377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 363/31432

CVE-2026-57583 CWE-94 3.3

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source

OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Prior to @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/w…

cve.org OpenZeppelin:contracts-wizard · @openzeppelin:wizard · @openzeppelin:wizard-cairo 14 Sep 2026
CVE-2026-54723 CWE-304 6.5

devpi: Database contents leak

devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary or deprecated master role allows an unauthenticated, modified GET…

cve.org devpi:devpi 14 Sep 2026
CVE-2026-57578 CWE-862 N/A

DotVVM: Missing authorization in AuthorizeActionFilter

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, AuthorizeActionFilter performs no authorization because its explicit ICommandActionFilter.OnCommandExecuti…

cve.org riganti:dotvvm 14 Sep 2026
CVE-2026-57577 CWE-1333 N/A

DotVVM: ReDOS in routing

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a route containing multiple unconstrained parameters in one path segment can cause excessive regular-expre…

cve.org riganti:dotvvm 14 Sep 2026
CVE-2026-57581 CWE-434 5.3

DotVVM: Unrestricted file upload

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users to submit files directly to D…

cve.org riganti:dotvvm 14 Sep 2026
CVE-2026-73494 CWE-444 7.4

blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Java parser under http/…

cve.org http4s:blaze · org.http4s:blaze-http_2.13 · org.http4s:blaze-http_3 14 Sep 2026
CVE-2026-53752 CWE-674 7.5

docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service

docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and adjacent helpers recursively follow the Wordprocessin…

cve.org plutext:docx4j · org.docx4j:docx4j-core 14 Sep 2026
CVE-2026-90806 CWE-862 6.3

DjangoCRM django-crm Bulk Case Update bulk_views.py BulkUpdateCasesView authorization

A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update. The manipulation le…

cve.org DjangoCRM:django-crm 14 Sep 2026
CVE-2026-53659 CWE-409 7.5

http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZip, RequestFilters.GunZip, and the underlying Gzip request-body decompression functions impose no li…

cve.org http4k:http4k 14 Sep 2026
CVE-2026-85892 CWE-362 7.8

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

cve.org Microsoft:Microsoft · Edge · (Chromium-based) 14 Sep 2026
CVE-2026-47256 CWE-22 5.3

OpenTelemetry: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer token

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the …

cve.org open-telemetry:opentelemetry-collector-contrib · open-telemetry:github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter 14 Sep 2026
CVE-2026-55091 CWE-915 7.5

flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key

flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested.prototype.convert in index.js uses attacker-influenced id and parent record fields directly as keys …

cve.org joaonuno:flat-to-nested-js 14 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 01 Oct 2026 03:07
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.