CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2026-3542

    Last Modified: 16 Apr 2026

    Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

    Published: 3 Mar 2026
    8.8
    High

    CVE-2026-3540

    Last Modified: 16 Apr 2026

    Inappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

    Published: 3 Mar 2026
    8.8
    High

    CVE-2026-3543

    Last Modified: 17 Apr 2026

    Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

    Published: 3 Mar 2026
    8.8
    High

    CVE-2026-3538

    Last Modified: 18 Apr 2026

    Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

    Published: 3 Mar 2026
    7.2
    High

    CVE-2025-63910

    Last Modified: 5 Mar 2026

    An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted patch file.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2026-24103

    Last Modified: 16 Apr 2026

    A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2025-70821

    Last Modified: 5 Mar 2026

    renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component

    Published: 3 Mar 2026
    9.1
    Critical

    CVE-2025-66945

    Last Modified: 4 Mar 2026

    A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed by the backend at /api/extract, files may be written outside the intended directory, leading to arbitrary file overwrite and potentially remote code execution

    Published: 3 Mar 2026
    7.8
    High

    CVE-2025-52365

    Last Modified: 4 Mar 2026

    A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to execute arbitrary system commands via unsanitized user input passed to os.system(). The vulnerability arises from improper input handling where command-line arguments are directly concatenated into shell commands without validation

    Published: 3 Mar 2026
    6.5
    Medium

    CVE-2024-55025

    Last Modified: 4 Mar 2026

    Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access the HMI system.

    Published: 3 Mar 2026
    7.5
    High

    CVE-2025-63912

    Last Modified: 10 May 2026

    Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to use a weak cryptography algorithm for data encryption, allowing attackers to trivially reverse the encyption and expose credentials.

    Published: 3 Mar 2026
    7.5
    High

    CVE-2025-62817

    Last Modified: 10 Mar 2026

    An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of session->ncp_hdr_buf in __pilot_parsing_ncp() causes a denial of service.

    Published: 3 Mar 2026
    5.5
    Medium

    CVE-2025-62816

    Last Modified: 4 Mar 2026

    An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4L_VERTEXIOC_BOOTUP input leads to a denial of service.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2024-55026

    Last Modified: 4 Mar 2026

    An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request.

    Published: 3 Mar 2026
    2.7
    Low

    CVE-2026-26891

    Last Modified: 18 Apr 2026

    Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_parcel_type.php.

    Published: 3 Mar 2026
    2.7
    Low

    CVE-2026-26890

    Last Modified: 17 Apr 2026

    Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_product.php.

    Published: 3 Mar 2026
    2.7
    Low

    CVE-2026-26889

    Last Modified: 17 Apr 2026

    Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_category.php.

    Published: 3 Mar 2026
    7.1
    High

    CVE-2025-66680

    Last Modified: 5 Mar 2026

    An issue in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter 7.3.2 and earlier allows attackers to delete arbitrary files via a crafted request.

    Published: 3 Mar 2026
    7.2
    High

    CVE-2025-67840

    Last Modified: 5 Mar 2026

    Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Build 14614 through TZM_1757588060_SEP2025_FULL.depot web application API endpoints (including Scheduler and Actions pages). The appliance directly concatenates user-controlled parameters into system commands without sufficient sanitisation, allowing an authenticated admin user to inject and execute arbitrary OS commands with root privileges. An attacker can intercept legitimate requests (e.g. during job creation or execution) using a proxy and modify parameters to include shell metacharacters, achieving remote code execution on the appliance. This completely bypasses the intended CLISH restricted shell confinement and results in full system compromise. The vulnerabilities persist in Release 4.0 Build 14614 including the latest patch (as of the time of testing) TZM_1757588060_SEP2025_FULL.depot.

    Published: 3 Mar 2026
    7.5
    High

    CVE-2025-66363

    Last Modified: 4 Mar 2026

    An issue was discovered in LBS in Samsung Mobile Processor Exynos 2200. There was no check for memory initialization within DL NAS Transport messages.

    Published: 3 Mar 2026
    5.5
    Medium

    CVE-2025-62815

    Last Modified: 4 Mar 2026

    An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of npu_proto_drv.ast.thread_ref in set_cpu_affinity() causes a denial of service.

