377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 63/31432

CVE-2026-54571 CWE-190 N/A

ESPAsyncWebServer: Integer overflow in multipart boundary parser causes denial of service

ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3.11.1, the multipart/form-data parser in src/WebRequest.cpp stores _boundaryPosition as an 8-bit val…

cve.org ESP32Async:ESPAsyncWebServer 4 hari lalu
CVE-2026-49292 CWE-862 0.0

Kiwi TCMS: The /init-db/ page renders and responds to requests after first use

Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiw…

cve.org kiwitcms:Kiwi 4 hari lalu
CVE-2026-54239 CWE-345 8.8

FaustWP — Authentication Bypass via Initialization Vector Modification in Token Envelope

Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and excludes the 16-byte initialization vector from the HMAC in WPE\FaustWP\…

cve.org wpengine:faustjs 4 hari lalu
CVE-2026-55061 CWE-88 N/A

uniget: EDITOR Command Injection in uniget CLI

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go parses UNIGET_EDITOR or EDITOR with strings.Split(editor, " ") and passes every space-deli…

cve.org uniget-org:cli 4 hari lalu
CVE-2026-55062 CWE-22 N/A

uniget: Path Traversal in Hook Files - Directory Escape Vulnerability

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing pare…

cve.org uniget-org:cli 4 hari lalu
CVE-2026-52727 CWE-321 7.2

lxc-ci: Pacman keyring stored in archlinux image with a private key

lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-signing private key in /e…

cve.org lxc:lxc-ci 4 hari lalu
CVE-2026-54451 CWE-674 N/A

Elixir protobuf: Unbounded recursion depth in embedded-message decoding

Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a s…

cve.org elixir-protobuf:protobuf 4 hari lalu
CVE-2026-47252 CWE-94 9.0

Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS plugins (Brave, Chrome, Edge, Reminders, Safari)

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because the Chrome plugin an…

cve.org julien040:anyquery · anyquery:github.com/julien040/anyquery/plugins/brave · anyquery:github.com/julien040/anyquery/plugins/chrome 4 hari lalu
CVE-2026-92927 CWE-200 5.3

SourceCodester Drug Recommendation System drug_recommendor.sql information disclosure

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendor.sql. Performing a manipulation results in information disclosure. Th…

cve.org SourceCodester:Drug · Recommendation · System 4 hari lalu
CVE-2026-89038 CWE-22 6.2

Verizon Cloud for Android < 26.7.10 Path Traversal via OneTouchUploadActivity

Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging dir…

cve.org Verizon:Verizon · Cloud · for 4 hari lalu
CVE-2026-92926 CWE-89 7.3

code-projects Matrimonial System partner_preference.php writepartnerprefs sql injection

A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to …

cve.org code-projects:Matrimonial · System 4 hari lalu
CVE-2026-52836 CWE-125 N/A

OpenDDS: out-of-bounds `rd_ptr` dereference in `RtpsSampleHeader::init` — triggered by malformed RTPS submessage, remotely exploitable denial of service

OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). Prior to 3.34.0, a network attacker can crash a reachable OpenDDS participant by sending a malformed RTPS…

cve.org OpenDDS:OpenDDS 4 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 21 Sep 2026 20:57
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.