp-server · @contentful:mcp-tools 15 Sep 2026
CVE-2026-54254 CWE-20 N/A

Cyberdrop-DL: Pixeldrain API key shared with unverified thirdparty sites

Cyberdrop-DL is a bulk asynchronous downloader for multiple file hosts. From 8.5.0 until 9.14.0, the Pixeldrain crawler uses substring host matching instead of requiring the input host to be an exact member of SUPPORTED_…

cve.org Cyberdrop-DL:cyberdrop-dl 15 Sep 2026
CVE-2026-49446 CWE-285 6.1

Cosmos: Authentication bypass via forward-auth header smuggling on Constellation tunnel in Cosmos-Server

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the…

cve.org azukaar:Cosmos-Server 15 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 30 Sep 2026 10:01
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.