377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 49/31432

CVE-2026-15650 CWE-79 6.4

RT Mega Menu <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute

The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute in all versions up to, and including, 1.5.2 due to …

Wordfence themewant:RT · Mega · Menu 3 hari lalu
CVE-2026-93468 CWE-23 7.5

HGiga|OAKlouds - Arbitrary File Read

The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrary system files.

cve.org HGiga:OAKlouds-bulletin_v3-2.0 · HGiga:OAKlouds-bulletin_v3-3.0 3 hari lalu
CVE-2026-93467 CWE-502 9.8

HGiga|OAKlouds - Insecure Deserialization

The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.

cve.org HGiga:OAKlouds-custom_page-2.0 · HGiga:OAKlouds-custom_page-3.0 · HGiga:OAKlouds-custom_page-4.0 3 hari lalu
CVE-2026-93371 CWE-77 8.3

marcopiovanello yt-dlp-web-ui generic.go NewGenericDownload command injection

A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argume…

cve.org marcopiovanello:yt-dlp-web-ui 3 hari lalu
CVE-2026-93331 CWE-125 7.3

GPAC RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt out-of-bounds

A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument siz…

cve.org n/a:GPAC 3 hari lalu
CVE-2026-93314 CWE-190 6.3

Freedesktop Poppler FoFiTrueType.cc mapCodeToGID integer overflow

A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer ov…

cve.org Freedesktop:Poppler 3 hari lalu
CVE-2026-82985 CWE-284 6.5

CVE-2026-82985

The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration. When an album owner s…

cve.org Nextcloud:Server 3 hari lalu
CVE-2026-82982 CWE-840 4.3

CVE-2026-82982

The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it. The ba…

cve.org Nextcloud:Approval 3 hari lalu
CVE-2026-82980 CWE-287 6.3

CVE-2026-82980

Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absolute request URI without verifying that the path segment match…

cve.org Nextcloud:Files · Lock 3 hari lalu
CVE-2026-77170 CWE-284 4.3

CVE-2026-77170

The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.

cve.org Nextcloud:Deck 3 hari lalu
CVE-2026-77169 CWE-284 6.5

CVE-2026-77169

A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace…

cve.org Nextcloud:Team · Folders 3 hari lalu
CVE-2026-77164 CWE-918 6.2

CVE-2026-77164

Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcl…

cve.org Nextcloud:Server 3 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 21 Sep 2026 15:32
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.