377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 387/31432

CVE-2026-90685 CWE-617 2.8

GPAC MP4Box lsr_dec.c lsr_exec_command_list assertion

A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Loca…

cve.org n/a:GPAC 14 Sep 2026
CVE-2026-90684 CWE-617 2.8

GPAC MP4Box base_scenegraph.c gf_node_get_field_count assertion

A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to …

cve.org n/a:GPAC 14 Sep 2026
CVE-2026-90683 CWE-617 3.3

GPAC MP4Box base_scenegraph.c gf_node_unregister assertion

A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion.…

cve.org n/a:GPAC 14 Sep 2026
CVE-2026-90682 CWE-122 5.3

Matthias-Wandel jhead WebP EXIF gpsinfo.c ProcessGpsInfo heap-based overflow

A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_…

cve.org Matthias-Wandel:jhead 14 Sep 2026
CVE-2026-90681 CWE-125 3.3

Matthias-Wandel jhead EXIF Parsing exif.c Get16u out-of-bounds

A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local…

cve.org Matthias-Wandel:jhead 14 Sep 2026
CVE-2026-90680 CWE-121 9.9

D-Link DIR-823G HNAP1 SetStaticRouteSettings strcpy stack-based overflow

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAd…

cve.org D-Link:DIR-823G 14 Sep 2026
CVE-2026-90623 CWE-295 3.7

andreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certificate validation

A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the file src/cochise/ssh_connection.py of the component SSH Host Key Handler. Executing a manipulation can …

cve.org andreashappe:cochise 14 Sep 2026
CVE-2026-90622 CWE-476 3.3

GNU libredwg Layer Encoding dwg.spec DWG_TABLE null pointer dereference

A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.spec of the component Layer Encoding. Performing a manipulation results in null pointer dereference. The…

cve.org GNU:libredwg 14 Sep 2026
CVE-2026-90621 CWE-78 6.3

ipa-lab HackingBuddyGPT ssh_run_command.py ssh_run_command os command injection

A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the file src/hackingBuddyGPT/extensions/ssh_run_command.py. Such manipulation leads to os command inject…

cve.org ipa-lab:HackingBuddyGPT 14 Sep 2026
CVE-2026-90620 CWE-306 7.3

0x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authentication

A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component API Command Endpoint. This…

cve.org 0x4m4:HexStrike · AI 14 Sep 2026
CVE-2026-90619 CWE-78 7.3

0x4m4 HexStrike AI Execute Endpoint hexstrike_server.py os command injection

A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknown function of the file hexstrike_server.py of the component Execute Endpoint. The manipulation of …

cve.org 0x4m4:HexStrike · AI 14 Sep 2026
CVE-2026-90618 CWE-78 7.3

GH05TCREW PentestAgent LocalRuntime runtime.py LocalRuntime.execute_command os command injection

A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. E…

cve.org GH05TCREW:PentestAgent 14 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 01 Oct 2026 09:33
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.