377,174 CVE lengkap 1999–2026

CVE Notifier

Arsip lengkap dari cve.org (CVE Record), skor CVSS dari NVD, dan daftar eksploitasi aktif dari CISA KEV. Ter-update tiap 30 menit.

arsip 377,174 CVE • 12,754 critical • 1,713 KEV

  • 1999–2026
  • 395.000+ CVE
  • cve.org
  • NVD CVSS
  • CISA KEV
  • Auto-update 30m
  • SQLite full-text

Menampilkan 12 dari 377,174 entri — halaman 62/31432

CVE-2026-92756 CWE-311 5.5

Combining encryption settings may disable encryption

Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields…

cve.org MongoDB · Inc.:MongoDB · Entity 3 hari lalu
CVE-2026-90997 CWE-294 7.4

Keycloak: Replay protection bypass leads to unauthorized access via database driver semantics mismatch

A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay prot…

cve.org Keycloak:Keycloak 3 hari lalu
CVE-2026-19477 CWE-121 7.8

Stack-based Buffer Overflow Vulnerability in Linux (uldaq)

There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq).  This may result in information disclosure or arbitrary code execution. This vulnerability affects MCC Un…

cve.org MCC:Universal · Library · for 3 hari lalu
CVE-2026-92230 CWE-401 N/A

Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching

Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or featu…

cve.org Apache · Software · Foundation:Apache 3 hari lalu
CVE-2026-54253 CWE-79 8.2

TS3 Manager: Reflected XSS via /api/download port parameter steals operator session

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled port query parameter to socket.connect(por…

cve.org joni1802:ts3-manager 3 hari lalu
CVE-2026-54504 CWE-306 8.8

MCP Documentation Server: Web UI API binds to all interfaces without authentication by default

MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startWebServer in src/web-s…

cve.org andrea9293:mcp-documentation-server 3 hari lalu
CVE-2026-54617 CWE-22 9.8

GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler

GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file se…

cve.org GravitLauncher:Launcher 3 hari lalu
CVE-2026-54524 CWE-89 N/A

Frappe HR: SQL Injection in HRMS Salary Payments Based on Payment Mode Report

Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Payments Based on Payment Mode report. In …

cve.org frappe:hrms 3 hari lalu
CVE-2026-52852 CWE-674 6.5

Traccar: Uncontrolled Infinite Loop DoS via Group Parent Cycle

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a cyclic group-parent hierarchy and request a trips or stops report fo…

cve.org traccar:traccar 3 hari lalu
CVE-2026-52851 CWE-89 7.1

Traccar: Authenticated Blind SQL Injection in DELETE /api/permissions

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/permissions with an extra attacker-controlle…

cve.org traccar:traccar 3 hari lalu
CVE-2026-92992 CWE-862 6.3

Dromara mayfly-go AI Assistant ai.go authorization

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to …

cve.org Dromara:mayfly-go 3 hari lalu
CVE-2026-54649 CWE-200 N/A

punchin-email: Operator inbox (FORWARD_TO) disclosed to correspondents on reply — Cloudflare forward() drops the relay Reply-To

punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops…

cve.org PunchIn-App:punchin-email 3 hari lalu

Statistik

Arsip lengkap kerentanan dari semua sumber — live dari database.

cache/cve.db • 20 Sep 2026 21:52
377,174 Total CVE terindeks
1999–2026
60,905 Tahun 2026
12,754 Critical (skor ≥ 9)
1,713 CISA KEV aktif

Distribusi Severity

CVSS v3
12,754 critical
  • Critical 12,754 (8%)
  • High 61,345 (41%)
  • Medium 68,090 (45%)
  • Low 8,634 (6%)
150,872 dinilai • 226,302 belum

Tren CVE per Tahun

1999–2026
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

cve.org

Arsip penuh CVE dari CVE Program — id, deskripsi, CWE, referensi.

245,461 CVE Record

NVD

Kerentanan dengan skor CVSS v3.x dari NIST National Vulnerability Database.

150,872 CVSS dinilai

Wordfence

Kerentanan plugin/theme WordPress dari Wordfence Intelligence.

11,134 WordPress

WPScan

Kerentanan ekosistem WordPress dari WPScan (Patchstack).

5,444 WordPress

GitHub

CVE yang menyentuh ekosistem GitHub (judul/deskripsi/produk).

3,208 Ekosistem

MITRE

CNA asli yang menerbitkan dan mengelola CVE Record.

114,963 CNA Publish

Sumber Data

cve.org

Arsip CVE Program — id, deskripsi, CWE, referensi. Update tiap 30 menit via delta release.

NVD

Skor CVSS v3.1 untuk entri yang dinilai NIST NVD.

CISA KEV

Kerentanan yang aktif dieksploitasi — prioritas tinggi.

WPScan

Kerentanan ekosistem WordPress.

Wordfence

Kerentanan plugin/theme WordPress.

GitHub

Security Advisories ekosistem open source.