377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 143/31432

CVE-2026-92780 CWE-862 8.8

KnowStreaming through 3.4.1 Missing Authorization on the REST API

KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create …

cve.org didi:KnowStreaming 6 hari lalu
CVE-2026-92779 CWE-1321 7.6

Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via Bindings

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set helper function that processes content block bindings without validation. Attackers can craft content b…

cve.org BuilderIO:@builder.io/sdk-react · BuilderIO:@builder.io/sdk-vue · BuilderIO:@builder.io/sdk-svelte 6 hari lalu
CVE-2026-92778 CWE-693 5.4

CMAK through 3.0.0.6 Feature Gate Bypass via HTML Form Routes

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring…

cve.org yahoo:CMAK 6 hari lalu
CVE-2026-92776 CWE-863 8.1

Wiki.js through 2.5.314 Path Prefix Matching Authorization Bypass

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and …

cve.org requarks:Wiki.js 6 hari lalu
CVE-2026-92775 CWE-918 6.5

Wiki.js through 2.5.314 Server-Side Request Forgery via Image Prefetch

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissio…

cve.org requarks:Wiki.js 6 hari lalu
CVE-2026-92774 CWE-863 4.3

Wiki.js through 2.5.314 Authorization Bypass via GraphQL Tag Omission

Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, tree, tags, searchTags, and links reso…

cve.org requarks:Wiki.js 6 hari lalu
CVE-2026-92773 CWE-639 7.1

Trigger.dev before 4.6.0 GitHub App Installation Takeover

Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization. Attackers can claim another user's GitHub App installation by replaying stat…

cve.org triggerdotdev:trigger.dev 6 hari lalu
CVE-2026-92772 CWE-862 7.1

Leantime before 3.9.6 Unauthorized Plugin Installation via HTMX

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and contro…

cve.org Leantime:leantime 6 hari lalu
CVE-2026-92771 CWE-863 6.5

Twenty before 2.35.0 Permission Bypass via groupBy-with-records Query

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks. Attackers with canReadObjectRecords permission but …

cve.org twentyhq:twenty 6 hari lalu
CVE-2026-92770 CWE-200 6.5

Harbor through 2.15.2 Scanner Credential Disclosure via Query Parameter

Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on the AccessCredential column to recover th…

cve.org goharbor:harbor 6 hari lalu
CVE-2026-92765 CWE-639 6.5

ArcherySec through 2.0.6 Information Disclosure via WebScanVulnList

ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan…

cve.org archerysec:archerysec 6 hari lalu
CVE-2026-92764 CWE-863 4.3

OpenCVE before 3.1.0 Organization API Ignores Token Scope

OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve …

cve.org opencve:opencve 6 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 23 Sep 2026 08:32
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.