377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 140/31432

CVE-2026-62997 CWE-502 N/A

Kedro-Datasets: Remote code execution in experimental `PyTorchDataset` via unsafe `torch.load`

Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.PyTorchDataset in kedro-datasets loads .pt model files with torch.load without enforcing weights_only…

cve.org kedro-org:kedro-plugins 6 hari lalu
CVE-2026-75513 CWE-89 9.1

Marten: SQL injection in Marten's LINQ provider via unescaped string literals

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, potentially attacker-controlled strings into…

cve.org JasperFx:marten 6 hari lalu
CVE-2026-81871 CWE-295 N/A

OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related c…

cve.org open-telemetry:opentelemetry-go 6 hari lalu
CVE-2026-81872 CWE-400 N/A

OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter a tight CPU loop when attacker-driven log emission fills its asynchron…

cve.org open-telemetry:opentelemetry-go 6 hari lalu
CVE-2026-81869 CWE-176 N/A

OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and string-slice attr…

cve.org open-telemetry:opentelemetry-go 6 hari lalu
CVE-2026-92816 CWE-22 7.8

ComfyUI before 0.30.0 Path Traversal via dataset save nodes

ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attack…

cve.org Comfy-Org:ComfyUI 6 hari lalu
CVE-2026-92815 CWE-918 7.5

changedetection.io through 0.60.6 SSRF via browser-step Goto URL

changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the optional_valu…

cve.org dgtlmoon:changedetection.io 6 hari lalu
CVE-2026-92814 CWE-79 4.2

changedetection.io through 0.60.6 Cross-Site Scripting via watch_title

changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection. Attackers can place malicious markup in monitored page titles that reaches notification…

cve.org dgtlmoon:changedetection.io 6 hari lalu
CVE-2026-92813 CWE-918 4.9

Metabase through 0.63.18 SSRF via GeoJSON URL validation bypass

Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with…

cve.org metabase:Metabase 6 hari lalu
CVE-2026-92812 CWE-22 6.8

decap-server Path Traversal via Sibling Directory Prefix Matching

decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names b…

cve.org decaporg:decap-server 6 hari lalu
CVE-2026-92811 CWE-200 6.5

browserless 1.44.0 through 2.56.7 File Protocol Restriction Bypass

browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token holders to read arbitrary files. Attackers can navigate Playwright-dri…

cve.org browserless:browserless 6 hari lalu
CVE-2026-92810 CWE-639 4.3

PrestaShop blockwishlist through 3.0.2 Information Disclosure

PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can …

cve.org PrestaShop:blockwishlist 6 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 23 Sep 2026 07:27
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.