VulDB
280 credited records · 280 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
22Monitor | CVE-2026-5244No exploit | Cesanta Mongoose TLS 1.3 mongoose.c mg_tls_recv_cert heap-based overflowcesanta · mongoose · CWE-119 | Medium5.5 | — | 0.8% | Apr 2, 2026 |
22Monitor | CVE-2026-5322No exploit | AlejandroArciniegas mcp-data-vis MCP server.js request sql injectionalejandroarciniegas · mcp-data-vis · CWE-74 | Medium5.5 | — | 0.4% | Apr 2, 2026 |
8Monitor | CVE-2026-5321No exploit | vanna-ai vanna FastAPI/Flask Server cross-domain policyvanna-ai · vanna · CWE-346 | Low2.1 | — | 0.2% | Apr 2, 2026 |
22Monitor | CVE-2026-5320No exploit | vanna-ai vanna Chat API Endpoint v2 missing authenticationvanna-ai · vanna · CWE-287 | Medium5.5 | — | 0.7% | Apr 2, 2026 |
8Monitor | CVE-2026-5317No exploit | Nothings stb stb_vorbis.c start_decoder out-of-bounds writenothings · stb vorbis.c · CWE-119 | Low2.1 | — | 0.6% | Apr 1, 2026 |
8Monitor | CVE-2026-5316No exploit | Nothings stb stb_vorbis.c setup_free allocation of resourcesnothings · stb vorbis.c · CWE-400 | Low2.1 | — | 0.7% | Apr 1, 2026 |
8Monitor | CVE-2026-5315No exploit | Nothings stb TTF File stb_truetype.h stbtt__buf_get8 out-of-boundsnothings · stb truetype.h · CWE-119 | Low2.1 | — | 0.8% | Apr 1, 2026 |
8Monitor | CVE-2026-5314No exploit | Nothings stb TTF File stb_truetype.h stbtt_InitFont_internal out-of-boundsnothings · stb truetype.h · CWE-119 | Low2.1 | — | 0.8% | Apr 1, 2026 |
8Monitor | CVE-2026-5313No exploit | Nothings stb GIF Decoder stb_image.h stbi__gif_load_next denial of servicenothings · stb · CWE-404 | Low2.1 | — | 0.5% | Apr 1, 2026 |
4Monitor | CVE-2026-5310No exploit | Enter Software Iperius Backup IperiusAccounts.ini hard-coded keyenter software · iperius backup · CWE-320 | Low1.1 | — | 0.1% | Apr 1, 2026 |
8Monitor | CVE-2026-1879No exploit | Harvard University IQSS Dataverse Theme Customization ThemeAndWidgets.xhtml unrestricted uploadharvard university · iqss dataverse · CWE-284 | Low2.1 | — | 0.3% | Apr 1, 2026 |
22Monitor | CVE-2026-5261No exploit | Shandong Hoteam InforCenter PLM BaseHandler.ashx uploadFileToIIS unrestricted uploadshandong hoteam · inforcenter plm · CWE-284 | Medium5.5 | — | 0.5% | Apr 1, 2026 |
22Monitor | CVE-2026-5258No exploit | Sanster IOPaint File Manager file_manager.py _get_file path traversalsanster · iopaint · CWE-22 | Medium5.5 | — | 0.7% | Apr 1, 2026 |
8Monitor | CVE-2026-5254No exploit | welovemedia FFmate Webhook AppJsonTreeView.vue cross site scriptingwelovemedia · ffmate · CWE-79 | Low2.0 | — | 0.3% | Apr 1, 2026 |
8Monitor | CVE-2026-5253No exploit | bufanyun HotGo editNotice Endpoint MessageList.vue cross site scriptingbufanyun · hotgo · CWE-79 | Low2.0 | — | 0.3% | Apr 1, 2026 |
8Monitor | CVE-2026-5252No exploit | z-9527 admin Message Create Endpoint message.js cross site scriptingz-9527 · admin · CWE-79 | Low2.0 | — | 0.3% | Apr 1, 2026 |
8Monitor | CVE-2026-5251No exploit | z-9527 admin User Update Endpoint user.js dynamically-determined object attributesz-9527 · admin · CWE-913 | Low2.1 | — | 0.4% | Mar 31, 2026 |
8Monitor | CVE-2026-5249No exploit | gougucms Record Endpoint record.html cross site scriptingCWE-79 | Low2.0 | — | 0.3% | Mar 31, 2026 |
8Monitor | CVE-2026-5248No exploit | gougucms User Registration Login.php reg_submit dynamically-determined object attributesCWE-913 | Low2.1 | — | 0.4% | Mar 31, 2026 |
8Monitor | CVE-2026-5205No exploit | chatwoot Webhook API trigger.rb Trigger server-side request forgeryCWE-918 | Low2.1 | — | 0.4% | Mar 31, 2026 |
7Monitor | CVE-2026-5186No exploit | Nothings stb Multi-frame GIF File stb_image.h stbi__load_gif_main double freenothings · stb · CWE-119 | Low1.9 | — | 0.2% | Mar 31, 2026 |
7Monitor | CVE-2026-5185No exploit | Nothings stb_image Multi-frame GIF File stb_image.h stbi__gif_load_next heap-based overflownothings · stb_image · CWE-119 | Low1.9 | — | 0.2% | Mar 31, 2026 |
11Monitor | CVE-2026-5184No exploit | TRENDnet TEW-713RE setSysAdm command injectiontrendnet · tew-713re firmware · CWE-74 | Low2.1 | — | 8.5% | Mar 31, 2026 |
