377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 165/31432

CVE-2026-19033 CWE-349 6.5

Unauthenticated IXFR deltas are applied to the live zone before TSIG verification

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not…

cve.org ISC:BIND · 9 16 Sep 2026
CVE-2026-76825 CWE-200 8.4

RestrictedPython: Sandbox escape via string.Formatter field resolution

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy o…

cve.org zopefoundation:RestrictedPython 16 Sep 2026
CVE-2026-84997 CWE-835 7.5

react/http: A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU

react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encodi…

cve.org reactphp:http 16 Sep 2026
CVE-2026-80274 CWE-617 7.5

Validating resolver can abort while caching a mismatched NOQNAME proof

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it w…

cve.org ISC:BIND · 9 16 Sep 2026
CVE-2026-61709 CWE-281 5.3

OpenFGA: ListUsers returns a deliberately-excluded user (authorization-decision over-inclusion) when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user

OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an intersection containing…

cve.org openfga:openfga 16 Sep 2026
CVE-2026-76163 CWE-617 7.5

named aborts on a TKEY query when the user configuration has no global options statement

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue a…

cve.org ISC:BIND · 9 16 Sep 2026
CVE-2026-89031 CWE-639 5.4

Blog2Social WordPress Plugin < 9.1.0 Broken Access Control via b2s_calendar_move_post

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php issues an UPDATE ag…

cve.org Adenion:Blog2Social 16 Sep 2026
CVE-2026-19666 CWE-416 7.5

Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.1…

cve.org ISC:BIND · 9 16 Sep 2026
CVE-2026-82964 CWE-281 8.8

Avast sandbox privilege escalation via unpreserved DACLs on virtualized files in aswSnx.sys

Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. …

cve.org Gen · Digital:Avast · Free 16 Sep 2026
CVE-2026-89030 CWE-862 4.3

Blog2Social WordPress Plugin < 9.1.0 User Email Disclosure via b2s_search_user

Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to low-privileged accounts. The b2s_search_user AJAX handler in includes/Ajax/Get.php invokes B2S_Tools:…

cve.org Adenion:Blog2Social 16 Sep 2026
CVE-2026-92365 CWE-407 4.3

vllm-project vllm thinking_budget_state.py algorithmic complexity

A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic c…

cve.org vllm-project:vllm 16 Sep 2026
CVE-2026-81563 CWE-401 7.5

SVCB AliasMode additional-data error leaks qpcache references

A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will e…

cve.org ISC:BIND · 9 16 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 25 Sep 2026 21:55
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.