2026 CVE Vulnerabilities

51,113 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-23487MEDIUM6.5Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.deta...
CVE-2026-23486MEDIUM5.3Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all use...
CVE-2026-23485MEDIUM5.3Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal ...
CVE-2026-23484MEDIUM6.5Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filter...
CVE-2026-23483MEDIUM5.3Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses...
CVE-2026-23481MEDIUM6.5Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an authenticated arbitrary file write...
CVE-2026-4596MEDIUM5.4A vulnerability was identified in projectworlds Lawyer Management System 1.0. This issue affects some unknown processing...
CVE-2026-33548MEDIUM6.1Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, improper escaping of tag names retriev...
CVE-2026-33517MEDIUM6.1Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, when deleting a Tag (tag_delete.php), ...
CVE-2026-32879MEDIUM4.9New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in ver...
CVE-2026-32852MEDIUM6.1MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that ...
CVE-2026-32851MEDIUM6.1MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that ...
CVE-2026-32850MEDIUM6.1MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that ...
CVE-2026-30886MEDIUM6.5New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio...
CVE-2026-27131MEDIUM5.5The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior...
CVE-2026-33723MEDIUM6.5WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Subscribe::save()` method in `o...
CVE-2026-33690MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAddr()` function in `o...
CVE-2026-33688MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `o...
CVE-2026-33685MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/AD_Server/reports.json.p...
CVE-2026-33683MEDIUM5.4WWBN AVideo is an open source video platform. In versions up to and including 26.0, a sanitization order-of-operations f...
CVE-2026-4593MEDIUM6.3A flaw has been found in erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the f...
CVE-2026-33501MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/Vie...
CVE-2026-33500MEDIUM5.4WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcq...
CVE-2026-33499MEDIUM6.1WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `vi...
CVE-2026-30007MEDIUM6.2XnSoft NConvert 7.230 is vulnerable to Use-After-Free via a crafted .tiff file

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now