Export limit exceeded: 404439 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 404439 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404439 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-107835 | 1 Coraza | 1 Coraza | 2026-10-11 | 4 Medium |
| OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.8.1, internal/cookies.ParseCookies in internal/cookies/cookies.go handles boundary ASCII control characters and control-only or empty cookie names differently from several backend cookie parsers. An unauthenticated attacker can craft a Cookie header so Coraza indexes or drops a cookie under a different name or value from the backend application, causing rules targeting REQUEST_COOKIES or REQUEST_COOKIES_NAMES to miss application-visible attacker data. Exploitation depends on the backend parser and affected rule scope, and interior control characters with inconsistent backend behavior are outside this advisory's remediation. This issue is fixed in version 3.8.1. | ||||
| CVE-2026-108575 | 1 Litellm | 1 Litellm | 2026-10-11 | 6.3 Medium |
| A vulnerability has been found in BerriAI LiteLLM up to 1.94.0. This affects the function get_secret of the file secret_managers/main.py of the component Secret Resolution. The manipulation of the argument api_key leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-106138 | 1 Progress | 1 Kendoreact | 2026-10-11 | 5.4 Medium |
| In Progress® KendoReact (@progress/kendo-react-charts) starting with version 1.1.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application. | ||||
| CVE-2026-106139 | 1 Progress | 1 Kendo Ui For Vue | 2026-10-11 | 5.4 Medium |
| In Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application. | ||||
| CVE-2026-108605 | 1 Jeecg | 2 Jeecg Boot, Jeecgboot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController updateById handler that allows any authenticated user to modify global OCR templates. Low-privileged attackers can send PUT requests to /airag/ocr/edit to overwrite LLM prompts in the shared airag:ocr Redis key, corrupting OCR results for all users. | ||||
| CVE-2026-108607 | 1 Jeecg | 2 Jeecg Boot, Jeecgboot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to delete other users' AI video generation records by supplying arbitrary userId values to DELETE /airag/video/deleteVideoRecord. Attackers can obtain record ids from the unchecked GET /airag/video/listByUser endpoint and delete victims' Redis-stored video history entries one record per request. | ||||
| CVE-2026-108618 | 1 Jeecg | 2 Jeecg Boot, Jeecgboot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to modify message templates via PUT /sys/message/sysMessageTemplate/edit. Attackers can obtain template ids from the unguarded list endpoint and overwrite system notification titles and content, delivering attacker-supplied text or links to other users. | ||||
| CVE-2026-108619 | 1 Jeecg | 2 Jeecg Boot, Jeecgboot | 2026-10-11 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to delete message templates via the DELETE /sys/message/sysMessageTemplate/deleteBatch endpoint. Attackers can supply comma-separated template ids from the unguarded list endpoint to delete all sys_sms_template rows, breaking template-based notifications such as workflow reminders. | ||||
| CVE-2026-108623 | 1 Jeecg | 2 Jeecg Boot, Jeecgboot | 2026-10-11 | 7.1 High |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysLogController deleteBatch handler that allows any authenticated user to delete system audit log entries. Low-privileged attackers can send a DELETE request with ids set to allclear to wipe the entire sys_log table, erasing all users' audit trails. | ||||
| CVE-2026-108624 | 1 Jeecg | 2 Jeecg Boot, Jeecgboot | 2026-10-11 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController deleteBatch handler that allows low-privileged authenticated users to delete message records. Attackers can obtain record ids from the unguarded list endpoint and submit them to deleteBatch to remove any message push records, including pending queued messages. | ||||
| CVE-2026-108628 | 1 Jeecg | 2 Jeecg Boot, Jeecgboot | 2026-10-11 | 8.1 High |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDeptRolePermission endpoint of SysDepartPermissionController that allows any authenticated user to modify department role permissions. Low-privileged attackers can submit roleId and permissionIds values to grant arbitrary menu or button permissions, escalating privileges or revoking other users' permissions. | ||||
| CVE-2026-108631 | 1 Jeecg | 2 Jeecg Boot, Jeecgboot | 2026-10-11 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartPermissionController delete handler that allows low-privileged authenticated users to delete department permission bindings. Attackers can obtain row ids from the unguarded list endpoint and send DELETE requests with the id parameter to remove menus or buttons departments can grant their roles. | ||||
| CVE-2026-108632 | 1 Jeecg | 2 Jeecg Boot, Jeecgboot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartPermissionController queryById handler that allows any authenticated user to read department permission records. Low-privileged attackers can request GET /sys/sysDepartPermission/queryById with arbitrary ids to retrieve depart_id, permission_id and data_rule_ids for any department. | ||||
| CVE-2026-108635 | 1 Jeecg | 2 Jeecg Boot, Jeecgboot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the GET /sys/sysDepart/getDepartmentHead endpoint of SysDepartController that allows any authenticated user to list department staff. Low-privileged attackers can enumerate departId values to retrieve staff names, avatars, posts, and mobile and telephone numbers, including contacts marked hidden. | ||||
| CVE-2026-108640 | 1 Jeecg | 2 Jeecg Boot, Jeecgboot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartRoleController queryById handler that lacks Shiro permission annotations. Low-privileged authenticated attackers can request GET /sys/sysDepartRole/queryById with any id to read department role names, codes, descriptions and audit fields. | ||||
| CVE-2026-108643 | 1 Jeecg | 2 Jeecg Boot, Jeecgboot | 2026-10-11 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to delete category dictionary entries via DELETE /sys/category/deleteBatch. Attackers can obtain node ids from the unguarded rootList and childList endpoints and submit them to recursively delete entire sys_category subtrees, breaking dependent forms and dictionary fields. | ||||
| CVE-2026-108644 | 1 Jeecg | 2 Jeecg Boot, Jeecgboot | 2026-10-11 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCategoryController delete handler that allows any authenticated user to delete category dictionary nodes. Low-privileged attackers can obtain node ids from the unguarded rootList and childList endpoints and delete entire sys_category subtrees, breaking dependent forms and dictionary fields. | ||||
| CVE-2026-108646 | 1 Jeecg | 2 Jeecg Boot, Jeecgboot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCategoryController importExcel handler that allows any authenticated user to import category dictionary entries. Low-privileged attackers can upload crafted Excel workbooks to bulk insert arbitrary nodes into the system-wide sys_category dictionary, including under existing parent nodes. | ||||
| CVE-2026-108648 | 1 Jeecg | 2 Jeecg Boot, Jeecgboot | 2026-10-11 | 6.5 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the GET /sys/api/getDynamicDbSourceByCode endpoint of SystemApiController, which lacks Shiro permission or role annotations. Any authenticated low-privileged user can supply datasource codes in the dbSourceCode parameter to retrieve JDBC URLs, usernames and decrypted cleartext database passwords. | ||||
| CVE-2026-108652 | 1 Jeecg | 2 Jeecg Boot, Jeecgboot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SystemApiController updateAvatar handler that allows any authenticated user to change other users' avatars. Low-privileged attackers can send PUT requests with a target user id and an arbitrary value, such as an attacker-controlled image URL, to replace administrators' avatars. | ||||