5.3

CVSS3.1

CVE-2026-40100 - FastGPT has Unauthenticated SSRF in /api/core/app/mcpTools/runTool via missing CHECK_INTERNAL_IP de…

FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool endpoint accepts arbitrary URLs without authentication. The internal IP check in isInternalAddress() only blocks private IPs when CHECK_INTERNAL_IP=true, which is not the default. This allows unauthenti…

📅 Published: April 10, 2026, 4:39 p.m. 🔄 Last Modified: April 15, 2026, 7:02 p.m.

3.7

CVSS3.1

CVE-2026-40097 - Step CA affected by an index out of bounds panic in TPM attestation EKU validation

Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to before 0.30.0-rc3, an attacker can trigger an index out-of-bounds panic in Step CA by sending a crafted attestation key (AK) certificate with an empty Extended Key Usage (EKU) extensio…

📅 Published: April 10, 2026, 4:34 p.m. 🔄 Last Modified: April 13, 2026, 3:02 p.m.

6.3

CVSS4.0

CVE-2026-40074 - SvelteKit's invalidated redirect in handle hook causes Denial-of-Service

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, redirect, when called from inside the handle server hook with a location parameter containing characters that are invalid in a HTTP header, will cause an unhandled TypeError. This coul…

📅 Published: April 10, 2026, 4:26 p.m. 🔄 Last Modified: April 15, 2026, 7:01 p.m.

8.2

CVSS4.0

CVE-2026-40073 - SvelteKit has a BODY_SIZE_LIMIT bypass in @sveltejs/adapter-node

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, under certain circumstances, requests could bypass the BODY_SIZE_LIMIT on SvelteKit applications running with adapter-node. This bypass does not affect body size limits at other layers…

📅 Published: April 10, 2026, 4:24 p.m. 🔄 Last Modified: April 15, 2026, 6:43 p.m.

5.3

CVSS3.1

CVE-2026-40086 - Rembg has a Path Traversal via Custom Model Loading

Rembg is a tool to remove images background. Prior to 2.0.75, a path traversal vulnerability in the rembg HTTP server allows unauthenticated remote attackers to read arbitrary files from the server's filesystem. By sending a crafted request with a malicious model_path parameter, an attacker can for…

📅 Published: April 10, 2026, 4:16 p.m. 🔄 Last Modified: April 13, 2026, 3:02 p.m.

4.3

CVSS3.1

CVE-2026-40103 - Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's scoped API token enforcement for custom project background routes is method-confused. A token with only projects.background can successfully delete a project background, while a token with only projects.backgr…

📅 Published: April 10, 2026, 4:12 p.m. 🔄 Last Modified: April 15, 2026, 2:45 p.m.

5.4

CVSS3.1

CVE-2026-35602 - Vikunja has a File Size Limit Bypass via Vikunja Import

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size field from the JSON metadata inside the import zip instead of the actual decompressed file content length for the file size enforcement check. By settin…

📅 Published: April 10, 2026, 4:10 p.m. 🔄 Last Modified: April 14, 2026, 3:16 p.m.

4.1

CVSS3.1

CVE-2026-35601 - Vikunja has an iCalendar Property Injection via CRLF in CalDAV Task Output

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV output generator builds iCalendar VTODO entries via raw string concatenation without applying RFC 5545 TEXT value escaping. User-controlled task titles containing CRLF characters break the iCalendar property …

📅 Published: April 10, 2026, 4:08 p.m. 🔄 Last Modified: April 13, 2026, 4:16 p.m.

5.4

CVSS3.1

CVE-2026-35600 - Vikunja has HTML Injection via Task Titles in Overdue Email Notifications

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, task titles are embedded directly into Markdown link syntax in overdue email notifications without escaping Markdown special characters. When rendered by goldmark and sanitized by bluemonday (which allows <a> and <img> …

📅 Published: April 10, 2026, 4:07 p.m. 🔄 Last Modified: April 14, 2026, 3:01 p.m.

6.5

CVSS3.1

CVE-2026-35599 - Vikunja has an Algorithmic Complexity DoS in Repeating Task Handler

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function uses an O(n) loop that advances a date by the task's RepeatAfter duration until it exceeds the current time. By creating a repeating task with a 1-second interval and a due date far …

📅 Published: April 10, 2026, 4:05 p.m. 🔄 Last Modified: April 13, 2026, 3:02 p.m.
Total resulsts: 344963
Page 114 of 34,497
« previous page » next page
Filters