377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 373/31432

CVE-2026-82438 CWE-346 N/A

Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Origins

Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-90788 CWE-78 4.7

magicblack MacCMS10 Template .%40template%40default%40html%40label.html os command injection

A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown functionality of the file /admin1.php/admin/template/index/path/.%40template%40default%40html%40labe…

cve.org magicblack:MacCMS10 14 Sep 2026
CVE-2026-82439 CWE-770 N/A

Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPC

Description The DRPC server kept a map from function name to request queue and created an entry the first time a function name was seen. No code path ever removed an entry: request cleanup removed the request from its q…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-82920 CWE-863 5.5

Mattermost ABAC parent policy bypass via policy update endpoint

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a syst…

cve.org Mattermost:Mattermost 14 Sep 2026
CVE-2026-82441 CWE-20 N/A

Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency Keys

Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs. Nimbus performed no validation of th…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-90941 CWE-862 4.3

novel-plus through 5.3.3 Missing Authorization on the Admin Book Download Endpoint

novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters. Attackers c…

cve.org 201206030:novel-plus 14 Sep 2026
CVE-2026-90940 CWE-1392 5.3

novel-plus through 5.3.3 Default Cache Management Password in the Front Portal

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default …

cve.org 201206030:novel-plus 14 Sep 2026
CVE-2026-90939 CWE-862 6.5

novel-plus through 5.3.3 Missing Authorization on the Admin /sys/user/list Endpoint

novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations. Authenticated attackers can retrieve password hashes and personal data in…

cve.org 201206030:novel-plus 14 Sep 2026
CVE-2026-84179 CWE-522 N/A

Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology Page

Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and returned the result without redaction in the topology_conf field of TopologyPageInfo. The Storm UI copie…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-86348 CWE-704 4.3

MS Calendar plugin: unrecovered handler panics from malformed post-action requests could crash the plugin process

Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenticated user to crash the plugin via a post-action request with an unexpected field type.. Mattermost …

cve.org Mattermost:Mattermost 14 Sep 2026
CVE-2026-86349 CWE-407 4.3

Mattermost Server Algorithmic DoS via Unbounded Markdown Block Nesting

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting depth in the server-side Markdown parser which allows an authenticated attacker to cause a denial of…

cve.org Mattermost:Mattermost 14 Sep 2026
CVE-2026-90787 CWE-269 7.3

Soarkey StudentManagement Registration Workflow register.html RegisterServlet.doPost privileges management

A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Regis…

cve.org Soarkey:StudentManagement 14 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 01 Oct 2026 05:47
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.