Skip to content
Noroxi

VulDB

280 credited records · 280 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • CVE-2026-5244
    22Monitor

    Cesanta Mongoose TLS 1.3 mongoose.c mg_tls_recv_cert heap-based overflow

    MediumCVSS 5.5No exploitEPSS 1%

    cesanta · mongooseApr 2, 2026

  • CVE-2026-5322
    22Monitor

    AlejandroArciniegas mcp-data-vis MCP server.js request sql injection

    MediumCVSS 5.5No exploitEPSS 0%

    alejandroarciniegas · mcp-data-visApr 2, 2026

  • vanna-ai vanna FastAPI/Flask Server cross-domain policy

    LowCVSS 2.1No exploitEPSS 0%

    vanna-ai · vannaApr 2, 2026

  • CVE-2026-5320
    22Monitor

    vanna-ai vanna Chat API Endpoint v2 missing authentication

    MediumCVSS 5.5No exploitEPSS 1%

    vanna-ai · vannaApr 2, 2026

  • Nothings stb stb_vorbis.c start_decoder out-of-bounds write

    LowCVSS 2.1No exploitEPSS 1%

    nothings · stb vorbis.cApr 1, 2026

  • Nothings stb stb_vorbis.c setup_free allocation of resources

    LowCVSS 2.1No exploitEPSS 1%

    nothings · stb vorbis.cApr 1, 2026

  • Nothings stb TTF File stb_truetype.h stbtt__buf_get8 out-of-bounds

    LowCVSS 2.1No exploitEPSS 1%

    nothings · stb truetype.hApr 1, 2026

  • Nothings stb TTF File stb_truetype.h stbtt_InitFont_internal out-of-bounds

    LowCVSS 2.1No exploitEPSS 1%

    nothings · stb truetype.hApr 1, 2026

  • Nothings stb GIF Decoder stb_image.h stbi__gif_load_next denial of service

    LowCVSS 2.1No exploitEPSS 0%

    nothings · stbApr 1, 2026

  • Enter Software Iperius Backup IperiusAccounts.ini hard-coded key

    LowCVSS 1.1No exploitEPSS 0%

    enter software · iperius backupApr 1, 2026

  • Harvard University IQSS Dataverse Theme Customization ThemeAndWidgets.xhtml unrestricted upload

    LowCVSS 2.1No exploitEPSS 0%

    harvard university · iqss dataverseApr 1, 2026

  • CVE-2026-5261
    22Monitor

    Shandong Hoteam InforCenter PLM BaseHandler.ashx uploadFileToIIS unrestricted upload

    MediumCVSS 5.5No exploitEPSS 0%

    shandong hoteam · inforcenter plmApr 1, 2026

  • CVE-2026-5258
    22Monitor

    Sanster IOPaint File Manager file_manager.py _get_file path traversal

    MediumCVSS 5.5No exploitEPSS 1%

    sanster · iopaintApr 1, 2026

  • welovemedia FFmate Webhook AppJsonTreeView.vue cross site scripting

    LowCVSS 2.0No exploitEPSS 0%

    welovemedia · ffmateApr 1, 2026

  • bufanyun HotGo editNotice Endpoint MessageList.vue cross site scripting

    LowCVSS 2.0No exploitEPSS 0%

    bufanyun · hotgoApr 1, 2026

  • z-9527 admin Message Create Endpoint message.js cross site scripting

    LowCVSS 2.0No exploitEPSS 0%

    z-9527 · adminApr 1, 2026

  • z-9527 admin User Update Endpoint user.js dynamically-determined object attributes

    LowCVSS 2.1No exploitEPSS 0%

    z-9527 · adminMar 31, 2026

  • gougucms Record Endpoint record.html cross site scripting

    LowCVSS 2.0No exploitEPSS 0%

    Mar 31, 2026

  • gougucms User Registration Login.php reg_submit dynamically-determined object attributes

    LowCVSS 2.1No exploitEPSS 0%

    Mar 31, 2026

  • chatwoot Webhook API trigger.rb Trigger server-side request forgery

    LowCVSS 2.1No exploitEPSS 0%

    Mar 31, 2026

  • Nothings stb Multi-frame GIF File stb_image.h stbi__load_gif_main double free

    LowCVSS 1.9No exploitEPSS 0%

    nothings · stbMar 31, 2026

  • Nothings stb_image Multi-frame GIF File stb_image.h stbi__gif_load_next heap-based overflow

    LowCVSS 1.9No exploitEPSS 0%

    nothings · stb_imageMar 31, 2026

  • CVE-2026-5184
    11Monitor

    TRENDnet TEW-713RE setSysAdm command injection

    LowCVSS 2.1No exploitEPSS 9%

    trendnet · tew-713re firmwareMar 31, 2026

  • CVE-2026-5183
    11Monitor

    TRENDnet TEW-713RE addRouting sub_421494 command injection

    LowCVSS 2.1No exploitEPSS 9%

    trendnet · tew-713re firmwareMar 31, 2026

  • YunaiV yudao-cloud page sql injection

    LowCVSS 2.0No exploitEPSS 0%

    yunaiv · yudao-cloudMar 30, 2026