377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 319/31432

CVE-2026-19515 CWE-78 7.0

OS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Extension Allows Arbitrary Command Execution

The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources. This allows a crafted project to inject and exe…

cve.org WSO2:WSO2 · Integrator: · MI 15 Sep 2026
CVE-2026-45051 CWE-502 N/A

OpenAM Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators wit…

cve.org OpenIdentityPlatform:OpenAM 15 Sep 2026
CVE-2026-62263 CWE-502 N/A

OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore…

cve.org OpenIdentityPlatform:OpenAM 15 Sep 2026
CVE-2026-46623 CWE-620 N/A

OpenAM Account Takeover via Unverified Password Change in OAuth2 Module

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStat…

cve.org OpenIdentityPlatform:OpenAM 15 Sep 2026
CVE-2026-46619 CWE-90 N/A

OpenAM Authentication Bypass via MSISDN LDAP Injection

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without es…

cve.org OpenIdentityPlatform:OpenAM 15 Sep 2026
CVE-2026-46498 CWE-639 N/A

OpenAM Arbitrary OAuth Token Minting via Push Registration

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and OAuth…

cve.org OpenIdentityPlatform:OpenAM 15 Sep 2026
CVE-2026-45794 CWE-502 N/A

OpenAM Unsafe Java Deserialization via SNS

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by SnsMessageResource falls back to a CTS predicate blob after a messageId expires f…

cve.org OpenIdentityPlatform:OpenAM 15 Sep 2026
CVE-2026-45048 CWE-200 8.5

OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticat…

cve.org OpenIdentityPlatform:OpenAM 15 Sep 2026
CVE-2026-44203 CWE-79 N/A

OpenAM: Pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied parameters before FormPostResponse.ftl…

cve.org OpenIdentityPlatform:OpenAM 15 Sep 2026
CVE-2026-44202 CWE-918 N/A

OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring…

cve.org OpenIdentityPlatform:OpenAM 15 Sep 2026
CVE-2026-62379 CWE-94 9.8

OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java cla…

cve.org OpenIdentityPlatform:OpenAM 15 Sep 2026
CVE-2026-53660 CWE-1004 N/A

OpenAM Insecure SSO Cookie Initialization

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite default…

cve.org OpenIdentityPlatform:OpenAM 15 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 30 Sep 2026 13:52
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.