377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 218/31432

CVE-2026-79994 CWE-367 N/A

Docker Sandboxes UDS forwarder can reach arbitrary host Unix sockets through a symlink race

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate direct…

cve.org Docker:Docker · Sandboxes 15 Sep 2026
CVE-2026-68950 CWE-798 8.8

Use of Hard-coded Credentials in Digital Watchdog VMAX DVR and NVR Product Lineups

The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.

cve.org Digital · Watchdog:VMAX · A1 15 Sep 2026
CVE-2026-68070 CWE-306 8.8

Missing Authentication for Critical Function in Digital Watchdog VMAX DVR and NVR Product Lineups

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

cve.org Digital · Watchdog:VMAX · A1 15 Sep 2026
CVE-2026-54544 CWE-918 7.2

Fireshare has unauthenticated SSRF via missing login_required on webhook test endpoints

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbound HTTP requests are missing the @login_required decorator. An unauthenticated attacker can call POS…

cve.org ShaneIsrael:fireshare 15 Sep 2026
CVE-2026-66890 CWE-798 9.6

Use of Hard-coded Credentials in Digital Watchdog VMAX DVR and NVR Product Lineups

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

cve.org Digital · Watchdog:VMAX · A1 15 Sep 2026
CVE-2026-54337 CWE-88 9.8

Fireshare has Unauthenticated Argument Injection to Arbitrary File Write/Overwrite

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. Version 1.6.14 fixes …

cve.org ShaneIsrael:fireshare 15 Sep 2026
CVE-2026-81927 CWE-79 N/A

Concrete CMS before 9.5.3 is vulnerable to Stored XSS via SVG upload in "Reject" sanitization mode

Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the non-default "Reject files containing potentially harmful elements" mode (concrete.f…

cve.org Concrete · CMS:Concrete · CMS 15 Sep 2026
CVE-2026-68953 CWE-306 6.5

Missing Authentication for Critical Function in Digital Watchdog VMAX DVR and NVR Product Lineups

The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted…

cve.org Digital · Watchdog:VMAX · A1 15 Sep 2026
CVE-2026-88065 CWE-200 7.5

`tts-be` application has a Broken Access Control vulnerability

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/ap…

cve.org NIAEFEUP:tts-be 15 Sep 2026
CVE-2026-18426 CWE-862 N/A

Concrete CMS 9.0.0 to 9.5.2 Express Form block missing authorization allows an authenticated editor to modify Express Forms they cannot edit

Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management actions, which relied solely on CSRF token validation. Because the token is bound to the…

cve.org Concrete · CMS:Concrete · CMS 15 Sep 2026
CVE-2026-92237 CWE-532 N/A

CVE-2026-92237

Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application toke…

cve.org Devolutions:PowerShell · Universal 15 Sep 2026
CVE-2026-81926 CWE-79 N/A

Concrete CMS 9.4.0 through 9.5.2 is vulnerable to Cross-site scripting in the location panel duplicate-path confirmation dialog

Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint returned the submitted path unmodified in …

cve.org Concrete · CMS:Concrete · CMS 15 Sep 2026

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 26 Sep 2026 10:28
377,174 Total CVE terindeks
▲ 1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.