377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 54/31432

CVE-2026-54734 CWE-918 10.0

Prebid Server Java: Vulnerability to request forgery allows for possible host environment data extraction

Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or…

cve.org prebid:prebid-server-java 3 hari lalu
CVE-2026-54519 CWE-862 8.8

AI Agent Automation: Missing ownership checks in memory APIs allow cross-user memory read and deletion

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authenticates requests but listMemories, dele…

cve.org vmDeshpande:ai-agent-automation 3 hari lalu
CVE-2026-86688 CWE-384 N/A

Session id is not renewed on authentication in ash_authentication, allowing session fixation

Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs in. AshAuthentication…

cve.org team-alembic:ash_authentication · team-alembic:ash_authentication 3 hari lalu
CVE-2026-76949 CWE-290 N/A

Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement

Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for t…

cve.org team-alembic:ash_authentication · team-alembic:ash_authentication 3 hari lalu
CVE-2026-54520 CWE-22 8.1

AI Agent Automation: Workflow file step path traversal allows read and write outside the expected directory

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user…

cve.org vmDeshpande:ai-agent-automation 3 hari lalu
CVE-2026-54767 CWE-306 9.1

WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded c…

cve.org LabRedesCefetRJ:WeGIA 3 hari lalu
CVE-2026-54671 CWE-639 8.8

WeGIA: Authorization Bypass via Empty Resource Array in InternoControle

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty…

cve.org LabRedesCefetRJ:WeGIA 3 hari lalu
CVE-2026-54670 CWE-22 9.1

WeGIA: Unauthenticated Auth Bypass + Local File Inclusion

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a c…

cve.org LabRedesCefetRJ:WeGIA 3 hari lalu
CVE-2026-54634 CWE-787 7.3

Hamlib: rigctld `send_raw` Stack Out-of-Bounds Write and Uninitialized Memory Disclosure

Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld send_raw command on TCP port 4532 reaches rigctl_send_raw() in tests/rigctl_parse.c, which writes a …

cve.org Hamlib:Hamlib 3 hari lalu
CVE-2026-54608 CWE-345 N/A

MythicalDash: Unauthenticated payment bypass in Stripe success-redirect endpoint allows arbitrary free credit top-up

MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/System/Gateways/Stripe.php creates a pending row in mythicaldash_stripe_payments before Stripe checkout s…

cve.org MythicalLTD:MythicalDash 3 hari lalu
CVE-2026-54506 CWE-79 7.6

Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] field and passes stored content through sani…

cve.org givanz:Vvveb 3 hari lalu
CVE-2026-54612 CWE-22 8.8

Vvveb: Authenticated editor path traversal to PHP file write/RCE via data-v-save-global

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until 1.0.8.5, saveGlobalElements() in admin/controller/editor/global-trait.php concatenates the attacker…

cve.org givanz:Vvveb 3 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 21 Sep 2026 17:12
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.