377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 139/31432

CVE-2026-92584 CWE-79 6.1

AVideo through 29.0 Stored Cross-Site Scripting via User-Agent Header

AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which wr…

cve.org WWBN:AVideo 6 hari lalu
CVE-2026-92583 CWE-307 6.5

AVideo through 29.0 Rate Limit Bypass via Non-Atomic Counter Increment

AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection…

cve.org WWBN:AVideo 6 hari lalu
CVE-2026-92582 CWE-352 7.1

AVideo through 29.0 Broken Access Control via videoAddNew.json.php CSRF Bypass

AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-reque…

cve.org WWBN:AVideo 6 hari lalu
CVE-2026-92581 CWE-20 4.3

AVideo through 29.0 Like Counter Desynchronization via Array Parameter

In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can se…

cve.org WWBN:AVideo 6 hari lalu
CVE-2026-92580 CWE-78 8.8

AVideo through 29.0 CloneSite Stored Shell Injection via SSH Password CSRF

In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '…

cve.org WWBN:AVideo 6 hari lalu
CVE-2026-92579 CWE-289 5.4

AVideo through 29.0 Broken Access Control via CSRF Exemption Basename Collision

In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The Log…

cve.org WWBN:AVideo 6 hari lalu
CVE-2026-92578 CWE-287 8.1

WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPassword…

cve.org WWBN:AVideo 6 hari lalu
CVE-2026-92577 CWE-639 7.5

AVideo through 29.0 API get_api_video Broken Access Control via clean_title

In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can…

cve.org WWBN:AVideo 6 hari lalu
CVE-2026-92576 CWE-918 8.6

HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchTool

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send…

cve.org HKUDS:nanobot 6 hari lalu
CVE-2026-89034 CWE-306 6.5

TCH QRing R20_B006 Unauthenticated BLE Access

TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, …

cve.org TCH:QRing 6 hari lalu
CVE-2026-64684 CWE-200 6.8

RMCP: Custom HTTP headers leak to cross-origin redirect targets

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_cl…

cve.org modelcontextprotocol:rust-sdk 6 hari lalu
CVE-2026-85469 CWE-1357 8.0

Quay-builder-qemu: quay-builder-qemu: release workflow uses third-party action pinned to mutable @master with registry credentials in scope

A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows th…

cve.org Red · Hat:Red · Hat 6 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 23 Sep 2026 07:28
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.