377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 379/31432

CVE-2026-13417 CWE-754 4.3

Boards plugin denial of service via unvalidated block fields.properties

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of `fields.properties` on block creation which allows an authenticated user with editor access to a …

cve.org Mattermost:Mattermost 14 Sep 2026
CVE-2026-86460 CWE-89 N/A

Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence

Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 th…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-9812 CWE-639 6.5

Missing property field ownership validation in Playbooks run property update endpoint

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating its value which allows an authenticated us…

cve.org Mattermost:Mattermost 14 Sep 2026
CVE-2026-20773 CWE-863 N/A

Improper Authorization in PingFederate Administrative Expression Evaluation Endpoint

A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their …

cve.org Ping · Identity:PingFederate 14 Sep 2026
CVE-2026-87779 CWE-532 N/A

Apache Syncope: AES Secret Key disclosure via log output

Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad the provided value with random characters. The…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-8821 CWE-862 7.1

Playbooks run owner channel membership permission bypass

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member t…

cve.org Mattermost:Mattermost 14 Sep 2026
CVE-2026-5132 CWE-409 6.5

Unbounded zlib decompression in Calls SDP WebSocket messages

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpacked SDP messages compressed with zlib, which allows attacker to deny service or crash server via se…

cve.org Mattermost:Mattermost 14 Sep 2026
CVE-2026-15814 CWE-409 6.5

Uploading a crafted image causes excessive memory allocation in the Mattermost Server

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount of memory allocated when decoding uploaded image files which allows an authenticated user to cause ex…

cve.org Mattermost:Mattermost 14 Sep 2026
CVE-2026-87785 CWE-290 N/A

Apache Syncope: JWT subject spoofing

Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's priv…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-90891 CWE-1256 5.5

ASRock|ASRock Polychrome SYNC/RGB software utility - Improper Access Control

ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Improper Access Control vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to write to …

cve.org ASRock:ASRock · Polychrome · SYNC/RGB 14 Sep 2026
CVE-2026-10542 CWE-639 5.0

Playbooks channel action update validation issue

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel action ownership which allows channel managers to update actions in other channels via the channel ac…

cve.org Mattermost:Mattermost 14 Sep 2026
CVE-2026-90890 CWE-822 5.5

ASRock|ASRock Polychrome SYNC/RGB software utility - Untrusted Pointer Dereference

ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to der…

cve.org ASRock:ASRock · Polychrome · SYNC/RGB 14 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 01 Oct 2026 07:17
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.