377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 116/31432

CVE-2026-90051 CWE-? 7.8

tcp: reject non zerocopy devmem tx

In the Linux kernel, the following vulnerability has been resolved: tcp: reject non zerocopy devmem tx Devmem tcp tx doesn't work without zero-copy, however it's not currently enforced if NETIF_F_SG isn't present. In t…

cve.org Linux:Linux · Linux:Linux 5 hari lalu
CVE-2026-90050 CWE-? N/A

net/sched: fq: clamp quantum and initial_quantum in change path

In the Linux kernel, the following vulnerability has been resolved: net/sched: fq: clamp quantum and initial_quantum in change path The fq change path accepts TCA_FQ_QUANTUM in [1, INT_MAX] and TCA_FQ_INITIAL_QUANTUM u…

cve.org Linux:Linux · Linux:Linux 5 hari lalu
CVE-2026-92980 CWE-434 7.2

HortusFox-Web < 6.1 Remote Code Execution via Import/Export

HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user by abusing the Import/Export functionalit…

cve.org danielbrendel:hortusfox-web 5 hari lalu
CVE-2026-85720 CWE-319 5.9

AsyncHttpClient: Origin credentials sent to the proxy on the plaintext CONNECT request

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS or…

cve.org AsyncHttpClient:async-http-client 5 hari lalu
CVE-2026-85718 CWE-400 5.9

AsyncHttpClient: Connection permit leak on TLS handshake failure causes per-host denial of service

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections or maxConnectionsPerHost set abo…

cve.org AsyncHttpClient:async-http-client 5 hari lalu
CVE-2026-85721 CWE-400 7.5

AsyncHttpClient: Unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 p…

cve.org AsyncHttpClient:async-http-client 5 hari lalu
CVE-2026-89036 CWE-88 8.8

Appwrite < 2.0.0 Argument Injection via providerRootDirectory Parameter

Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write or sites.write permissions to execute arbitrary commands by injecting TAB characters into the provid…

cve.org appwrite:appwrite 5 hari lalu
CVE-2026-85717 CWE-200 6.8

AsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect target

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide…

cve.org AsyncHttpClient:async-http-client 5 hari lalu
CVE-2026-85719 CWE-319 7.5

AsyncHttpClient: SOCKS proxy credentials sent to the origin server over plaintext HTTP

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using an authenticated SOCKS proxy can ex…

cve.org AsyncHttpClient:async-http-client 5 hari lalu
CVE-2026-61700 CWE-284 3.7

MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, ClientMessage.readPacket processes a server-initiated LOCAL INFILE protocol …

cve.org mariadb-corporation:mariadb-connector-j 5 hari lalu
CVE-2026-69197 CWE-200 N/A

Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion

Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the Content Delivery API applies member and Public Access checks to the directly requested node but not to referenced nodes serialized through Content Pick…

cve.org umbraco:Umbraco-CMS 5 hari lalu
CVE-2026-81515 CWE-755 7.5

Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. From 4.0.0 until 4.3.0, EurekaDiscoveryClient deserializes the registry response as one unit, a…

cve.org SteeltoeOSS:security-advisories 5 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 22 Sep 2026 23:02
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.