Export limit exceeded: 404425 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (404425 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-108608 2 Jeecg, Jeecgboot 3 Jeecg-boot, Jeecg Boot, Jeecgboot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to delete other users' AI voice records by supplying an arbitrary userId to DELETE /airag/voice/deleteVoiceRecord. Attackers can obtain record ids from the unchecked GET /airag/voice/listByUser endpoint and delete victims' text-to-speech history entries stored in Redis, one per request.
CVE-2026-108651 2 Jeecg, Jeecgboot 3 Jeecg-boot, Jeecg Boot, Jeecgboot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the getRolesByUserId handler of SystemApiController that allows authenticated users to retrieve any user's role codes. Low-privileged attackers can supply arbitrary userId values to GET /sys/api/getRolesByUserId to enumerate role assignments and identify administrator accounts.
CVE-2026-108696 1 Coreshop 1 Coreshop 2026-10-11 4.3 Medium
CoreShop through 1.5.5 contains an authorization bypass vulnerability in the OrderController that allows authenticated customers to act on other customers' orders by supplying user-controlled ids. Attackers can omit the data field in OrderConfirm or supply another reshipId to SendReship to confirm receipt of others' orders and overwrite return tracking details.
CVE-2026-108694 1 C4illin 1 Convertx 2026-10-11 6.5 Medium
ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files because src/converters/pandoc.ts invokes Pandoc without the --sandbox flag. Attackers can upload a reStructuredText document with an include directive naming an absolute path, convert it, and download output containing the referenced file's contents.
CVE-2026-108653 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryPageList handler of OpenApiController that allows any authenticated user to list OpenAPI registry definitions. Low-privileged attackers can query GET /openapi/list to read virtual paths, internal origin URLs, IP whitelists, and header and parameter templates intended for administrators.
CVE-2026-108620 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController deleteBatch handler that allows any authenticated user to delete organizational positions. Low-privileged attackers can send comma-separated position ids, obtained from the unguarded list endpoint, to remove all sys_position rows and orphan user-position assignments.
CVE-2026-108629 2 Jeecg, Jeecgboot 3 Jeecg-boot, Jeecg Boot, Jeecgboot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDatarule handler of SysDepartPermissionController that allows any authenticated user to modify department data rules. Low-privileged attackers can send departId, permissionId and dataRuleIds to POST /sys/sysDepartPermission/datarule to change, add or clear data rules on any department-menu permission binding.
CVE-2026-108645 2 Jeecg, Jeecgboot 3 Jeecg-boot, Jeecg Boot, Jeecgboot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in SysCategoryController that allows any authenticated user to edit category dictionary nodes via /sys/category/edit. Low-privileged attackers can send POST or PUT requests supplying a node id to rename, recode, or move system-wide sys_category nodes, altering classification values used across forms.
CVE-2026-108649 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryUserRolesById handler of SystemApiController that lets authenticated users read any user's role codes. Low-privileged attackers can send a userId to GET /sys/api/queryUserRolesById to enumerate role assignments and identify administrator accounts.
CVE-2026-108650 2 Jeecg, Jeecgboot 3 Jeecg-boot, Jeecg Boot, Jeecgboot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the getUserPermissionSet handler of SystemApiController that allows any authenticated user to read other users' permission codes. Low-privileged attackers can supply an arbitrary userId to GET /sys/api/getUserPermissionSet to retrieve the full permission set of any account, including administrators.
CVE-2026-108656 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController GET /sys/tenant/getTenantPackApplyUsers endpoint that allows any authenticated user to read tenant administrator applications. Low-privileged attackers can iterate the tenantId parameter to retrieve pending applicants' usernames, real names, phone numbers and departments for any tenant.
CVE-2026-82049 1 Python 1 Cpython 2026-10-11 7.1 High
In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.
CVE-2026-108614 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController exportXls handler that allows any authenticated user to export AI evaluator data. Low-privileged attackers can request /airag/extData/exportXls to download every user's airag_ext_data evaluator definitions and test-tracking records as an Excel workbook.
CVE-2026-108616 2 Jeecg, Jeecgboot 3 Jeecg-boot, Jeecg Boot, Jeecgboot 2026-10-10 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController deleteBatch handler that allows any authenticated user to delete AI evaluator records. Low-privileged attackers can send comma-separated ids to DELETE /airag/extData/deleteBatch, which lacks owner or tenant checks, deleting other users' evaluator and test-tracking records.
CVE-2026-108602 1 Helicone 1 Helicone 2026-10-10 4.3 Medium
Helicone through v2025.08.21-1 contains a server-side request forgery vulnerability in the Jawn webhook sender that allows authenticated organization users to reach internal services by using hostnames resolving to private addresses. Attackers can create webhooks with public hostnames that resolve or DNS-rebind to loopback or internal addresses, causing blind POST requests to internal HTTPS services.
CVE-2026-104841 2026-10-10 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-108679 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the sendBusAnnouncement handler of SystemApiController that allows any authenticated user to send announcements without the required permissions. Low-privileged attackers can POST crafted bodies to /sys/api/sendBusAnnouncement with forged sender, recipients, title and content to deliver spoofed admin or system messages for phishing.
CVE-2026-108674 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the OpenApiController queryById handler that allows low-privileged authenticated users to read OpenAPI definitions without openapi permissions. Attackers can request GET /openapi/queryById with an entry id to obtain internal origin URLs, virtual paths, IP whitelists, and header and parameter templates.
CVE-2026-108657 1 Jeecg 1 Jeecg Boot 2026-10-10 8.1 High
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController passApply handler that allows any authenticated user to approve tenant administrator applications. Attackers can file a pending application via doApplyTenantPackUser and approve it through PUT /sys/tenant/passApply to gain tenant administrator pack permissions in any tenant.
CVE-2026-108622 1 Jeecg 1 Jeecg Boot 2026-10-10 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysLogController delete handler that allows any authenticated user to delete audit log entries. Low-privileged attackers can obtain log ids from the unguarded /sys/log/list endpoint and delete chosen sys_log records to erase traces of their actions.