377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 19/31432

CVE-2019-25776 CWE-89 7.5

Weaver E-cology SQL Injection via SyncUserInfo.jsp

Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by submitting malicious input through the userIdentifiers GET parameter in the mobile …

cve.org Weaver · Network · Co., 1 hari lalu
CVE-2023-54399 CWE-89 9.8

Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree

Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped…

cve.org Hongjing:e-HR 1 hari lalu
CVE-2026-93854 CWE-1025 N/A

CVE-2026-93854

In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wra…

MITRE OpenStack:Blazar 1 hari lalu
CVE-2026-75894 CWE-617 N/A

Reachable assertion at ranap_handle_co_dt()

In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service.

cve.org Osmocom:osmo-iuh 1 hari lalu
CVE-2026-93852 CWE-862 N/A

CVE-2026-93852

In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to…

MITRE OpenStack:Blazar 1 hari lalu
CVE-2026-75893 CWE-122 N/A

Heap based buffer overflow at ipaccess_proxy_read_msg()

In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg()  function via IPA frame lengths.

cve.org Osmocom:osmo-bsc 1 hari lalu
CVE-2026-75892 CWE-787 N/A

Out of bounds write in PDP ctx GSN-Address decode

In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function through the PDP context GSN-Address sub-field, leading to memory corruption.

cve.org Osmocom:osmo-ggsn 1 hari lalu
CVE-2026-93650 CWE-307 3.7

Saleor throttling.py get_client_ip excessive authentication

A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improp…

cve.org n/a:Saleor 1 hari lalu
CVE-2026-59163 CWE-347 9.1

Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass

Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passed the token to a jwt …

cve.org AxDSan:mnemosyne 1 hari lalu
CVE-2026-92768 CWE-214 5.5

Cockpit-machines: cockpit-machines: sensitive data exposure via command-line arguments

A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM…

cve.org Red · Hat:Red · Hat 1 hari lalu
CVE-2026-92747 CWE-214 5.0

Cockpit-machines: cockpit-machines: sensitive data exposure of guest credentials via json argument in process list

A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `use…

cve.org Red · Hat:Red · Hat 1 hari lalu
CVE-2026-92745 CWE-214 5.0

Cockpit-machines: cockpit-machines: information disclosure of rhsm offline token via process arguments

A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exp…

cve.org Red · Hat:Red · Hat 1 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 19 Sep 2026 23:34
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.