CVE-2026-35595
High Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only requires Ca...
Related Vulnerabilities
- CVE-2026-40258: gramps-webapi: Zip Slip Path Traversal in Media Archive Import CRITICAL
- CVE-2026-40159: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) MEDIUM
- CVE-2026-6026: A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability aff CRITICAL
- CVE-2026-5460: A heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC) hybrid KeyShare pr MEDIUM
- CVE-2026-29129: Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects MEDIUM
Related Coverage
Threat Actors