377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 37/31432

CVE-2026-93596 CWE-862 4.3

ArcadeDB before 26.9.1 Authorization Bypass via Batch Edge Connect

ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker threads used by the parallel edge-connect phase of POST /api/v1/bat…

cve.org ArcadeData:arcadedb 1 hari lalu
CVE-2026-93595 CWE-862 6.5

ArcadeDB before 26.9.1 ACL Bypass via query_database Tool

ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI chat endpoints. The tool executes queries without binding the authenticated principal to DatabaseCo…

cve.org ArcadeData:arcadedb 1 hari lalu
CVE-2026-93594 CWE-863 8.1

ArcadeDB before 26.9.1 ACL Bypass via Index and TimeSeries

ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through LSM …

cve.org ArcadeData:arcadedb 1 hari lalu
CVE-2026-93593 CWE-863 8.1

ArcadeDB before 26.9.1 TimeSeries ACL Bypass via Type Permission

ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets. An authent…

cve.org ArcadeData:arcadedb 1 hari lalu
CVE-2026-93592 CWE-129 7.5

vLLM before 0.28.0 Denial of Service via negative token ID

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single re…

cve.org vllm-project:vllm 1 hari lalu
CVE-2026-93591 CWE-89 7.6

SiYuan before 3.8.3 SQL Injection via unescaped tag in graph.go

SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader…

cve.org siyuan-note:siyuan 1 hari lalu
CVE-2026-93590 CWE-400 3.7

ImageMagick before 7.1.2-31 Policy Bypass in UHDR encoder

ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing s…

cve.org ImageMagick:ImageMagick 1 hari lalu
CVE-2026-93589 CWE-369 3.7

ImageMagick before 7.1.2-31 Division by Zero in FLIF encoder

ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resultin…

cve.org ImageMagick:ImageMagick · ImageMagick:ImageMagick 1 hari lalu
CVE-2026-93588 CWE-476 3.1

ImageMagick before 7.1.2-31 Null Pointer Dereference via PNM

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a specific point during processing, the failed allocation is not …

cve.org ImageMagick:ImageMagick · ImageMagick:ImageMagick 1 hari lalu
CVE-2026-93587 CWE-400 3.3

ImageMagick before 7.1.2-31 Policy Bypass via PCD decoder

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a co…

cve.org ImageMagick:ImageMagick · ImageMagick:ImageMagick 1 hari lalu
CVE-2026-93586 CWE-416 2.9

ImageMagick before 7.1.2-31 Use After Free via ImagesToBlob

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability im…

cve.org ImageMagick:ImageMagick · ImageMagick:ImageMagick 1 hari lalu
CVE-2023-5778 CWE-130 7.5

Missing Length Check

Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. This issue affects F…

cve.org ABB:Freelance · Controller · DCP 1 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 20 Sep 2026 08:00
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.