377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 372/31432

CVE-2026-90789 CWE-89 7.3

itsourcecode Leave Management System login.php sql injection

A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Executing a manipulation of the argument user_email can lead to sql…

cve.org itsourcecode:Leave · Management · System 14 Sep 2026
CVE-2026-82431 CWE-863 N/A

Apache Storm Client: Authorization Bypass When nimbus.groups Is Configured Without nimbus.users

Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered. An operator who restricted cluster access by group alone, l…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-82433 CWE-522 N/A

Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Daemon Configuration via Nimbus and the UI

Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes `storm.zookeeper.au…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-82432 CWE-863 N/A

Apache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configuration Overrides

Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance operation accepts configuration overrides and stripped a small set of keys from them, but never re…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-82019 CWE-79 4.2

TripleLift video-bundle.js DOM-based XSS via postMessage

TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a publisher's domain by sending crafted …

cve.org TripleLift:video-bundle.js 14 Sep 2026
CVE-2026-82434 CWE-522 N/A

Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs

Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration v…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-12985 CWE-601 6.8

Mattermost DCR redirect URI allowlist bypass via improper URL component validation

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead…

cve.org Mattermost:Mattermost 14 Sep 2026
CVE-2026-15600 CWE-89 N/A

SQL Injection in Alior Bank raty PrestaShop module

Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotionAction method. The module inserts value of the POST parameter "status" into SQL UPDATE queries with…

cve.org Alior · Bank:raty 14 Sep 2026
CVE-2026-7848 CWE-89 N/A

SQL Injection in Alior Bank raty PrestaShop module

Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the "hookActionObjectProductUpdateBefore", "hookActionObjectCategoryUpdateBefore", and "hookActionObjectCategoryAddAfter" hook…

cve.org Alior · Bank:raty 14 Sep 2026
CVE-2026-82435 CWE-789 N/A

Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decoder

Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffers sized from a lengt…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-82437 CWE-862 N/A

Apache Storm Logviewer: Log Access Controls Not Enforced by Logviewer

Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For daemon logs those settings were not applied: the access decision combined the "this is a daemon log"…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-82426 CWE-22 N/A

Apache Storm Nimbus: Arbitrary File Read on Nimbus via Unvalidated Uploaded Jar Location

Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and opened it directly, without checking that it referred to a file the caller had actu…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 01 Oct 2026 05:21
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.