377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 361/31432

CVE-2026-89021 CWE-59 6.9

MikroTik RouterOS Path Traversal via Container OCI/tar Image Extraction

MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container i…

cve.org MikroTik:RouterOS 14 Sep 2026
CVE-2026-89020 CWE-121 4.3

MikroTik RouterOS Stack Buffer Overflow via TFTP URL Path

MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget work…

cve.org MikroTik:RouterOS 14 Sep 2026
CVE-2026-77884 CWE-552 N/A

Gallery - Private Photo Vault 1.0.41 - Unauthenticated local-network HTTP file exposure

Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external stora…

cve.org Brain · Trust:Gallery · - 14 Sep 2026
CVE-2026-86830 CWE-266 7.2

Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center

Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, appr…

cve.org AWS:iam-identity-center-team 14 Sep 2026
CVE-2026-90808 CWE-184 6.3

HKUDS nanobot ExecTool shell.py ExecTool._spawn incomplete blacklist

A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes i…

cve.org HKUDS:nanobot 14 Sep 2026
CVE-2026-55832 CWE-22 6.1

Tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled external_data location from an ONNX model thro…

cve.org sonos:tract 14 Sep 2026
CVE-2026-54181 CWE-79 5.4

backpack/crud: Stored XSS in the color column — the `@if($column['escaped'])` branches are inverted

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, src/resources/v…

cve.org Laravel-Backpack:CRUD 14 Sep 2026
CVE-2026-54177 CWE-434 6.6

backpack/crud: HasUploadFields keeps the attacker-supplied file extension — public-disk uploads of `shell.php` reach the webserver

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, HasUploadFields…

cve.org Laravel-Backpack:CRUD 14 Sep 2026
CVE-2026-54176 CWE-287 6.5

backpack/crud: MyAccountController allows changing the login email without a current-password check

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, MyAccountContro…

cve.org Laravel-Backpack:CRUD 14 Sep 2026
CVE-2026-54180 CWE-639 7.6

backpack/crud: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, the Update, Del…

cve.org Laravel-Backpack:CRUD 14 Sep 2026
CVE-2026-91081 CWE-918 5.8

Docs through 5.6.1 SSRF via Unauthenticated cors-proxy Endpoint

Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS …

cve.org suitenumerique:docs 14 Sep 2026
CVE-2026-91080 CWE-770 7.5

webhook through 2.8.3 Memory Exhaustion via Oversized Request Body

webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request…

cve.org adnanh:webhook 14 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 01 Oct 2026 02:28
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.