The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2026-35534 - ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in PersonView.php due to incorrect use of sanitizeText() as an output sanitizer for HTML attribute context. The function only ... read CVE-2026-35534
Published: April 07, 2026; 12:16:29 PM -0400 -
CVE-2018-25248 - MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field. Attackers can submit a new download with HTML/JavaScript code in the tit... read CVE-2018-25248
Published: April 04, 2026; 10:16:20 AM -0400V3.1: 7.2 HIGH
-
CVE-2018-25249 - MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments. Attackers can add crafted HTML and JavaScript payloads in the commen... read CVE-2018-25249
Published: April 04, 2026; 10:16:20 AM -0400V3.1: 6.4 MEDIUM
-
CVE-2026-34166 - LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter in LiquidJS incorrectly accounts for memory usage when the memoryLimit option is enabled. It charges str.length + pattern.leng... read CVE-2026-34166
Published: April 08, 2026; 3:25:21 PM -0400V3.1: 5.3 MEDIUM
-
CVE-2026-35525 - LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, for {% include %}, {% render %}, and {% layout %}, LiquidJS checks whether the candidate path is inside the configured partials or layouts roots ... read CVE-2026-35525
Published: April 08, 2026; 4:16:24 PM -0400V3.1: 7.5 HIGH
-
CVE-2026-39859 - LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, liquidjs 10.25.0 documents root as constraining filenames passed to renderFile() and parseFile(), but top-level file loads do not enforce that bo... read CVE-2026-39859
Published: April 08, 2026; 4:16:26 PM -0400 -
CVE-2025-45057 - D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published: April 08, 2026; 2:24:45 PM -0400 -
CVE-2025-45058 - D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fx parameter in the jingx_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published: April 08, 2026; 2:24:45 PM -0400 -
CVE-2025-45059 - D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published: April 08, 2026; 2:24:45 PM -0400 -
CVE-2025-50665 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of input parameters in the /web_keyword.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request via the name, en, t... read CVE-2025-50665
Published: April 08, 2026; 3:24:17 PM -0400 -
CVE-2025-50666 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in parameters such ... read CVE-2025-50666
Published: April 08, 2026; 3:24:17 PM -0400 -
CVE-2025-50667 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the iface parameter in the /wan_line_detection.asp endpoint.
Published: April 08, 2026; 3:24:17 PM -0400 -
CVE-2025-50668 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the s parameter in the /web_list_opt.asp endpoint.
Published: April 08, 2026; 3:24:17 PM -0400 -
CVE-2025-50669 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of the wan_ping parameter in the /wan_ping.asp endpoint.
Published: April 08, 2026; 3:24:17 PM -0400 -
CVE-2025-50670 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_bwr.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in the name, qq, and time pa... read CVE-2025-50670
Published: April 08, 2026; 3:24:17 PM -0400 -
CVE-2025-50672 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint.
Published: April 08, 2026; 3:24:17 PM -0400 -
CVE-2025-50673 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.asp endpoint.
Published: April 08, 2026; 3:24:18 PM -0400 -
CVE-2025-50655 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endpoint.
Published: April 08, 2026; 3:24:16 PM -0400 -
CVE-2025-50657 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpoint.
Published: April 08, 2026; 3:24:16 PM -0400 -
CVE-2025-50659 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error parameter in the /user.asp endpoint.
Published: April 08, 2026; 3:24:16 PM -0400