377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 158/31432

CVE-2026-20306 CWE-78 9.1

Cisco Identity Services Engine Command Injection Vulnerability

A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit th…

cve.org Cisco:Cisco · Identity · Services 16 Sep 2026
CVE-2026-92402 CWE-862 6.3

ChangeWeDer crm top.upstudy.crm.controller.UserController UserController.java index authorization

A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the file UserController.java of the component top.upstudy.crm.controller.Use…

cve.org ChangeWeDer:crm 16 Sep 2026
CVE-2026-87031 CWE-862 N/A

Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through 9.5.3 allows arbitrary account creation

n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/Users.php) did not perform a permission check before creating an account. …

cve.org Concrete · CMS:Concrete · CMS 16 Sep 2026
CVE-2026-87028 CWE-862 N/A

Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Discloses Restricted Page Summary Fields

Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint belonged to the board instance the requesting user was authorized to edit, and did not enforce page-vie…

cve.org Concrete · CMS:Concrete · CMS 16 Sep 2026
CVE-2026-57173 CWE-770 6.5

vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions

vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls AudioMediaIO.load_bytes or AudioMediaIO.load_file without passing VLLM_MAX_…

cve.org vllm-project:vllm 16 Sep 2026
CVE-2026-85386 CWE-79 N/A

Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticated XML/XSLT file upload in the Form Block

Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload question. Plain XML uploads were validated by file extension only and stored as publicly accessible files…

cve.org Concrete · CMS:Concrete · CMS 16 Sep 2026
CVE-2026-85756 CWE-78 7.5

SSH.NET: ScpClient allows server-side RCE via default SCP path handling

SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on the server, and the default RemotePathTransformation.DoubleQuote tran…

cve.org sshnet:SSH.NET 16 Sep 2026
CVE-2026-85385 CWE-79 N/A

Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field

Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output encoding on the Dashboard user management page, where Date::getTimezoneDisplayName() returns any non-I…

cve.org Concrete · CMS:Concrete · CMS 16 Sep 2026
CVE-2026-92401 CWE-287 7.3

ChangeWeDer crm improper authentication

A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie. The manipulation lead…

cve.org ChangeWeDer:crm 16 Sep 2026
CVE-2026-84993 CWE-89 6.5

MikroORM: SQL injection via unvalidated order direction in orderBy

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 and 7.1.7, the shared SQL layer validates the field key of an orderBy clause but does not validate it…

cve.org mikro-orm:mikro-orm 16 Sep 2026
CVE-2026-86359 CWE-276 8.5

CVE-2026-86359

Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation o…

cve.org Dell:Repository · Manager 16 Sep 2026
CVE-2026-85731 CWE-22 8.8

oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path…

cve.org oras-project:oras-go 16 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 24 Sep 2026 14:33
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.