Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-35620 — OpenClaw < 2026.3.24 - Missing Authorization in /send and /allowlist Chat Commands

OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handlers. The /send command allows non-owner command-authorized senders to change own…

openclaw | Remote | Authorization
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
5.3 MEDIUM
CVE-2026-35619 — OpenClaw < 2026.3.24 - Authorization Bypass via HTTP /v1/models Endpoint

OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to enforce operator read scope requirements. Attackers with only operator.approvals…

openclaw | Remote | Authorization
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
7.1 HIGH
CVE-2026-35602 — Vikunja has a File Size Limit Bypass via Vikunja Import

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size field from the JSON metadata inside the import zip i…

vikunja | Remote | Misconfiguration
Apr 10, 2026 Apr 17, 2026
Apr 10, 2026
Apr 17, 2026
4.1 MEDIUM
CVE-2026-35601 — Vikunja has an iCalendar Property Injection via CRLF in CalDAV Task Output

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV output generator builds iCalendar VTODO entries via raw string concatenation without applying RFC 5545 TEXT …

vikunja | Remote | Injection
Apr 10, 2026 Apr 17, 2026
Apr 10, 2026
Apr 17, 2026
5.4 MEDIUM
CVE-2026-35600 — Vikunja has HTML Injection via Task Titles in Overdue Email Notifications

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, task titles are embedded directly into Markdown link syntax in overdue email notifications without escaping Markdown sp…

vikunja | Remote | Cross-Site Scripting
Apr 10, 2026 Apr 17, 2026
Apr 10, 2026
Apr 17, 2026
6.5 MEDIUM
CVE-2026-35599 — Vikunja has an Algorithmic Complexity DoS in Repeating Task Handler

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function uses an O(n) loop that advances a date by the task's RepeatAfter duration until it…

vikunja | Remote | Denial of Service
Apr 10, 2026 Apr 17, 2026
Apr 10, 2026
Apr 17, 2026
4.3 MEDIUM
CVE-2026-35598 — Vikunja has Missing Authorization on CalDAV Task Read

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesByList methods fetch tasks by UID from the database without verifying that the a…

vikunja | Remote | Authorization
Apr 10, 2026 Apr 17, 2026
Apr 10, 2026
Apr 17, 2026
7.5 HIGH
CVE-2026-35597 — Vikunja Affected by TOTP Brute-Force Due to Non-Functional Account Lockout

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the TOTP failed-attempt lockout mechanism is non-functional due to a database transaction handling bug. When a TOTP val…

vikunja | Remote | Authentication
Apr 10, 2026 Apr 17, 2026
Apr 10, 2026
Apr 17, 2026
4.3 MEDIUM
CVE-2026-35596 — Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the hasAccessToLabel function contains a SQL operator precedence bug that allows any authenticated user to read any lab…

vikunja | Remote | Authorization
Apr 10, 2026 Apr 17, 2026
Apr 10, 2026
Apr 17, 2026
8.3 HIGH
CVE-2026-35595 — Vikunja Affected by Privilege Escalation via Project Reparenting

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only requires CanWrite on the new parent project when …

vikunja | Remote | Authorization
Apr 10, 2026 Apr 17, 2026
Apr 10, 2026
Apr 17, 2026
5.3 MEDIUM
CVE-2026-22560 — Rocket.Chat Open Redirect Vulnerability

An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters within a SAML endpoint.

rocket.chat | Remote | Misconfiguration
Apr 10, 2026 Apr 17, 2026
Apr 10, 2026
Apr 17, 2026
3.3 LOW
CVE-2026-40228 — systemd Journald ANSI Escape Sequence Injection Vulnerability

In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.

systemd | Misconfiguration
Apr 10, 2026 Apr 17, 2026
Apr 10, 2026
Apr 17, 2026
6.2 MEDIUM
CVE-2026-40227 — Systemd Null Pointer Vulnerability

In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.

systemd | Denial of Service
Apr 10, 2026 Apr 14, 2026
Apr 10, 2026
Apr 14, 2026
6.4 MEDIUM
CVE-2026-40226 — systemd nspawn Escape-to-Host Vulnerability

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

systemd | Misconfiguration
Apr 10, 2026 Apr 17, 2026
Apr 10, 2026
Apr 17, 2026
6.4 MEDIUM
CVE-2026-40225 — "Systemd Udev Kernel Output Execution Vulnerability"

In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.

systemd | Misconfiguration
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
6.7 MEDIUM
CVE-2026-40224 — "Systemd Machined Varlink Privilege Escalation"

In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.

systemd | Authorization
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
4.7 MEDIUM
CVE-2026-40223 — Systemd Assert Vulnerability

In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.

systemd | Misconfiguration
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
6.3 MEDIUM
CVE-2026-40023 — Apache Log4cxx, Apache Log4cxx (Conan), Apache Log4cxx (Brew): Silent log event loss in X…

Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions before 1.7.0, fails to sanitize characters forbidden by the XML 1.0 specifica…

log4cxx | Remote | Misconfiguration
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
6.3 MEDIUM
CVE-2026-40021 — Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unesca…

Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts…

log4net | Remote | Misconfiguration
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
6.5 MEDIUM
CVE-2026-35594 — Vikunja Link Share JWT tokens remain valid for 72 hours after share deletion or permissio…

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (GetLinkShareFromClaims in pkg/models/link_sharing.go) constructs authorization obj…

vikunja | Remote | Authentication
Apr 10, 2026 Apr 14, 2026
Apr 10, 2026
Apr 14, 2026
Showing 20 of 6488 Results