377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 362/31432

CVE-2026-91079 CWE-918 8.5

Huly Platform through 0.7.426 SSRF via Print Service

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print…

cve.org hcengineering:platform 14 Sep 2026
CVE-2026-90946 CWE-73 7.5

DeepWiki-Open through commit d92819a Arbitrary File Read via /ws/chat WebSocket

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply a…

cve.org AsyncFuncAI:deepwiki-open 14 Sep 2026
CVE-2026-90945 CWE-321 9.8

Crawlab through 0.6.3 Authentication Bypass via Hard-coded JWT Secret

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to acc…

cve.org crawlab-team:crawlab 14 Sep 2026
CVE-2026-90944 CWE-306 8.2

Krayin CRM through 2.2.6 Unauthenticated Email Injection via inbound-parse

Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822…

cve.org krayin:laravel-crm 14 Sep 2026
CVE-2026-90942 CWE-863 9.6

Casdoor through 4.4.0 Private Key Exposure via Certificate Endpoints

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the ex…

cve.org casdoor:casdoor 14 Sep 2026
CVE-2026-57570 CWE-862 6.5

backpack/crud: HasMany/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelation

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.15 and 7.0.47, HasMany and Mor…

cve.org Laravel-Backpack:CRUD 14 Sep 2026
CVE-2026-54178 CWE-22 8.1

backpack/crud: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisk

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.12 and 7.0.35, HasUploadFields::upload…

cve.org Laravel-Backpack:CRUD 14 Sep 2026
CVE-2026-54182 CWE-20 8.1

backpack/crud: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpac…

cve.org Laravel-Backpack:CRUD 14 Sep 2026
CVE-2026-54175 CWE-620 7.6

backpack/crud: Unverified password change in MyAccountController via mass assignment

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.11 and 7.0.34, MyAccountController::po…

cve.org Laravel-Backpack:CRUD 14 Sep 2026
CVE-2026-44162 CWE-409 2.7

fluent-plugin-s3: Denial of Service (DoS) via Decompression Bomb in `in_s3`

fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads the entire decompressed payload of gzip, lzma2, and lzop objects into memory without enforcing a dec…

cve.org fluent:fluent-plugin-s3 14 Sep 2026
CVE-2026-90807 CWE-59 6.3

nanocoai NanoClaw Attachment agent-route.ts forwardAttachedFiles link following

A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. The manipulatio…

cve.org nanocoai:NanoClaw 14 Sep 2026
CVE-2026-86836 CWE-379 N/A

CVE-2026-86836

In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime config…

cve.org Eclipse · Foundation:Eclipse · Ankaios 14 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 01 Oct 2026 02:30
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.