Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
33925
Total
2632
Critical
10022
High
10229
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-35599 | MEDIUM | 6.5 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function uses an O(n) loop that advances a date by the task's … | Apr 10, 2026 |
| CVE-2026-35598 | MEDIUM | 4.3 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesByList methods fetch tasks by UID from the database without … | Apr 10, 2026 |
| CVE-2026-35597 | MEDIUM | 5.9 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the TOTP failed-attempt lockout mechanism is non-functional due to a database transaction handling bug. … | Apr 10, 2026 |
| CVE-2026-35596 | MEDIUM | 4.3 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the hasAccessToLabel function contains a SQL operator precedence bug that allows any authenticated user … | Apr 10, 2026 |
| CVE-2026-35595 | HIGH | 8.3 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only requires CanWrite on the new parent project when … | Apr 10, 2026 |
| CVE-2026-22560 | UNKNOWN | — | An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters within a SAML endpoint. | Apr 10, 2026 |
| CVE-2026-40228 | LOW | 2.9 | In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes … | Apr 10, 2026 |
| CVE-2026-40227 | MEDIUM | 6.2 | In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has … | Apr 10, 2026 |
| CVE-2026-40226 | MEDIUM | 6.4 | In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file. | Apr 10, 2026 |
| CVE-2026-40225 | MEDIUM | 6.4 | In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output. | Apr 10, 2026 |
| CVE-2026-40224 | MEDIUM | 6.7 | In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace. | Apr 10, 2026 |
| CVE-2026-40223 | MEDIUM | 4.7 | In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running. | Apr 10, 2026 |
| CVE-2026-40023 | UNKNOWN | — | Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions before 1.7.0, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets in log messages, NDC, and … | Apr 10, 2026 |
| CVE-2026-40021 | UNKNOWN | — | Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions before 3.3.0, fail to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets in MDC … | Apr 10, 2026 |
| CVE-2026-35594 | MEDIUM | 6.5 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (GetLinkShareFromClaims in pkg/models/link_sharing.go) constructs authorization objects entirely from JWT claims … | Apr 10, 2026 |
| CVE-2026-34727 | HIGH | 7.4 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking whether the matched … | Apr 10, 2026 |
| CVE-2026-34481 | UNKNOWN | — | Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, … | Apr 10, 2026 |
| CVE-2026-34480 | UNKNOWN | — | Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing … | Apr 10, 2026 |
| CVE-2026-34479 | UNKNOWN | — | The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML … | Apr 10, 2026 |
| CVE-2026-34478 | UNKNOWN | — | Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant … | Apr 10, 2026 |
| CVE-2026-34477 | UNKNOWN | — | The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property, but not when configured through … | Apr 10, 2026 |
| CVE-2026-29043 | MEDIUM | 5.5 | HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based … | Apr 10, 2026 |
| CVE-2026-29002 | HIGH | 7.2 | CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin accounts by tampering with the f_k_levels_list parameter in user creation requests. … | Apr 10, 2026 |
| CVE-2026-23781 | UNKNOWN | — | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the application package. … | Apr 10, 2026 |
| CVE-2026-36236 | UNKNOWN | — | SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter. | Apr 10, 2026 |