377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 141/31432

CVE-2026-92809 CWE-639 4.3

PrestaShop psgdpr through 1.4.3 GDPR Log Forgery

PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged con…

cve.org PrestaShop:psgdpr 6 hari lalu
CVE-2026-92806 CWE-352 8.1

phpList before 3.6.17 Cross-Site Request Forgery via massremove.php

phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler. Attackers can induce logged-in administrators to visit crafted pages that silently delete and…

cve.org phpList:phpList 6 hari lalu
CVE-2026-92805 CWE-306 9.8

UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard

UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create supe…

cve.org uvdesk:community-skeleton 6 hari lalu
CVE-2026-92804 CWE-918 7.1

Nango through 0.70.4 Server-Side Request Forgery via Configuration

Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authenticated attackers can supply malicious configuration values to direct…

cve.org NangoHQ:Nango 6 hari lalu
CVE-2026-92803 CWE-862 5.3

LibreTranslate through 1.9.6 Missing Access Check on the download_file Route

LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files. Attackers can bypass API key requirements and abuse ban lists to download f…

cve.org LibreTranslate:LibreTranslate 6 hari lalu
CVE-2026-92802 CWE-862 4.3

kan through 0.6.0 Authorization Bypass via GitHub Project Import

kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. Attackers can bypass authorization …

cve.org kanbn:kan 6 hari lalu
CVE-2026-92801 CWE-863 8.8

cc-connect through 1.5.0 User Allowlist Bypass via Feishu Card Actions

cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by triggering card actions in admitted chats…

cve.org chenhg5:cc-connect 6 hari lalu
CVE-2026-92800 CWE-613 6.8

Docs before 5.4.1 Stale Collaboration Session After Access Revocation

Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through…

cve.org suitenumerique:Docs 6 hari lalu
CVE-2026-92796 CWE-863 8.8

Manticore Search 27.0.0 before 28.4.4 Multi-Statement Authorization Bypass

Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries. Attackers can append additional SE…

cve.org manticoresoftware:Manticore · Search 6 hari lalu
CVE-2026-92795 CWE-918 6.5

Coze Studio through 0.5.1 Server-Side Request Forgery via Plugin

Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. Attackers can construct plugin requests to acce…

cve.org coze-dev:coze-studio 6 hari lalu
CVE-2026-92794 CWE-862 7.5

OpenSign through 2.41.3 Information Disclosure via getDocument

OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled. Attackers can supply a document identifier from guest signing links to retrieve…

cve.org OpenSignLabs:OpenSign 6 hari lalu
CVE-2026-92793 CWE-863 8.1

GoAdmin through 1.2.26 Authorization Bypass via Query Parameter

GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter. Attackers can append a query string c…

cve.org GoAdminGroup:go-admin 6 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 23 Sep 2026 07:59
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.