377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 380/31432

CVE-2026-14344 CWE-862 4.3

Inconsistent authorization checks in Mattermost Boards endpoints

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create boards via the board d…

cve.org Mattermost:Mattermost 14 Sep 2026
CVE-2026-12882 CWE-407 4.3

Mattermost Markdown autolink parsing denial of service

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to parse Markdown autolinks with unmatched trailing closing parentheses in linear time, which allows an authenticated use…

cve.org Mattermost:Mattermost 14 Sep 2026
CVE-2026-90706 CWE-78 6.6

D-Link DWR-M921 formWsc os command injection

A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc. The manipulation of the argument targetAPSsid leads to os command injection. The attack is possible…

cve.org D-Link:DWR-M921 14 Sep 2026
CVE-2026-11993 CWE-770 4.3

Fix authenticated members disabling file content indexing server-wide via extraction pool exhaustion

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with perm…

cve.org Mattermost:Mattermost 14 Sep 2026
CVE-2026-89180 CWE-89 7.5

Thinking Software Technology|EFence - SQL Injection

EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

cve.org Thinking · Software · Technology:EFence 14 Sep 2026
CVE-2026-14259 CWE-862 4.3

Board archive import bypasses team board creation permissions

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to…

cve.org Mattermost:Mattermost 14 Sep 2026
CVE-2026-87802 CWE-347 N/A

Apache Syncope: SRA OAuth2 JWT signature verification bypass

Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identi…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-90898 CWE-306 9.8

Bifrost unauthenticated remote code execution via MCP stdio client registration

Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is gov…

cve.org maximhq:Bifrost 14 Sep 2026
CVE-2026-90705 CWE-78 6.6

D-Link DWR-M921 Boa Dispatch Table formsysCmd os command injection

A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead …

cve.org D-Link:DWR-M921 14 Sep 2026
CVE-2026-68570 CWE-863 N/A

Apache Doris: Authorization bypass leading to unauthorized data access

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information. This …

cve.org Apache · Software · Foundation:Apache 14 Sep 2026
CVE-2026-90704 CWE-77 6.6

D-Link DWR-M921 formDiskPartition system command injection

A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. R…

cve.org D-Link:DWR-M921 14 Sep 2026
CVE-2026-72524 CWE-863 N/A

Apache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitrary tables

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to. This issue affects Apache Doris: from 3.1.0 through 3…

cve.org Apache · Software · Foundation:Apache 14 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 01 Oct 2026 07:18
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.