377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 142/31432

CVE-2026-92792 CWE-287 7.5

OpenNHP through 1.0.2 Authentication Bypass via Fallback Verifier

OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally. Attackers can bypass at…

cve.org OpenNHP:opennhp 6 hari lalu
CVE-2026-92791 CWE-22 7.5

Uber Kraken through 0.1.29 Path Traversal via tag parameter

Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-dir…

cve.org uber:kraken 6 hari lalu
CVE-2026-92790 CWE-703 6.5

Higress before 2.2.4 Rate Limit Bypass via Malformed Cookie Header

Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper to recover and return a continue action that bypasses AI token rate limiting. Unauthenticated attacke…

cve.org higress-group:higress 6 hari lalu
CVE-2026-92789 CWE-918 6.5

Graylog through 7.1.4 Server-Side Request Forgery via HTTP Redirect

Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or event notification permissions can craft a…

cve.org Graylog2:graylog2-server 6 hari lalu
CVE-2026-92788 CWE-863 8.8

Coze Studio through 0.5.1 Cross-Tenant Database Access via Workflow SQL Node

Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace. Authenticated attackers can enumerate predictable table identifiers and execute SQL state…

cve.org coze-dev:coze-studio 6 hari lalu
CVE-2026-92787 CWE-798 9.8

Feast through 0.66.0 Authentication Bypass via Unverified Token

Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Atta…

cve.org feast-dev:feast 6 hari lalu
CVE-2026-92786 CWE-787 7.8

LightGBM through 4.7.0 Out-of-Bounds Write via Crafted Model

LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with inva…

cve.org lightgbm-org:LightGBM 6 hari lalu
CVE-2026-92785 CWE-502 8.1

Angel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary Classes

Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator …

cve.org Angel-ML:angel 6 hari lalu
CVE-2026-92784 CWE-94 7.5

@refinedev/inferencer through 7.0.0 Code Injection via API Field Names

@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON pro…

cve.org refinedev:@refinedev/inferencer 6 hari lalu
CVE-2026-92783 CWE-862 8.1

Yeti through 2.11.0 Missing Authorization on RBAC Relationship Deletion

Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and perman…

cve.org yeti-platform:yeti 6 hari lalu
CVE-2026-92782 CWE-863 8.1

Chroma through 1.5.9 Authorization Bypass via Collection Identifier

Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers ca…

cve.org chroma-core:chroma 6 hari lalu
CVE-2026-92781 CWE-1321 6.3

Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via builder.userAttributes

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. Attackers can …

cve.org BuilderIO:@builder.io/sdk-react · BuilderIO:@builder.io/sdk-vue · BuilderIO:@builder.io/sdk-svelte 6 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 23 Sep 2026 07:59
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.