377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 34/31432

CVE-2026-16514 CWE-125 4.3

Out-of-bounds read in gPTP Announce path-trace validation via unvalidated stepsRemoved

gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one. The loop bound was taken sole…

cve.org zephyrproject:zephyr 1 hari lalu
CVE-2026-16512 CWE-125 3.1

Out-of-bounds read in the Zephyr gPTP receive path when handling short Ethernet frames

gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type without first checking that the received frame carries at least sizeof(struct …

cve.org zephyrproject:zephyr 1 hari lalu
CVE-2024-56344 CWE-327 5.9

IBM Cognos Analytics 12.0.4 and 12.1.3 versions are affected by security vulnerabilities

IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An att…

cve.org IBM:Cognos · Analytics 1 hari lalu
CVE-2026-85511 CWE-290 4.2

Wildfly-elytron-realm-token: parameter injection in eap's elytron oauth2

A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.

cve.org Red · Hat:Red · Hat 1 hari lalu
CVE-2026-93569 CWE-444 8.2

Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 :authority, overriding the request-target authority

A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflict…

cve.org Red · Hat:Red · Hat 1 hari lalu
CVE-2026-77929 CWE-434 8.8

ClipBucket < 5.5.3-#182 Remote Code Execution via Photo Upload Endpoint

ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint…

cve.org MacWarrior:clipbucket-v5 1 hari lalu
CVE-2026-93567 CWE-20 7.5

Io.netty/netty-codec-http2: http/1 authority-form connect is translated to malformed http/2 connect with host-controlled :authority

A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. A…

cve.org Red · Hat:Red · Hat 1 hari lalu
CVE-2026-93660 CWE-639 6.5

SQLBot through 1.10.1 Improper Access Control via Dashboard Update

SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary…

cve.org dataease:SQLBot 1 hari lalu
CVE-2026-93659 CWE-79 8.7

Concrete CMS Community Store before 2.7.8 Stored XSS

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fie…

cve.org concretecms-community-store:community_store 1 hari lalu
CVE-2026-93658 CWE-281 7.0

uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid

uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when …

cve.org uutils:coreutils 1 hari lalu
CVE-2026-93657 CWE-347 7.5

hickory-resolver before 0.26.2 DNSSEC Validation Bypass

hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers …

cve.org hickory-dns:hickory-resolver 1 hari lalu
CVE-2026-77928 CWE-89 6.5

ClipBucket < 5.5.3-#182 Blind SQL Injection via Private Message Deletion Endpoint

ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as an array to bypass the clean_reque…

cve.org MacWarrior:clipbucket-v5 1 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 20 Sep 2026 07:05
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.