CVE-2026-35602
Medium Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size field from t...
Related Vulnerabilities
- CVE-2026-40259: SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttribut HIGH
- CVE-2026-1263: The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, MEDIUM
- CVE-2026-5996: A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected el CRITICAL
- CVE-2026-5187: Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. MEDIUM
- CVE-2026-5983: A vulnerability was determined in D-Link DIR-605L 2.13B01. This issue affects the function formSetDD HIGH
Related Coverage
Threat Actors