U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-35534 - ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in PersonView.php due to incorrect use of sanitizeText() as an output sanitizer for HTML attribute context. The function only ... read CVE-2026-35534
    Published: April 07, 2026; 12:16:29 PM -0400

  • CVE-2018-25248 - MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field. Attackers can submit a new download with HTML/JavaScript code in the tit... read CVE-2018-25248
    Published: April 04, 2026; 10:16:20 AM -0400

    V3.1: 7.2 HIGH

  • CVE-2018-25249 - MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments. Attackers can add crafted HTML and JavaScript payloads in the commen... read CVE-2018-25249
    Published: April 04, 2026; 10:16:20 AM -0400

    V3.1: 6.4 MEDIUM

  • CVE-2026-34166 - LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter in LiquidJS incorrectly accounts for memory usage when the memoryLimit option is enabled. It charges str.length + pattern.leng... read CVE-2026-34166
    Published: April 08, 2026; 3:25:21 PM -0400

    V3.1: 5.3 MEDIUM

  • CVE-2026-35525 - LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, for {% include %}, {% render %}, and {% layout %}, LiquidJS checks whether the candidate path is inside the configured partials or layouts roots ... read CVE-2026-35525
    Published: April 08, 2026; 4:16:24 PM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-39859 - LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, liquidjs 10.25.0 documents root as constraining filenames passed to renderFile() and parseFile(), but top-level file loads do not enforce that bo... read CVE-2026-39859
    Published: April 08, 2026; 4:16:26 PM -0400

  • CVE-2025-45057 - D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
    Published: April 08, 2026; 2:24:45 PM -0400

  • CVE-2025-45058 - D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fx parameter in the jingx_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
    Published: April 08, 2026; 2:24:45 PM -0400

  • CVE-2025-45059 - D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
    Published: April 08, 2026; 2:24:45 PM -0400

  • CVE-2025-50665 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of input parameters in the /web_keyword.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request via the name, en, t... read CVE-2025-50665
    Published: April 08, 2026; 3:24:17 PM -0400

  • CVE-2025-50666 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in parameters such ... read CVE-2025-50666
    Published: April 08, 2026; 3:24:17 PM -0400

  • CVE-2025-50667 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the iface parameter in the /wan_line_detection.asp endpoint.
    Published: April 08, 2026; 3:24:17 PM -0400

  • CVE-2025-50668 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the s parameter in the /web_list_opt.asp endpoint.
    Published: April 08, 2026; 3:24:17 PM -0400

  • CVE-2025-50669 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of the wan_ping parameter in the /wan_ping.asp endpoint.
    Published: April 08, 2026; 3:24:17 PM -0400

  • CVE-2025-50670 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_bwr.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in the name, qq, and time pa... read CVE-2025-50670
    Published: April 08, 2026; 3:24:17 PM -0400

  • CVE-2025-50672 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint.
    Published: April 08, 2026; 3:24:17 PM -0400

  • CVE-2025-50673 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.asp endpoint.
    Published: April 08, 2026; 3:24:18 PM -0400

  • CVE-2025-50655 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endpoint.
    Published: April 08, 2026; 3:24:16 PM -0400

  • CVE-2025-50657 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpoint.
    Published: April 08, 2026; 3:24:16 PM -0400

  • CVE-2025-50659 - A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error parameter in the /user.asp endpoint.
    Published: April 08, 2026; 3:24:16 PM -0400

Created September 20, 2022 , Updated August 27, 2024