CVE-2026-35595
High Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only requires Ca...
Related Vulnerabilities
- CVE-2026-40224: In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink c MEDIUM
- CVE-2026-5778: Integer underflow in wolfSSL packet sniffer LOW
- CVE-2025-13926: An attacker could use data obtained by sniffing the network traffic to
forge packets in order to ma MEDIUM
- CVE-2026-6030: A flaw has been found in itsourcecode Construction Management System 1.0. The impacted element is an MEDIUM
- CVE-2026-34944: Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64 MEDIUM
Related Coverage
Threat Actors