377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 168/31432

CVE-2026-19941 CWE-345 5.9

checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof

An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wild…

cve.org ISC:BIND · 9 16 Sep 2026
CVE-2026-61590 CWE-306 7.4

djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a remote method-in…

cve.org djust-org:djust 16 Sep 2026
CVE-2026-19662 CWE-416 5.9

qpcache NOQNAME proof use-after-free crashes recursive resolver

An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the …

cve.org ISC:BIND · 9 16 Sep 2026
CVE-2026-19667 CWE-197 7.5

Remote assertion failure via 16-bit length truncation in `dns_ncache_add()`

If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named`…

cve.org ISC:BIND · 9 16 Sep 2026
CVE-2026-92364 CWE-89 6.3

itsourcecode Leave Management System index.php sql injection

A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /module/employee/index.php. The manipulation of the argument ID leads to …

cve.org itsourcecode:Leave · Management · System 16 Sep 2026
CVE-2026-81736 CWE-1050 7.5

Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees

If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 …

cve.org ISC:BIND · 9 16 Sep 2026
CVE-2026-85104 CWE-924 N/A

Brain stimulation parameters can be modified via Bluetooth in Sooma

In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can make unauthenticated changes to brain stimulation parameters.

cve.org Sooma:Sooma · tDCS · Home 16 Sep 2026
CVE-2026-92363 CWE-400 4.3

ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption

A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executing a manipulation can lead to resource consumption. The attack…

cve.org ag-ui-protocol:ag-ui 16 Sep 2026
CVE-2026-92469 CWE-639 8.1

microservices-platform through 6.0.0 Arbitrary File Deletion via Missing Ownership Check

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumera…

cve.org zlt2000:microservices-platform 16 Sep 2026
CVE-2026-92468 CWE-639 6.5

microservices-platform through 6.0.0 Arbitrary Elasticsearch Index Read via search-center

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in…

cve.org zlt2000:microservices-platform 16 Sep 2026
CVE-2026-92467 CWE-620 8.3

microservices-platform through 6.0.0 Unverified Password Change via /users/password

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current…

cve.org zlt2000:microservices-platform 16 Sep 2026
CVE-2026-92466 CWE-862 8.8

microservices-platform through 6.0.0 Missing Authorization via Disabled URL Permission Checking

zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. A…

cve.org zlt2000:microservices-platform 16 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 25 Sep 2026 19:05
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.