    Published: 3 Mar 2026
    7.5
    High

    CVE-2025-62814

    Last Modified: 4 Mar 2026

    An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, and 2400. A NULL pointer dereference of ft_handle in load_fw_utc_vector() causes a denial of service.

    Published: 3 Mar 2026
    8.8
    High

    CVE-2024-55022

    Last Modified: 9 Mar 2026

    Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name parameter.

    Published: 3 Mar 2026
    7.5
    High

    CVE-2024-55021

    Last Modified: 9 Mar 2026

    Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2024-55020

    Last Modified: 4 Mar 2026

    A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges.

    Published: 3 Mar 2026
    7.5
    High

    CVE-2024-55019

    Last Modified: 4 Mar 2026

    Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files.

    Published: 3 Mar 2026
    2.7
    Low

    CVE-2026-26886

    Last Modified: 16 Apr 2026

    Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /admin/services/manage_service.php.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2025-70237

    Last Modified: 9 Mar 2026

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetPortTr.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2025-70236

    Last Modified: 4 Mar 2026

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDomainFilter.

    Published: 3 Mar 2026
    7.5
    High

    CVE-2025-69765

    Last Modified: 4 Mar 2026

    Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can cause memory corruption and enable remote code execution.

    Published: 3 Mar 2026
    7.2
    High

    CVE-2025-63911

    Last Modified: 5 Mar 2026

    Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injection vulnerability.

    Published: 3 Mar 2026
    2.7
    Low

    CVE-2026-26887

    Last Modified: 17 Apr 2026

    Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_supplier.php.

    Published: 3 Mar 2026
    2.7
    Low

    CVE-2026-26884

    Last Modified: 16 Apr 2026

    Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/admin/appointments/view_appointment.php.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2024-55024

    Last Modified: 4 Mar 2026

    An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to perform Administrative actions using service accounts.

    Published: 3 Mar 2026
    5.3
    Medium

    CVE-2024-55023

    Last Modified: 9 Mar 2026

    Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitive information.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2025-70240

    Last Modified: 9 Mar 2026

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard51.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2025-70241

    Last Modified: 9 Mar 2026

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5.

    Published: 3 Mar 2026
    7.5
    High

    CVE-2024-55027

    Last Modified: 4 Mar 2026

    Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.

    Published: 3 Mar 2026
    8.1
    High

    CVE-2021-35486

    Last Modified: 13 Mar 2026

    A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwrite the entire application configuration. Specifically, in /ui/rest-proxy/entity/import, neither the X-CSRF-NONCE HTTP header nor the CSRF-NONCE cookie is validated.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2025-70239

    Last Modified: 9 Mar 2026

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard55.

    Published: 3 Mar 2026
    7.2
    High

    CVE-2025-63909

    Last Modified: 5 Mar 2026

    Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers to escalate privileges to root and read and write arbitrary files.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2025-70234

    Last Modified: 9 Mar 2026

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetQoS.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2025-57622

    Last Modified: 12 Mar 2026

    An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature = pickle.loads(request.get_data()) component

    Published: 3 Mar 2026
    8
    High

    CVE-2021-35485

    Last Modified: 5 Mar 2026

    The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one.

    Published: 3 Mar 2026
    2
    Low

    CVE-2023-31044

    Last Modified: 9 Mar 2026

    An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate data fields that may attempt data exfiltration or other malicious activity when automatically executed by the spreadsheet software.

    Published: 3 Mar 2026
    9.6
    Critical

    CVE-2026-3545

    Last Modified: 17 Apr 2026

    Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 3 Mar 2026
    2.7
    Low

    CVE-2026-26888

    Last Modified: 17 Apr 2026

    Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_stock.php.

    Published: 3 Mar 2026
    8.8
    High

    CVE-2026-3541

    Last Modified: 16 Apr 2026

    Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

    Published: 3 Mar 2026
    2.7
    Low

    CVE-2026-26885

    Last Modified: 16 Apr 2026

    Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /classes/Master.php?f=delete_service.

    Published: 3 Mar 2026
    2.7
    Low

    CVE-2026-26883

    Last Modified: 16 Apr 2026

    Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/classes/Master.php?f=delete_appointment.

    Published: 3 Mar 2026