377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 11/31432

CVE-2026-61722 CWE-190 6.8

FluidSynth: DLS Articulation Chunk Integer Overflow

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates articulation chunks using the unsigned expression cbsize + connblocks * 12 without fir…

cve.org FluidSynth:fluidsynth 23 jam lalu
CVE-2026-61714 CWE-122 7.8

FluidSynth: Heap Buffer Overflow in MIDI Player

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside it…

cve.org FluidSynth:fluidsynth 23 jam lalu
CVE-2026-61721 CWE-122 8.0

FluidSynth: Heap-based buffer overrun for DLS samples

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling f…

cve.org FluidSynth:fluidsynth 23 jam lalu
CVE-2026-58264 CWE-122 9.8

FluidSynth: Heap-based buffer overrun

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before …

cve.org FluidSynth:fluidsynth 23 jam lalu
CVE-2026-76899 CWE-89 5.7

CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page`

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. From 1.7.0 until 1.7.4, POST /account-pool/page allows an authenticated caller with MODULE_SETTING_UPDATE t…

cve.org 1Panel-dev:CordysCRM 23 jam lalu
CVE-2026-76902 CWE-306 5.0

CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/pic/preview/{id}`

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, ShiroFilter configures /attachment/preview/{id} and /pic/preview/{id} as anonymous, and bot…

cve.org 1Panel-dev:CordysCRM 23 jam lalu
CVE-2026-76900 CWE-918 6.8

CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Validation at Runtime

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. In version 1.7.3, ApprovalResourceService.sendWebHook reads WebHookConfig.webHookUrl from stored approval-n…

cve.org 1Panel-dev:CordysCRM 23 jam lalu
CVE-2026-93873 CWE-352 4.3

Cotonti through 1.0.0 Cross-Site Request Forgery in the Contact Plugin

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-submit contact forms from attacker-controlled pages to send forg…

cve.org Cotonti:Cotonti 23 jam lalu
CVE-2026-93872 CWE-502 7.5

Cotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb Parameter

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP o…

cve.org Cotonti:Cotonti 23 jam lalu
CVE-2026-93871 CWE-601 5.4

Cotonti through 1.0.0 Stored Open Redirect via Page redir: Prefix

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts. Attac…

cve.org Cotonti:Cotonti 23 jam lalu
CVE-2026-93870 CWE-352 4.3

Cotonti through 1.0.0 Cross-Site Request Forgery in the Ratings Plugin AJAX Handler

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated users. Attackers can craft malicious pages that auto-submit POST…

cve.org Cotonti:Cotonti 23 jam lalu
CVE-2026-93869 CWE-601 6.1

Cotonti through 1.0.0 Open Redirect via Unanchored cot_url_check() Regex

Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers can bypass the redi…

cve.org Cotonti:Cotonti 23 jam lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 19 Sep 2026 19:54
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.