11Monitor | CVE-2026-5183No exploit | TRENDnet TEW-713RE addRouting sub_421494 command injectiontrendnet · tew-713re firmware · CWE-74 | Low2.1 | — | 8.9% | Mar 31, 2026 |
8Monitor | CVE-2026-5148No exploit | YunaiV yudao-cloud page sql injectionyunaiv · yudao-cloud · CWE-74 | Low2.0 | — | 0.3% | Mar 30, 2026 |
- CVE-2026-524422Monitor
Cesanta Mongoose TLS 1.3 mongoose.c mg_tls_recv_cert heap-based overflow
MediumCVSS 5.5No exploitEPSS 1%cesanta · mongooseApr 2, 2026
- CVE-2026-532222Monitor
AlejandroArciniegas mcp-data-vis MCP server.js request sql injection
MediumCVSS 5.5No exploitEPSS 0%alejandroarciniegas · mcp-data-visApr 2, 2026
- CVE-2026-53218Monitor
vanna-ai vanna FastAPI/Flask Server cross-domain policy
LowCVSS 2.1No exploitEPSS 0%vanna-ai · vannaApr 2, 2026
- CVE-2026-532022Monitor
vanna-ai vanna Chat API Endpoint v2 missing authentication
MediumCVSS 5.5No exploitEPSS 1%vanna-ai · vannaApr 2, 2026
- CVE-2026-53178Monitor
Nothings stb stb_vorbis.c start_decoder out-of-bounds write
LowCVSS 2.1No exploitEPSS 1%nothings · stb vorbis.cApr 1, 2026
- CVE-2026-53168Monitor
Nothings stb stb_vorbis.c setup_free allocation of resources
LowCVSS 2.1No exploitEPSS 1%nothings · stb vorbis.cApr 1, 2026
- CVE-2026-53158Monitor
Nothings stb TTF File stb_truetype.h stbtt__buf_get8 out-of-bounds
LowCVSS 2.1No exploitEPSS 1%nothings · stb truetype.hApr 1, 2026
- CVE-2026-53148Monitor
Nothings stb TTF File stb_truetype.h stbtt_InitFont_internal out-of-bounds
LowCVSS 2.1No exploitEPSS 1%nothings · stb truetype.hApr 1, 2026
- CVE-2026-53138Monitor
Nothings stb GIF Decoder stb_image.h stbi__gif_load_next denial of service
LowCVSS 2.1No exploitEPSS 0%nothings · stbApr 1, 2026
- CVE-2026-53104Monitor
Enter Software Iperius Backup IperiusAccounts.ini hard-coded key
LowCVSS 1.1No exploitEPSS 0%enter software · iperius backupApr 1, 2026
- CVE-2026-18798Monitor
Harvard University IQSS Dataverse Theme Customization ThemeAndWidgets.xhtml unrestricted upload
LowCVSS 2.1No exploitEPSS 0%harvard university · iqss dataverseApr 1, 2026
- CVE-2026-526122Monitor
Shandong Hoteam InforCenter PLM BaseHandler.ashx uploadFileToIIS unrestricted upload
MediumCVSS 5.5No exploitEPSS 0%shandong hoteam · inforcenter plmApr 1, 2026
- CVE-2026-525822Monitor
Sanster IOPaint File Manager file_manager.py _get_file path traversal
MediumCVSS 5.5No exploitEPSS 1%sanster · iopaintApr 1, 2026
- CVE-2026-52548Monitor
welovemedia FFmate Webhook AppJsonTreeView.vue cross site scripting
LowCVSS 2.0No exploitEPSS 0%welovemedia · ffmateApr 1, 2026
- CVE-2026-52538Monitor
bufanyun HotGo editNotice Endpoint MessageList.vue cross site scripting
LowCVSS 2.0No exploitEPSS 0%bufanyun · hotgoApr 1, 2026
- CVE-2026-52528Monitor
z-9527 admin Message Create Endpoint message.js cross site scripting
LowCVSS 2.0No exploitEPSS 0%z-9527 · adminApr 1, 2026
- CVE-2026-52518Monitor
z-9527 admin User Update Endpoint user.js dynamically-determined object attributes
LowCVSS 2.1No exploitEPSS 0%z-9527 · adminMar 31, 2026
- CVE-2026-52498Monitor
gougucms Record Endpoint record.html cross site scripting
LowCVSS 2.0No exploitEPSS 0%Mar 31, 2026
- CVE-2026-52488Monitor
gougucms User Registration Login.php reg_submit dynamically-determined object attributes
LowCVSS 2.1No exploitEPSS 0%Mar 31, 2026
- CVE-2026-52058Monitor
chatwoot Webhook API trigger.rb Trigger server-side request forgery
LowCVSS 2.1No exploitEPSS 0%Mar 31, 2026
- CVE-2026-51867Monitor
Nothings stb Multi-frame GIF File stb_image.h stbi__load_gif_main double free
LowCVSS 1.9No exploitEPSS 0%nothings · stbMar 31, 2026
- CVE-2026-51857Monitor
Nothings stb_image Multi-frame GIF File stb_image.h stbi__gif_load_next heap-based overflow
LowCVSS 1.9No exploitEPSS 0%nothings · stb_imageMar 31, 2026
- CVE-2026-518411Monitor
TRENDnet TEW-713RE setSysAdm command injection
LowCVSS 2.1No exploitEPSS 9%trendnet · tew-713re firmwareMar 31, 2026
- CVE-2026-518311Monitor
TRENDnet TEW-713RE addRouting sub_421494 command injection
LowCVSS 2.1No exploitEPSS 9%trendnet · tew-713re firmwareMar 31, 2026
- CVE-2026-51488Monitor
YunaiV yudao-cloud page sql injection
LowCVSS 2.0No exploitEPSS 0%yunaiv · yudao-cloudMar 30, 2026