U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-4780 - A vulnerability was detected in SourceCodester Sales and Inventory System 1.0. Impacted is an unknown function of the file update_out_standing.php of the component HTTP GET Parameter Handler. Performing a manipulation of the argument sid results i... read CVE-2026-4780
    Published: March 24, 2026; 8:16:41 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-4779 - A security vulnerability has been detected in SourceCodester Sales and Inventory System 1.0. This issue affects some unknown processing of the file update_customer_details.php of the component HTTP GET Parameter Handler. Such manipulation of the a... read CVE-2026-4779
    Published: March 24, 2026; 7:17:12 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2025-13044 - IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
    Published: April 06, 2026; 10:16:15 PM -0400

    V3.1: 6.2 MEDIUM

  • CVE-2026-33765 - Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 have a critical OS Command Injection vulnerability in the savesettings.php file. The application t... read CVE-2026-33765
    Published: March 27, 2026; 4:16:34 PM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2026-5733 - Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 149.0.2.
    Published: April 07, 2026; 9:16:47 AM -0400

  • CVE-2026-5734 - Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been explo... read CVE-2026-5734
    Published: April 07, 2026; 9:16:47 AM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2026-5735 - Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability... read CVE-2026-5735
    Published: April 07, 2026; 9:16:47 AM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2026-30867 - CocoaMQTT is a MQTT 5.0 client library for iOS and macOS written in Swift. Prior to version 2.2.2, a vulnerability exists in the packet parsing logic of CocoaMQTT that allows an attacker (or a compromised/malicious MQTT broker) to remotely crash t... read CVE-2026-30867
    Published: April 02, 2026; 10:16:28 AM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-35200 - Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73 and 9.7.1-alpha.4, a file can be uploaded with a filename extension that passes the file extension allowlist (e.g., .txt) but w... read CVE-2026-35200
    Published: April 06, 2026; 4:16:27 PM -0400

    V3.1: 5.4 MEDIUM

  • CVE-2026-4570 - A vulnerability was identified in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /view_customers.php of the component HTTP POST Request Handler. Such manipulation of the argument searchtxt leads to sql i... read CVE-2026-4570
    Published: March 23, 2026; 1:16:06 AM -0400

    V3.1: 8.8 HIGH

  • CVE-2025-57834 - An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem (Exynos 980, 850, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400, and Modem 5410... read CVE-2025-57834
    Published: April 06, 2026; 4:16:20 PM -0400

  • CVE-2025-54328 - An issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. A Stack-ba... read CVE-2025-54328
    Published: April 06, 2026; 4:16:20 PM -0400

  • CVE-2026-5355 - A vulnerability has been found in Trendnet TEW-657BRM 1.00.1. Affected by this issue is the function vpn_drop of the file /setup.cgi. The manipulation of the argument policy_name leads to os command injection. The attack is possible to be carried ... read CVE-2026-5355
    Published: April 02, 2026; 1:16:32 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-5354 - A flaw has been found in Trendnet TEW-657BRM 1.00.1. Affected by this vulnerability is the function vpn_connect of the file /setup.cgi. Executing a manipulation of the argument policy_name can lead to os command injection. The attack can be execut... read CVE-2026-5354
    Published: April 02, 2026; 1:16:32 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-5353 - A vulnerability was detected in Trendnet TEW-657BRM 1.00.1. Affected is the function ping_test of the file /setup.cgi. Performing a manipulation of the argument c4_IPAddr results in os command injection. Remote exploitation of the attack is possib... read CVE-2026-5353
    Published: April 02, 2026; 1:16:32 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-5352 - A security vulnerability has been detected in Trendnet TEW-657BRM 1.00.1. This impacts the function Edit of the file /setup.cgi. Such manipulation of the argument pcdb_list leads to os command injection. The attack may be launched remotely. The ex... read CVE-2026-5352
    Published: April 02, 2026; 1:16:31 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-5351 - A weakness has been identified in Trendnet TEW-657BRM 1.00.1. This affects the function add_wps_client of the file /setup.cgi. This manipulation of the argument wl_enrolee_pin causes os command injection. The attack may be initiated remotely. The ... read CVE-2026-5351
    Published: April 02, 2026; 12:16:28 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-5732 - Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability affects Firefox < 149.0.2 and Firefox ESR < 140.9.1.
    Published: April 07, 2026; 9:16:47 AM -0400

  • CVE-2025-57835 - An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. Improper m... read CVE-2025-57835
    Published: April 06, 2026; 2:16:40 PM -0400

  • CVE-2025-59440 - An issue was discovered in USIM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. Improper ... read CVE-2025-59440
    Published: April 06, 2026; 2:16:40 PM -0400

Created September 20, 2022 , Updated August 27, 2024