2026 CVE Vulnerabilities

67,245 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-23487MEDIUM6.5Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.deta...
CVE-2026-23486MEDIUM5.3Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all use...
CVE-2026-23485MEDIUM5.3Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal ...
CVE-2026-23484MEDIUM6.5Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filter...
CVE-2026-23483MEDIUM5.3Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses...
CVE-2026-23482HIGH7.5Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the file server endpoint does not perform perm...
CVE-2026-23481MEDIUM6.5Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an authenticated arbitrary file write...
CVE-2026-23480HIGH8.8Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is a privilege escalation vulnerability....
CVE-2026-4596MEDIUM5.4A vulnerability was identified in projectworlds Lawyer Management System 1.0. This issue affects some unknown processing...
CVE-2026-33548MEDIUM6.1Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, improper escaping of tag names retriev...
CVE-2026-33517MEDIUM6.1Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, when deleting a Tag (tag_delete.php), ...
CVE-2026-32879MEDIUM4.9New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in ver...
CVE-2026-32852MEDIUM6.1MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that ...
CVE-2026-32851MEDIUM6.1MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that ...
CVE-2026-32850MEDIUM6.1MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that ...
CVE-2026-30886MEDIUM6.5New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio...
CVE-2026-30849CRITICAL9.8Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family database...
CVE-2026-2298CRITICAL9.4Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing...
CVE-2026-27131MEDIUM5.5The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior...
CVE-2026-4595LOW2.4A vulnerability was determined in code-projects Exam Form Submission 1.0. This vulnerability affects unknown code of the...
CVE-2026-33723MEDIUM6.5WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Subscribe::save()` method in `o...
CVE-2026-33719HIGH8.6WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN...
CVE-2026-33717HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()`...
CVE-2026-33716CRITICAL9.4WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control e...
CVE-2026-33690MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAddr()` function in `o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now