Export limit exceeded: 404215 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404215 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-108621 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController edit handler that allows any authenticated user to modify organizational positions. Low-privileged attackers can obtain position ids from the unguarded list endpoint and send PUT or POST requests to /sys/position/edit to alter position names, codes, and ranks. | ||||
| CVE-2026-108620 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController deleteBatch handler that allows any authenticated user to delete organizational positions. Low-privileged attackers can send comma-separated position ids, obtained from the unguarded list endpoint, to remove all sys_position rows and orphan user-position assignments. | ||||
| CVE-2026-108619 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to delete message templates via the DELETE /sys/message/sysMessageTemplate/deleteBatch endpoint. Attackers can supply comma-separated template ids from the unguarded list endpoint to delete all sys_sms_template rows, breaking template-based notifications such as workflow reminders. | ||||
| CVE-2026-108618 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to modify message templates via PUT /sys/message/sysMessageTemplate/edit. Attackers can obtain template ids from the unguarded list endpoint and overwrite system notification titles and content, delivering attacker-supplied text or links to other users. | ||||
| CVE-2026-108617 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to create message templates by calling POST /sys/message/sysMessageTemplate/add. Attackers holding only minimal roles can insert arbitrary notification templates with chosen codes and content into the shared sys_sms_template library used for system, e-mail, SMS and IM notifications. | ||||
| CVE-2026-108616 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController deleteBatch handler that allows any authenticated user to delete AI evaluator records. Low-privileged attackers can send comma-separated ids to DELETE /airag/extData/deleteBatch, which lacks owner or tenant checks, deleting other users' evaluator and test-tracking records. | ||||
| CVE-2026-108615 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController delete handler that allows low-privileged authenticated users to delete AI evaluator records. Attackers can send DELETE requests to /airag/extData/delete with any id parameter to remove other users' AI evaluator or test-tracking records without owner or tenant checks. | ||||
| CVE-2026-108614 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController exportXls handler that allows any authenticated user to export AI evaluator data. Low-privileged attackers can request /airag/extData/exportXls to download every user's airag_ext_data evaluator definitions and test-tracking records as an Excel workbook. | ||||
| CVE-2026-108613 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragAppController release handler that allows any authenticated user to publish or unpublish other users' AI applications. Low-privileged attackers can send POST requests to /airag/app/release to obtain share tokens exposing applications to anonymous chat access, or invalidate existing share links. | ||||
| CVE-2026-108612 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AigcWordTemplateController deleteBatch handler that allows low-privileged authenticated users to delete word templates. Attackers can send a DELETE request to /airag/word/deleteBatch with comma-separated ids to permanently delete any templates in the shared library. | ||||
| CVE-2026-108611 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AigcWordTemplateController delete handler that allows any authenticated user to delete word templates. Low-privileged attackers can send DELETE requests to /airag/word/delete with an id parameter to permanently remove any template from the shared library. | ||||
| CVE-2026-108610 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AigcWordTemplateController edit handler that allows any authenticated user to modify word templates. Low-privileged attackers can send PUT or POST requests to /airag/word/edit to overwrite shared templates that other users rely on to generate documents. | ||||
| CVE-2026-108609 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to read other users' AI voice generation history via the userId parameter of GET /airag/voice/listByUser. Attackers who know another user's id can retrieve submitted text-to-speech input, voice settings, timestamps, and generated audio file names and paths stored in Redis. | ||||
| CVE-2026-108608 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to delete other users' AI voice records by supplying an arbitrary userId to DELETE /airag/voice/deleteVoiceRecord. Attackers can obtain record ids from the unchecked GET /airag/voice/listByUser endpoint and delete victims' text-to-speech history entries stored in Redis, one per request. | ||||
| CVE-2026-108607 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to delete other users' AI video generation records by supplying arbitrary userId values to DELETE /airag/video/deleteVideoRecord. Attackers can obtain record ids from the unchecked GET /airag/video/listByUser endpoint and delete victims' Redis-stored video history entries one record per request. | ||||
| CVE-2026-108606 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController deleteById handler that allows any authenticated user to delete OCR records. Low-privileged attackers can obtain record ids from the unguarded GET /airag/ocr/list endpoint and repeatedly delete every shared OCR prompt record stored in Redis. | ||||
| CVE-2026-108605 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController updateById handler that allows any authenticated user to modify global OCR templates. Low-privileged attackers can send PUT requests to /airag/ocr/edit to overwrite LLM prompts in the shared airag:ocr Redis key, corrupting OCR results for all users. | ||||
| CVE-2026-108591 | 1 Innocommerce | 1 Innoshop | 2026-10-10 | 4.4 Medium |
| InnoShop 0.9.2 contains a local file disclosure vulnerability that allows authenticated administrators with files_create permission to read server files by abusing the AI Core MCP file_upload tool's source argument. Attackers can supply file:// or php:// stream wrappers passed to file_get_contents(), storing contents on the public media disk to expose the .env file with APP_KEY and database credentials. | ||||
| CVE-2026-103685 | 2026-10-10 | 4.3 Medium | ||
| Missing Authorization vulnerability in VillaTheme ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce woo-alidropship allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce: from n/a through 2.2.4. | ||||
| CVE-2026-108604 | 2026-10-10 | 6.3 Medium | ||
| Tabularis through 0.27.0 contains an incorrect authorization vulnerability in the MCP run_query safety gate that allows prompt-injected agents or untrusted MCP clients to bypass read-only mode by submitting side-effecting SELECT statements. Attackers can run statements like SELECT setval, nextval, or PostgreSQL query_to_xml with embedded DELETE to modify data without approval prompts. | ||||