CVE-2026-35602
Medium Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size field from t...
Related Vulnerabilities
- CVE-2025-14545: The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via CRITICAL
- CVE-2026-5994: A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the CRITICAL
- CVE-2026-40242: Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint HIGH
- CVE-2026-6016: A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd o HIGH
- CVE-2026-40175: Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain CRITICAL
Related Coverage
Threat Actors