377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 321/31432

CVE-2026-91846 CWE-862 N/A

MISP Collection Element Add Missing Authorization on Referenced Object UUID

Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit explains that collection …

cve.org MISP:MISP 15 Sep 2026
CVE-2026-91780 CWE-476 3.3

GNU Binutils elflink.c elf_link_add_object_symbols null pointer dereference

A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be …

cve.org GNU:Binutils 15 Sep 2026
CVE-2026-75092 CWE-250 7.3

Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld --validate-config as root and can load mysql-writable plugins

A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2…

cve.org Red · Hat:Red · Hat 15 Sep 2026
CVE-2026-91779 CWE-476 3.3

GNU Binutils Eh Frame elf-eh-frame.c _bfd_elf_eh_frame_section_offset null pointer dereference

A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in …

cve.org GNU:Binutils 15 Sep 2026
CVE-2026-91825 CWE-862 N/A

MISP: Missing Authorization Check for Event Sharing Group When Distribution Field Is Omitted During Edit

Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could use a sharing_group_id only when the request explicitly su…

cve.org MISP:MISP 15 Sep 2026
CVE-2026-91091 CWE-119 4.3

GPAC Node Insertion base_scenegraph.c gf_node_list_insert_child memory corruption

A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to m…

cve.org n/a:GPAC 15 Sep 2026
CVE-2026-91819 CWE-352 N/A

MISP: HTTP Method Override Bypasses CSRF and Form Validation in BetterSecurityComponent

Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the …

cve.org MISP:MISP 15 Sep 2026
CVE-2026-91090 CWE-121 3.9

GPAC base_scenegraph.c gf_node_activate_ex stack-based overflow

A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer overflow. It is possib…

cve.org n/a:GPAC 15 Sep 2026
CVE-2026-91089 CWE-416 6.3

GPAC base_scenegraph.c gf_node_get_name_and_id use after free

A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after free. It is possible to launch the attack…

cve.org n/a:GPAC 15 Sep 2026
CVE-2026-91778 CWE-863 N/A

CVE-2026-91778

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script …

cve.org Octopus · Deploy:Octopus · Server 15 Sep 2026
CVE-2026-18063 CWE-79 6.4

Job Postings <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'position_button' Parameter

The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escapin…

Wordfence blueglassch:Job · Postings 15 Sep 2026
CVE-2026-91088 CWE-122 4.8

GPAC URL url.c gf_url_concatenate_ex heap-based overflow

A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. The manipulation leads to heap-based buffer overflow. An …

cve.org n/a:GPAC 15 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 30 Sep 2026 14:25
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.