377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 12/31432

CVE-2026-93868 CWE-338 8.1

Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attacke…

cve.org Cotonti:Cotonti 1 hari lalu
CVE-2026-76901 CWE-639 5.8

CordysCRM: Broken object-level authorization in lead pool and account pool detail endpoints exposes arbitrary leads and accounts

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, GET /pool/lead/get/{id} in PoolClueController.get and GET /pool/account/get/{id} in PoolCus…

cve.org 1Panel-dev:CordysCRM 1 hari lalu
CVE-2026-84239 CWE-89 7.6

IBM Guardium Data Protection is affected by multiple vulnerabilities.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

cve.org IBM:Guardium · Data · Protection 1 hari lalu
CVE-2026-92708 CWE-200 7.5

devalue: Cross-request process memory disclosure in devalue when `stringify` / `uneval` serialize Node Buffers

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emit…

cve.org sveltejs:devalue 1 hari lalu
CVE-2026-63647 CWE-306 N/A

CordysCRM SSE Notification Stream Hijack via `/sse/subscribe`

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoint…

cve.org 1Panel-dev:CordysCRM 1 hari lalu
CVE-2026-84241 CWE-285 8.1

IBM Guardium Data Protection is affected by multiple vulnerabilities.

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

cve.org IBM:Guardium · Data · Protection 1 hari lalu
CVE-2026-84108 CWE-79 8.1

IBM Guardium Data Protection is affected by multiple vulnerabilities.

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

cve.org IBM:Guardium · Data · Protection 1 hari lalu
CVE-2026-84106 CWE-79 8.9

IBM Guardium Data Protection is affected by multiple vulnerabilities.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

cve.org IBM:Guardium · Data · Protection 1 hari lalu
CVE-2026-84105 CWE-89 7.7

IBM Guardium Data Protection is affected by multiple vulnerabilities.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

cve.org IBM:Guardium · Data · Protection 1 hari lalu
CVE-2026-63646 CWE-200 N/A

CordysCRM MCP Form Configuration Endpoint Exposed to Anonymous Users

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, GET /mcp/form/config/{formKey} calls McpController.getMcpField without authentication becau…

cve.org 1Panel-dev:CordysCRM 1 hari lalu
CVE-2026-84089 CWE-269 7.8

IBM Guardium Data Protection is affected by multiple vulnerabilities.

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

cve.org IBM:Guardium · Data · Protection 1 hari lalu
CVE-2026-84086 CWE-22 7.2

IBM Guardium Data Protection is affected by multiple vulnerabilities.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

cve.org IBM:Guardium · Data · Protection 1 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 19 Sep 2026 20:47
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.