377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 375/31432

CVE-2026-90784 CWE-401 5.3

Dvidelabs flatcc semantics.c fb_clear_parser memory leak

A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The impacted element is the function fb_clear_parser of the file src/Compiler/semantics.c. The manipulation leads to memory leak. It is possible to initiate…

cve.org Dvidelabs:flatcc 14 Sep 2026
CVE-2026-78299 CWE-22 N/A

CVE-2026-78299

In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to ot…

cve.org Eclipse · Foundation:Eclipse · Embedded 14 Sep 2026
CVE-2026-73470 CWE-269 N/A

Apache Syncope: Delegating users can grant unowned Roles

Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-73579 CWE-863 N/A

Apache Syncope: Non-recursive Any search could skip Realms restrictions

Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important compon…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-75015 CWE-522 N/A

Apache Syncope: Nested secrets leak cleartext into audit records readable

Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowi…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-75030 CWE-862 N/A

Apache Syncope: Incomplete authorization checks for Group members deprovisioning

Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-77051 CWE-89 N/A

Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked qu…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-73668 CWE-863 N/A

Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values

Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, …

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-77147 CWE-94 N/A

Apache Syncope: Groovy Sandbox escape for empty CommandArgs

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy Command class containing untrusted…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-90938 CWE-306 8.6

LangBot through 0.4.17 Unauthenticated Plugin Registration via WebSocket

LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/plugin/ws) whose authentication is gated on plugin_debug_key, which defaults to an empty string and i…

cve.org langbot-app:LangBot 14 Sep 2026
CVE-2026-90937 CWE-93 9.9

froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs conta…

cve.org froxlor:froxlor 14 Sep 2026
CVE-2026-90936 CWE-200 4.3

Froxlor before 2.3.7 Information Disclosure via customer_email.php

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender valu…

cve.org froxlor:froxlor 14 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 01 Oct 2026 06:16
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.