2026 CVE Vulnerabilities
51,113 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23487 | MEDIUM | 6.5 | 0.2% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.deta... |
| CVE-2026-23486 | MEDIUM | 5.3 | 0.7% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all use... |
| CVE-2026-23485 | MEDIUM | 5.3 | 0.3% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal ... |
| CVE-2026-23484 | MEDIUM | 6.5 | 0.3% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filter... |
| CVE-2026-23483 | MEDIUM | 5.3 | 0.8% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses... |
| CVE-2026-23481 | MEDIUM | 6.5 | 0.4% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an authenticated arbitrary file write... |
| CVE-2026-4596 | MEDIUM | 5.4 | 0.2% | Mar 23, 2026 | A vulnerability was identified in projectworlds Lawyer Management System 1.0. This issue affects some unknown processing... |
| CVE-2026-33548 | MEDIUM | 6.1 | 0.2% | Mar 23, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, improper escaping of tag names retriev... |
| CVE-2026-33517 | MEDIUM | 6.1 | 0.2% | Mar 23, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, when deleting a Tag (tag_delete.php), ... |
| CVE-2026-32879 | MEDIUM | 4.9 | 0.3% | Mar 23, 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in ver... |
| CVE-2026-32852 | MEDIUM | 6.1 | 0.3% | Mar 23, 2026 | MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that ... |
| CVE-2026-32851 | MEDIUM | 6.1 | 0.3% | Mar 23, 2026 | MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that ... |
| CVE-2026-32850 | MEDIUM | 6.1 | 0.3% | Mar 23, 2026 | MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that ... |
| CVE-2026-30886 | MEDIUM | 6.5 | 0.3% | Mar 23, 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio... |
| CVE-2026-27131 | MEDIUM | 5.5 | 0.3% | Mar 23, 2026 | The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior... |
| CVE-2026-33723 | MEDIUM | 6.5 | 0.2% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Subscribe::save()` method in `o... |
| CVE-2026-33690 | MEDIUM | 5.3 | 0.2% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAddr()` function in `o... |
| CVE-2026-33688 | MEDIUM | 5.3 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `o... |
| CVE-2026-33685 | MEDIUM | 5.3 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/AD_Server/reports.json.p... |
| CVE-2026-33683 | MEDIUM | 5.4 | 0.2% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, a sanitization order-of-operations f... |
| CVE-2026-4593 | MEDIUM | 6.3 | 0.2% | Mar 23, 2026 | A flaw has been found in erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the f... |
| CVE-2026-33501 | MEDIUM | 5.3 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/Vie... |
| CVE-2026-33500 | MEDIUM | 5.4 | 0.2% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcq... |
| CVE-2026-33499 | MEDIUM | 6.1 | 0.2% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `vi... |
| CVE-2026-30007 | MEDIUM | 6.2 | 0.2% | Mar 23, 2026 | XnSoft NConvert 7.230 is vulnerable to Use-After-Free via a crafted .tiff file |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now