377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 161/31432

CVE-2026-92625 CWE-306 7.5

Control iD iDSecure Unauthenticated Denial of Service

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that term…

cve.org Control · iD:iDSecure 16 Sep 2026
CVE-2026-92615 CWE-413 6.6

Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tenant tls-config bleed

A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, or tenant-supplied mTLS cli…

cve.org Red · Hat:Red · Hat 16 Sep 2026
CVE-2026-70416 CWE-502 10.0

CVE-2026-70416

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote exec…

cve.org Dell:ObjectScale 16 Sep 2026
CVE-2026-92627 CWE-416 N/A

Heap Use-After-Free in H5T__conv_f_f

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer alloca…

cve.org The · HDF · Group:HDF5 16 Sep 2026
CVE-2026-92385 CWE-79 2.4

SourceCodester Online Food Ordering System Category Update update_category.php cross site scripting

A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. The manipulation lead…

cve.org SourceCodester:Online · Food · Ordering 16 Sep 2026
CVE-2026-76104 CWE-732 5.5

CVE-2026-76104

Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access could potentially exploit this vulnera…

cve.org Dell:ObjectScale 16 Sep 2026
CVE-2026-26947 CWE-269 6.7

CVE-2026-26947

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit t…

cve.org Dell:ECS 16 Sep 2026
CVE-2025-43936 CWE-287 8.1

CVE-2025-43936

Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthor…

cve.org Dell:ObjectScale 16 Sep 2026
CVE-2025-36591 CWE-327 4.4

CVE-2025-36591

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A high privileged attacker with local access could po…

cve.org Dell:Elastic · Cloud · Storage 16 Sep 2026
CVE-2026-92383 CWE-352 4.3

PbootCMS User Management UserController.php mod cross-site request forgery

A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the comp…

cve.org n/a:PbootCMS 16 Sep 2026
CVE-2026-82410 CWE-248 N/A

Pocketbase: Unhandled panic in worker goroutines

Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middleware covers regular request handling but not internal child and worker goroutines. A panic in one of …

cve.org pocketbase:pocketbase 16 Sep 2026
CVE-2026-79651 CWE-400 7.5

Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching

A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the syste…

cve.org Red · Hat:Red · Hat 16 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 24 Sep 2026 15:20
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.