377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 376/31432

CVE-2026-90935 CWE-285 4.3

Froxlor before 2.3.7 Authorization Bypass via Mysqls.add API

Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases…

cve.org froxlor:froxlor 14 Sep 2026
CVE-2026-90934 CWE-863 4.3

EspoCRM before 10.0.4 Field-level Security Bypass via Attendees

EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses. Attackers can recover hidden atte…

cve.org espocrm:espocrm 14 Sep 2026
CVE-2026-90933 CWE-862 7.1

laradashboard through 1.2.2 Missing Authorization via License API

laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys. Attackers with …

cve.org laradashboard:laradashboard 14 Sep 2026
CVE-2026-90932 CWE-73 7.2

LaraDashboard 0.9.2 through 1.2.2 Path Traversal RCE

LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-sup…

cve.org laradashboard:laradashboard 14 Sep 2026
CVE-2026-90931 CWE-79 5.4

LaraDashboard 0.9.0 through 1.2.2 Stored XSS via SVG Upload

LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags. W…

cve.org laradashboard:laradashboard 14 Sep 2026
CVE-2026-90930 CWE-59 6.8

File Browser through 2.63.23 Path Traversal via Symlink Alias

File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules. Attackers can read and …

cve.org filebrowser:filebrowser 14 Sep 2026
CVE-2026-90929 CWE-863 8.1

File Browser 2.5.0 Directory Deletion via Upload Failure Cleanup

File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go). Unlike the TUS upload handler, the direct-upload handler does…

cve.org filebrowser:filebrowser 14 Sep 2026
CVE-2026-90928 CWE-400 6.5

File Browser through 2.63.23 Memory Exhaustion via subtitle endpoint

File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permissi…

cve.org filebrowser:filebrowser 14 Sep 2026
CVE-2026-90927 CWE-400 6.5

filebrowser through 2.63.23 Denial of Service via unbounded WebSocket message

filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages. Attackers can send oversized W…

cve.org filebrowser:filebrowser 14 Sep 2026
CVE-2024-58383 CWE-732 7.3

Froxlor before 2.2.0 Insecure File Permissions mysql.conf

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL u…

cve.org froxlor:froxlor 14 Sep 2026
CVE-2026-77181 CWE-863 N/A

Apache Syncope: ClientApp update entitlement not effective

Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the related operation, while ClientApp's create entitlement is checked both for create…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-90716 CWE-125 5.5

marcobambini Gravity Number gravity_parser.c parse_number_expression out-of-bounds

A vulnerability was detected in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of the file src/compiler/gravity_parser.c of the component Number Parser. Performing a manipulation resu…

cve.org marcobambini:Gravity 14 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 01 Oct 2026 06:13
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.