377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 51/31432

CVE-2026-2585 CWE-79 6.4

Brizy – Page Builder <= 2.8.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'rootAttributes' Parameter

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ parameter in all versions up to, and including, 2.8.14 due to insufficient input sanitization and output…

Wordfence themefusecom:Brizy · – · Page 2 hari lalu
CVE-2026-18441 CWE-639 4.3

LatePoint - Appointment Booking & Scheduling <= 5.6.9 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure via 'customer[id]' Parameter

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9 via the set_customer_ob…

Wordfence latepoint:Appointment · Booking · Plugin 2 hari lalu
CVE-2026-93454 CWE-79 5.4

Aureus ERP through 1.6.0 Stored XSS via Payment Term Note

Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the …

cve.org Webkul:Aureus · ERP 2 hari lalu
CVE-2026-93453 CWE-640 8.3

SOGo before 5.12.11 Password Reset Token Interception via Origin Header

SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can s…

cve.org Alinto:SOGo 2 hari lalu
CVE-2026-93452 CWE-787 7.5

snappy-java through 1.1.10.8 Buffer Overflow in Snappy.compress

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds t…

cve.org xerial:snappy-java 2 hari lalu
CVE-2026-93451 CWE-787 6.5

snappy-java through 1.1.10.8 Buffer Overflow via typed uncompress methods

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to …

cve.org xerial:snappy-java 2 hari lalu
CVE-2026-93450 CWE-674 7.5

go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal and Unmarshal

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply…

cve.org go-openapi:swag 2 hari lalu
CVE-2026-93308 CWE-770 4.3

O-RAN-SC SMO OAM VES Collector allocation of resources

A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation results in allocation of resources. The attac…

cve.org O-RAN-SC:SMO · OAM 2 hari lalu
CVE-2026-85887 CWE-732 7.7

M365 Copilot Information Disclosure Vulnerability

cve.org Microsoft:Microsoft · 365 · Copilot 2 hari lalu
CVE-2026-83946 CWE-79 8.2

Azure Portal Spoofing Vulnerability

cve.org Microsoft:Azure · Portal 2 hari lalu
CVE-2026-69843 CWE-290 10.0

Microsoft Fabric Elevation of Privilege Vulnerability

cve.org Microsoft:Microsoft · Fabric 2 hari lalu
CVE-2026-85878 CWE-285 9.9

Azure Database for PostgreSQL Elevation of Privilege Vulnerability

cve.org Microsoft:Azure · HorizonDB 2 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 20 Sep 2026 17:39
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.