377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 124/31432

CVE-2026-92972 CWE-306 8.6

SGLang through 0.5.19 Unauthenticated Route Poisoning via PUT endpoint

SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV transfer routing table. Attackers can su…

cve.org sgl-project:sglang 5 hari lalu
CVE-2026-92971 CWE-617 7.5

InternLM LMDeploy through 0.17.0 Assertion Denial of Service

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migrati…

cve.org InternLM:lmdeploy 5 hari lalu
CVE-2026-92970 CWE-22 8.8

HUBzero CMS through 2.2.32 Path Traversal via File Upload

HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository. Attackers can supply t…

cve.org hubzero:hubzero-cms 5 hari lalu
CVE-2026-80355 CWE-352 5.4

CVE-2026-80355

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, l…

cve.org Dell:OpenManage · Server · Administrator 5 hari lalu
CVE-2026-89418 CWE-674 N/A

Uncontrolled Recursion leading to Denial of Service in protobuf-javascript (google-protobuf)

google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes to any Node.js service that calls the gener…

cve.org Google:protobuf-javascript · (aka · google-protobuf 5 hari lalu
CVE-2026-14850 CWE-640 N/A

Weak password recovery mechanism for forgotten password in MobiAPParc

The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords fo…

cve.org MobiAPParc:MobiAPParc 5 hari lalu
CVE-2026-90887 CWE-79 7.1

WordPress WP Inventory Manager plugin <= 2.5.4 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.

cve.org WP · Inventory:WP · Inventory 5 hari lalu
CVE-2026-78528 CWE-862 5.3

WordPress BerqWP plugin <= 4.1.15 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.

cve.org BerqWP:BerqWP 5 hari lalu
CVE-2026-78295 CWE-352 8.8

WordPress Xagio SEO plugin <= 7.1.0.43 - Cross Site Request Forgery (CSRF) vulnerability

Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.

cve.org Xagio · SEO:Xagio · SEO 5 hari lalu
CVE-2026-78294 CWE-79 6.5

WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.

cve.org Dylan · Kuhn:Geo · Mashup 5 hari lalu
CVE-2026-74017 CWE-862 5.3

WordPress User Registration plugin <= 5.2.7 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.

cve.org wpeverest:User · Registration 5 hari lalu
CVE-2026-74005 CWE-352 5.4

WordPress PublishPress Series plugin <= 3.1.3 - Cross Site Request Forgery (CSRF) vulnerability

Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.

cve.org PublishPress:PublishPress · Series 5 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 23 Sep 2026 02:11
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.