CVE-2026-35602
Medium Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size field from t...
Related Vulnerabilities
- CVE-2026-5144: The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions HIGH
- CVE-2026-34945: Wasmtime has host data leakage with 64-bit tables and Winch MEDIUM
- CVE-2026-29043: HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file MEDIUM
- CVE-2026-28704: Emocheck insecurely loads Dynamic Link Libraries (DLLs). If a crafted DLL file is placed to the same HIGH
- CVE-2026-32932: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulne MEDIUM
Related Coverage
Threat Actors