377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 393/31432

CVE-2023-24035 CWE-208 3.5

CVE-2023-24035

An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing…

MITRE Nagios:Nagios · XI 14 Sep 2026
CVE-2023-24034 CWE-601 3.1

CVE-2023-24034

An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability.

MITRE Nagios:Nagios · XI 14 Sep 2026
CVE-2023-22632 CWE-88 2.7

CVE-2023-22632

PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.

MITRE Paessler:PRTG · Network · Monitor 14 Sep 2026
CVE-2023-22631 CWE-88 2.7

CVE-2023-22631

PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.

MITRE Paessler:PRTG · Network · Monitor 14 Sep 2026
CVE-2026-90606 CWE-120 9.9

Totolink A3002MU boa formIpv6Setup buffer overflow

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument sta…

cve.org Totolink:A3002MU 13 Sep 2026
CVE-2026-90605 CWE-120 9.9

Totolink A3002MU boa formFilter buffer overflow

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6ad…

cve.org Totolink:A3002MU 13 Sep 2026
CVE-2026-90604 CWE-79 3.5

Totolink A3002MU Anchor Tag cross site scripting

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation …

cve.org Totolink:A3002MU 13 Sep 2026
CVE-2026-90603 CWE-434 7.3

Anil-matcha Open-Generative-AI S3 Upload upload-binary unrestricted upload

A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of th…

cve.org Anil-matcha:Open-Generative-AI 13 Sep 2026
CVE-2026-15892 CWE-401 5.3

Heap memory leak in mcumgr settings-management handlers on access-hook rejection leads to denial of service

The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in subsys/mgmt/mcumgr/grp/settings_mgmt/src/settings_mgmt.c allocate a key_name buffer (and, for r…

cve.org zephyrproject:zephyr 13 Sep 2026
CVE-2026-15891 CWE-476 7.5

NULL pointer dereference in Zephyr MQTT-SN client when removing a non-responsive gateway

The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next…

cve.org zephyrproject:zephyr 13 Sep 2026
CVE-2026-90602 CWE-79 3.5

Anil-matcha Open-Generative-AI Studio Components ImageStudio.js renderHistory cross site scripting

A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipu…

cve.org Anil-matcha:Open-Generative-AI 13 Sep 2026
CVE-2026-90601 CWE-287 7.3

getzep graphiti REST API main.py improper authentication

A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The atta…

cve.org getzep:graphiti 13 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 01 Oct 2026 11:57
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.