CVE-2026-35602
Medium Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size field from t...
Related Vulnerabilities
- CVE-2026-6016: A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd o HIGH
- CVE-2026-3358: The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthori MEDIUM
- CVE-2026-34500: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled a MEDIUM
- CVE-2026-25854: Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via th MEDIUM
- CVE-2026-40070: bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and is MEDIUM
Related Coverage
Threat Actors