377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 377/31432

CVE-2026-90955 CWE-778 N/A

MISP CLI Shell Audit Logs Lose User Identity and CLI Marker After First Lazy Model Load

Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP user ID. However, the …

cve.org MISP:MISP 14 Sep 2026
CVE-2026-77883 CWE-202 N/A

Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist

Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrat…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-90715 CWE-190 7.3

marcobambini Gravity udp json-parser gravity_json.c integer overflow

A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the file src/utils/gravity_json.c of the component udp json-parser. Such manipulation leads to integer o…

cve.org marcobambini:Gravity 14 Sep 2026
CVE-2026-78318 CWE-79 N/A

Apache Syncope: Unauthenticated reflected XSS in Console and Enduser

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. The notification message, as optionally shown by Console's and Enduser's login pages can be instruc…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-78330 CWE-266 N/A

Apache Syncope: Privilege escalation for admin user via JWT authentication

Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after …

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-78336 CWE-201 N/A

Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user

Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned pa…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-90714 CWE-119 6.3

marcobambini Gravity JSON parser gravity_json.c memory corruption

A weakness has been identified in marcobambini Gravity up to 0.9.7. The impacted element is an unknown function of the file src/utils/gravity_json.c of the component JSON parser. This manipulation causes memory corruptio…

cve.org marcobambini:Gravity 14 Sep 2026
CVE-2026-12258 CWE-284 N/A

Inadequate access control in the Hiperdino REST API

Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a regi…

cve.org Hiperdino:REST · API 14 Sep 2026
CVE-2026-90713 CWE-404 3.3

vllm-project vLLM tiktoken vocab File mod.rs new denial of service

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Hand…

cve.org vllm-project:vLLM 14 Sep 2026
CVE-2026-90712 CWE-404 4.3

Gitlawb openclaude xAI OAuth Callback xaiOAuthCallback.ts waitForCallback denial of service

A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file src/services/api/xaiOAuthCallback.ts of the component xAI OAuth Callback Handler. The manipulation o…

cve.org Gitlawb:openclaude 14 Sep 2026
CVE-2026-90919 CWE-502 9.8

LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Server Pickle Deserialization

LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers ca…

cve.org ModelTC:LightLLM 14 Sep 2026
CVE-2026-90710 CWE-918 7.3

taisan tarzan-cms Theme Download Function ThemeService.java openConnection server-side request forgery

A vulnerability was determined in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file com/tarzan/cms/modules/admin/service/biz/ThemeService.java of the component Theme Download Function. E…

cve.org taisan:tarzan-cms 14 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 01 Oct 2026 06:47
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.