377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 323/31432

CVE-2026-91003 CWE-121 9.1

D-Link DI-8300 CGI Service rzgl.asp rzgl_asp stack-based overflow

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer ove…

cve.org D-Link:DI-8300 15 Sep 2026
CVE-2026-17495 CWE-27 5.9

moment vulnerable to Path Traversal via crafted non-string locale name

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-na…

cve.org moment:moment 15 Sep 2026
CVE-2026-81320 CWE-532 5.5

Hawtio-operator: hawtio-operator: tls private key written to operator log at debug level

A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialize…

cve.org Red · Hat:Red · Hat 15 Sep 2026
CVE-2026-81303 CWE-441 6.3

Hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routehostname

A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route sp…

cve.org Red · Hat:Red · Hat 15 Sep 2026
CVE-2026-91002 CWE-306 5.3

stamparm maltrail Blacklist Endpoint httpd.py _blacklist missing authentication

A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist Endpoint. Executing a manipulation can lead to miss…

cve.org stamparm:maltrail 15 Sep 2026
CVE-2026-91001 CWE-121 9.9

D-Link DI-8400 DDNS Configuration ddns.asp ddns_asp stack-based overflow

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/…

cve.org D-Link:DI-8400 15 Sep 2026
CVE-2026-15758 CWE-200 5.3

3D FlipBook <= 1.16.20 - Unauthenticated Sensitive Information Exposure in 'id' Parameter

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter. This …

Wordfence iberezansky:3D · FlipBook · – 15 Sep 2026
CVE-2026-90881 CWE-200 5.3

D-Link DIR-882 CGI Binary dllog.cgi main information disclosure

A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The at…

cve.org D-Link:DIR-882 15 Sep 2026
CVE-2026-90880 CWE-77 7.4

D-Link DSL-3782 Diagnostics Diagnostics.asp system command injection

A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the ar…

cve.org D-Link:DSL-3782 15 Sep 2026
CVE-2026-90879 CWE-89 7.3

zyx0814 FilePress Publish search.php sql injection

A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz/publish/search.php of the component Publish Module. Such manipulation of the argument orderby/order…

cve.org zyx0814:FilePress 15 Sep 2026
CVE-2026-90878 CWE-400 4.3

vllm-project vLLM Jinja Template Rendering completions resource consumption

A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template c…

cve.org vllm-project:vLLM 15 Sep 2026
CVE-2026-90877 CWE-89 7.3

SourceCodester Online Faculty Clearance System update_requirement_status.php sql injection

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /update_requirement_status.php. The manipulation of the argument haydi res…

cve.org SourceCodester:Online · Faculty · Clearance 15 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 30 Sep 2026 15:02
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.