2026 CVE Vulnerabilities
67,245 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23487 | MEDIUM | 6.5 | 0.2% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.deta... |
| CVE-2026-23486 | MEDIUM | 5.3 | 0.7% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all use... |
| CVE-2026-23485 | MEDIUM | 5.3 | 0.3% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal ... |
| CVE-2026-23484 | MEDIUM | 6.5 | 0.3% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filter... |
| CVE-2026-23483 | MEDIUM | 5.3 | 0.8% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses... |
| CVE-2026-23482 | HIGH | 7.5 | 1.5% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the file server endpoint does not perform perm... |
| CVE-2026-23481 | MEDIUM | 6.5 | 0.4% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an authenticated arbitrary file write... |
| CVE-2026-23480 | HIGH | 8.8 | 0.3% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is a privilege escalation vulnerability.... |
| CVE-2026-4596 | MEDIUM | 5.4 | 0.2% | Mar 23, 2026 | A vulnerability was identified in projectworlds Lawyer Management System 1.0. This issue affects some unknown processing... |
| CVE-2026-33548 | MEDIUM | 6.1 | 0.2% | Mar 23, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, improper escaping of tag names retriev... |
| CVE-2026-33517 | MEDIUM | 6.1 | 0.2% | Mar 23, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, when deleting a Tag (tag_delete.php), ... |
| CVE-2026-32879 | MEDIUM | 4.9 | 0.3% | Mar 23, 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in ver... |
| CVE-2026-32852 | MEDIUM | 6.1 | 0.3% | Mar 23, 2026 | MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that ... |
| CVE-2026-32851 | MEDIUM | 6.1 | 0.3% | Mar 23, 2026 | MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that ... |
| CVE-2026-32850 | MEDIUM | 6.1 | 0.3% | Mar 23, 2026 | MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that ... |
| CVE-2026-30886 | MEDIUM | 6.5 | 0.3% | Mar 23, 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio... |
| CVE-2026-30849 | CRITICAL | 9.8 | 0.4% | Mar 23, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family database... |
| CVE-2026-2298 | CRITICAL | 9.4 | 0.4% | Mar 23, 2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing... |
| CVE-2026-27131 | MEDIUM | 5.5 | 0.3% | Mar 23, 2026 | The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior... |
| CVE-2026-4595 | LOW | 2.4 | 0.2% | Mar 23, 2026 | A vulnerability was determined in code-projects Exam Form Submission 1.0. This vulnerability affects unknown code of the... |
| CVE-2026-33723 | MEDIUM | 6.5 | 0.2% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Subscribe::save()` method in `o... |
| CVE-2026-33719 | HIGH | 8.6 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN... |
| CVE-2026-33717 | HIGH | 8.8 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()`... |
| CVE-2026-33716 | CRITICAL | 9.4 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control e... |
| CVE-2026-33690 | MEDIUM | 5.3 | 0.2% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAddr()` function in `o... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now