14 Total advisories
14 Vulnerabilities
0 Malware
Vulnerabilities
MEDIUM 5.9
CVE-2026-40265
Note Mark has Broken Access Control on Asset Download
CRITICAL 9.4
CVE-2026-41571
Note Mark: OIDC-registered users authenticated by submitting password "null"
LOW 3.7
CVE-2026-40263
Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel
CRITICAL 10.0
CVE-2026-44523
Note Mark has a JWT Secret Weakness that allows Full Account Takeover via Token Forgery
UNKNOWN
CVE-2026-41571
Note Mark: OIDC-registered users authenticated by submitting password "null" in github.com/enchant97/note-mark/backend
UNKNOWN
CVE-2026-40263
Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel in github.com/enchant97/note-mark/backend
UNKNOWN
CVE-2026-44523
Note Mark has a JWT Secret Weakness that allows Full Account Takeover via Token Forgery in github.com/enchant97/note-mark/backend
UNKNOWN
CVE-2026-40265
Note Mark has Broken Access Control on Asset Download in github.com/enchant97/note-mark/backend
UNKNOWN
CVE-2026-44522
Note Mark: Arbitrary File Write via Path Traversal in Asset Names Leads to Remote Code Execution
HIGH 8.7
CVE-2026-40262
Note Mark has Stored XSS via Unrestricted Asset Upload
UNKNOWN
CVE-2026-44522
Note Mark: Arbitrary File Write via Path Traversal in Asset Names Leads to Remote Code Execution in github.com/enchant97/note-mark/backend
UNKNOWN
CVE-2026-40262
Note Mark has Stored XSS via Unrestricted Asset Upload in github.com/enchant97/note-mark/backend
MEDIUM 5.3
CVE-2026-41572
Note Mark: Unauthenticated read of notes and assets in soft-deleted public books
UNKNOWN
CVE-2026-41572
Note Mark: Unauthenticated read of notes and assets in soft-deleted public books in github.com/enchant97/note-mark/backend
Ready to move
Start Securing
Free, no credit card | First findings in minutes