377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 156/31432

CVE-2026-63126 CWE-190 7.5

Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical m…

cve.org square:wire 16 Sep 2026
CVE-2026-92417 CWE-476 6.5

Open5GS PFCP types.c ogs_pfcp_parse_volume_measurement null pointer dereference

A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component PFCP Handler. The manipulation results in null pointer derefe…

cve.org n/a:Open5GS 16 Sep 2026
CVE-2026-69147 CWE-400 6.5

vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation

vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, and MediaConnector.fetc…

cve.org vllm-project:vllm 16 Sep 2026
CVE-2026-92416 CWE-617 4.3

Open5GS PFCP Session Report Request n4-handler.c smf_n4_handle_session_report_request assertion

A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_report_request of the file src/smf/n4-handler.c of the component PFCP Session Report Request Handler. Th…

cve.org n/a:Open5GS 16 Sep 2026
CVE-2026-47094 CWE-639 8.8

SIMAC MyPHR 1.1 IDOR Account Takeover via /api/employes/put/{id}

SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to access and modify arbitrary employee records due to missing server-side ownership validation. Attac…

cve.org SIMAC:MyPHR 16 Sep 2026
CVE-2026-92720 CWE-306 9.1

Kubero through 3.1.1 Unauthenticated Notifications API Access

Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated attackers to read webhook secrets and service URLs. Attackers can retrieve stored credentials and reg…

cve.org kubero-dev:kubero 16 Sep 2026
CVE-2026-92719 CWE-918 7.5

Quickwit through 0.9.0 SSRF via SQS queue_url Parameter

Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses. Attackers can supply a mali…

cve.org quickwit-oss:quickwit 16 Sep 2026
CVE-2026-92718 CWE-347 7.3

Nuclei from 3.7.0 before 3.11.1 Template Signature Bypass via Modification-Time-Only Cache

Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the…

cve.org projectdiscovery:nuclei 16 Sep 2026
CVE-2026-92717 CWE-306 9.1

Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub

Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can use the obtained toke…

cve.org cobbr:Covenant 16 Sep 2026
CVE-2026-92716 CWE-639 9.6

Shuffle through 2.2.1 API Key Reset Cross-Tenant Privilege Escalation

Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users in other organizations…

cve.org Shuffle:Shuffle 16 Sep 2026
CVE-2026-92605 CWE-639 6.5

IRIS through 2.4.29 Unauthorized Comment Access via Object ID

IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumerate sequential object …

cve.org dfir-iris:iris-web 16 Sep 2026
CVE-2026-92604 CWE-22 8.1

Scirius through 3.8.0 Arbitrary File Write via PCAP Upload

Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacker-controlled JSON content to filesystem paths. Attackers can …

cve.org StamusNetworks:scirius 16 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 24 Sep 2026 13:47
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.