Search

Search Results (404425 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-98351 1 Linux 1 Linux Kernel 2026-10-11 5.5 Medium
In the Linux kernel, the following vulnerability has been resolved: wifi: virt_wifi: free skb when disconnected When the simulated link is disconnected, virt_wifi_start_xmit() returns NET_XMIT_DROP without freeing the skb. dev_hard_start_xmit() treats this return value as consumed, so every packet sent while disconnected leaks its skb. Free the skb before returning the drop status.
CVE-2026-108634 2 Jeecg, Jeecgboot 3 Jeecg-boot, Jeecg Boot, Jeecgboot 2026-10-11 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to delete department permission bindings via the DELETE /sys/sysDepartPermission/deleteBatch endpoint. Attackers can obtain row ids from the unguarded list endpoint and submit them in the ids parameter to remove menus and buttons departments can grant to their roles.
CVE-2026-108636 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartController appImportExcel handler that allows any authenticated user to import departments. Low-privileged attackers can upload a crafted Excel workbook to POST /sys/sysDepart/appImportExcel to create arbitrary sys_depart records in the administrator-maintained department tree.
CVE-2026-98252 1 Linux 1 Linux Kernel 2026-10-11 7 High
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() iwpm_get_nlmsg_request() initializes refcount _after_ list_add_tail() making it accessible to global list where another CPU can kref_get() on nlmsg_request causing a refcount "addition on 0" bug. Fix this by initializing kref _before_ list_add_tail() so refcount for nlmsg_request can be incremented/decremented normally. In addition, also initialize every field before list_add_tail().
CVE-2026-98254 1 Linux 1 Linux Kernel 2026-10-11 7.8 High
In the Linux kernel, the following vulnerability has been resolved: swiotlb: use the adjusted address for the highmem page lookup swiotlb_bounce() reads the page frame number from the slot's recorded orig_addr, then advances orig_addr by tlb_offset to reach the address the caller asked about. The highmem branch mixes the two: the offset within the page comes from the adjusted address, the page from the value before it. Once the adjustment crosses a page boundary the pair no longer describes one location, and the whole copy lands one page below the intended one for a positive tlb_offset, one above for a negative one. DMA_FROM_DEVICE writes the device data over the wrong page and leaves the intended one stale, DMA_TO_DEVICE feeds the device from a page the mapping may not cover. Partial syncs through dma_sync_single_range_for_*() are what make tlb_offset non-zero. The branch test is picked the same way, so a slot recorded in lowmem can be adjusted into highmem and the lowmem path then hands a highmem address to phys_to_virt(). Take both from orig_addr once it is final and keep pfn in the branch that uses it. PhysHighMem() asks the question straight from the address, as dma-debug already does.
CVE-2026-108654 2 Jeecg, Jeecgboot 3 Jeecg-boot, Jeecg Boot, Jeecgboot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the OssFileController queryById handler that allows low-privileged authenticated users to read object storage file records. Attackers who know a record id can request GET /sys/oss/file/queryById to obtain original file names and direct storage URLs of files uploaded by other users.
CVE-2026-108608 2 Jeecg, Jeecgboot 3 Jeecg-boot, Jeecg Boot, Jeecgboot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to delete other users' AI voice records by supplying an arbitrary userId to DELETE /airag/voice/deleteVoiceRecord. Attackers can obtain record ids from the unchecked GET /airag/voice/listByUser endpoint and delete victims' text-to-speech history entries stored in Redis, one per request.
CVE-2026-108651 2 Jeecg, Jeecgboot 3 Jeecg-boot, Jeecg Boot, Jeecgboot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the getRolesByUserId handler of SystemApiController that allows authenticated users to retrieve any user's role codes. Low-privileged attackers can supply arbitrary userId values to GET /sys/api/getRolesByUserId to enumerate role assignments and identify administrator accounts.
CVE-2026-108696 1 Coreshop 1 Coreshop 2026-10-11 4.3 Medium
CoreShop through 1.5.5 contains an authorization bypass vulnerability in the OrderController that allows authenticated customers to act on other customers' orders by supplying user-controlled ids. Attackers can omit the data field in OrderConfirm or supply another reshipId to SendReship to confirm receipt of others' orders and overwrite return tracking details.
CVE-2026-108694 1 C4illin 1 Convertx 2026-10-11 6.5 Medium
ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files because src/converters/pandoc.ts invokes Pandoc without the --sandbox flag. Attackers can upload a reStructuredText document with an include directive naming an absolute path, convert it, and download output containing the referenced file's contents.
CVE-2026-108653 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryPageList handler of OpenApiController that allows any authenticated user to list OpenAPI registry definitions. Low-privileged attackers can query GET /openapi/list to read virtual paths, internal origin URLs, IP whitelists, and header and parameter templates intended for administrators.
CVE-2026-108620 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController deleteBatch handler that allows any authenticated user to delete organizational positions. Low-privileged attackers can send comma-separated position ids, obtained from the unguarded list endpoint, to remove all sys_position rows and orphan user-position assignments.
CVE-2026-108629 2 Jeecg, Jeecgboot 3 Jeecg-boot, Jeecg Boot, Jeecgboot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDatarule handler of SysDepartPermissionController that allows any authenticated user to modify department data rules. Low-privileged attackers can send departId, permissionId and dataRuleIds to POST /sys/sysDepartPermission/datarule to change, add or clear data rules on any department-menu permission binding.
CVE-2026-108645 2 Jeecg, Jeecgboot 3 Jeecg-boot, Jeecg Boot, Jeecgboot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in SysCategoryController that allows any authenticated user to edit category dictionary nodes via /sys/category/edit. Low-privileged attackers can send POST or PUT requests supplying a node id to rename, recode, or move system-wide sys_category nodes, altering classification values used across forms.
CVE-2026-108649 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryUserRolesById handler of SystemApiController that lets authenticated users read any user's role codes. Low-privileged attackers can send a userId to GET /sys/api/queryUserRolesById to enumerate role assignments and identify administrator accounts.
CVE-2026-108650 2 Jeecg, Jeecgboot 3 Jeecg-boot, Jeecg Boot, Jeecgboot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the getUserPermissionSet handler of SystemApiController that allows any authenticated user to read other users' permission codes. Low-privileged attackers can supply an arbitrary userId to GET /sys/api/getUserPermissionSet to retrieve the full permission set of any account, including administrators.
CVE-2026-108656 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController GET /sys/tenant/getTenantPackApplyUsers endpoint that allows any authenticated user to read tenant administrator applications. Low-privileged attackers can iterate the tenantId parameter to retrieve pending applicants' usernames, real names, phone numbers and departments for any tenant.
CVE-2026-82049 1 Python 1 Cpython 2026-10-11 7.1 High
In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.
CVE-2026-108614 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController exportXls handler that allows any authenticated user to export AI evaluator data. Low-privileged attackers can request /airag/extData/exportXls to download every user's airag_ext_data evaluator definitions and test-tracking records as an Excel workbook.
CVE-2026-108616 2 Jeecg, Jeecgboot 3 Jeecg-boot, Jeecg Boot, Jeecgboot 2026-10-10 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController deleteBatch handler that allows any authenticated user to delete AI evaluator records. Low-privileged attackers can send comma-separated ids to DELETE /airag/extData/deleteBatch, which lacks owner or tenant checks, deleting other users' evaluator and test-tracking records.