Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Blinko HIGH 7.2
CVE-2026-23882

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creation function allows specifying…

Fix: 1.8.4+
Fix from $1,950 2026-03-23
Blinko MEDIUM 6.5
CVE-2026-23487

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.detail Endpoint Leaks the Superad…

Fix: 1.8.4+
Fix from $1,600 2026-03-23
Blinko MEDIUM 5.3
CVE-2026-23488

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the /api/v1/comment/create endpoint has an unauthorized access vulnerabilit…

Fix: 1.8.4+
Fix from $1,600 2026-03-23
Blinko HIGH 7.5
CVE-2026-23482

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the file server endpoint does not perform permission checks on the temp/ pa…

Fix: 1.8.4+
Fix from $1,950 2026-03-23
Blinko MEDIUM 6.5
CVE-2026-23481

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an authenticated arbitrary file write vulnerability in saveAdditio…

Fix: 1.8.4+
Fix from $1,600 2026-03-23
Blinko MEDIUM 6.5
CVE-2026-23484

Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filtered, allowing path traversal t…

Fix: 1.8.3+
Fix from $1,600 2026-03-23
Blinko MEDIUM 5.3
CVE-2026-23483

Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths …

Fix: 1.8.3+
Fix from $1,600 2026-03-23
Blinko MEDIUM 5.3
CVE-2026-23485

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal sequences, allowing enumerati…

Fix: 1.8.4+
Fix from $1,600 2026-03-23
Blinko MEDIUM 5.3
CVE-2026-23486

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all user information, including user…

Fix: 1.8.4+
Fix from $1,600 2026-03-23
Blinko HIGH 8.8
CVE-2026-23480

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is a privilege escalation vulnerability. The upsertUser endpoint has …

Fix: 1.8.4+
Fix from $1,950 2026-03-23