Products: 1
Vulnerabilities: 11
Known Exploited: 0
1
Critical Level Threats
1
High Level Threats
5
Medium Level Threats
2
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-64677
Anki's local HTTP server is vulnerable to directory traversal attacks
Last Modified: Aug 08, 2026
Published: Aug 06, 2026
CVE-2026-58266
Anki: User scripts in iframes have access to the internal Anki API
Last Modified: Jul 08, 2026
Published: Jul 07, 2026
CVE-2026-59153
Anki's local HTTP server does not sufficiently validate requests
Last Modified: Jul 08, 2026
Published: Jul 07, 2026
CVE-2025-62187
In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux (media file pathnames are not necessarily relative to the media folder).
Last Modified: Oct 10, 2025
Published: Oct 07, 2025
CVE-2025-62185
In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed for a YouTube link in the deck. The executable name could be youtube-dl.exe or yt-dlp.exe or yt-dlp_x86.exe.
Last Modified: Oct 10, 2025
Published: Oct 07, 2025
Items Per Page
