Export limit exceeded: 24494 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 404328 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404328 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-89302 | 2026-10-11 | 8.6 High | ||
| The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-108732 | 1 Frappe | 2 Frappe Hr, Hrms | 2026-10-11 | 4.3 Medium |
| Frappe HR (hrms) before 16.11.0, including all 14.x and 15.x releases through 15.64.3, contains a missing authorization vulnerability in the whitelisted get_account_and_amount method that lets authenticated users read payroll amounts. Attackers without HR roles can call the method over /api/method with enumerable Salary Slip or claim document names to disclose other employees' net pay and loan, advance, and claim balances. | ||||
| CVE-2026-108859 | 1 Mark3labs | 1 Mcp-go | 2026-10-11 | 7.5 High |
| mcp-go through 1.2.1 contains a denial of service vulnerability in StreamableHTTPServer.ServeHTTP that allows remote unauthenticated attackers to exhaust memory by sending oversized POST bodies. Attackers can send arbitrarily large or many concurrent POST requests, read fully via io.ReadAll before validation, to degrade or OOM-kill the server process. | ||||
| CVE-2026-108864 | 1 Iflytek | 1 Astron-agent | 2026-10-11 | 4.2 Medium |
| iFlytek Astron Agent through 1.1.2 contains an insecure direct object reference vulnerability that allows authenticated applications to resume other applications' paused workflows by supplying their event_id to POST /workflow/v1/resume. Attackers can predict Snowflake event IDs to inject resume content into victim workflows and read their continuation output stream, breaking cross-tenant isolation. | ||||
| CVE-2026-108891 | 1 Jeecg | 1 Jeecg Boot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController getUserDetailByUserId handler that allows any authenticated user to read other users' details. Low-privileged attackers can supply arbitrary userId values to retrieve real names, usernames, emails, phone numbers, birthdays, employee numbers, department paths and posts. | ||||
| CVE-2026-108888 | 1 Jeecg | 1 Jeecg Boot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartRoleController exportXls handler that allows any authenticated user to export department roles. Low-privileged attackers holding only the default minimal role can call /sys/sysDepartRole/exportXls to download all sys_depart_role records, including role names, codes, descriptions and creating users. | ||||
| CVE-2026-108884 | 1 Jeecg | 1 Jeecg Boot | 2026-10-11 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageTemplateController delete handler that allows any authenticated user to delete message templates. Low-privileged attackers can obtain template ids from the unguarded list endpoint and delete shipped notification templates, causing system notices and workflow reminders to fail. | ||||
| CVE-2026-108883 | 1 Jeecg | 1 Jeecg Boot | 2026-10-11 | 6.5 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the editThirdAppConfig handler that allows any authenticated user to modify third-party application configurations. Low-privileged attackers can replace client id, client secret, agent id and corp id of DingTalk, WeCom or Feishu integrations to redirect directory synchronisation and messaging to attacker-controlled applications or break them. | ||||
| CVE-2026-108882 | 1 Jeecg | 1 Jeecg Boot | 2026-10-11 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController removeUserPosition handler that allows any authenticated user to remove position members. Low-privileged attackers can send DELETE requests with arbitrary userIds and positionId values to delete sys_user_position rows, detaching users from positions without logging. | ||||
| CVE-2026-108878 | 1 Jeecg | 1 Jeecg Boot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragAppController queryById handler that allows low-privileged authenticated users to read any AI application configuration. Attackers can enumerate application ids via the unguarded /airag/app/listDict endpoint and query each id to obtain system prompts, memory prompts, model ids, knowledge base ids, and plugin bindings of other users' applications. | ||||
| CVE-2026-108876 | 1 Jeecg | 1 Jeecg Boot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the putCancelQuit handler of SysUserController, allowing any authenticated user to cancel user resignations. Low-privileged attackers can supply user ids and a tenantId parameter or X-Tenant-Id header to restore ended, pending, or refused tenant memberships to normal. | ||||
| CVE-2026-108875 | 1 Jeecg | 1 Jeecg Boot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController addSysUserGroup handler that allows any authenticated user to modify user group membership. Low-privileged attackers can send POST requests with arbitrary user ids and a groupId to add any users to administrator-maintained groups without permission checks. | ||||
| CVE-2026-108874 | 1 Jeecg | 1 Jeecg Boot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to assign or remove department heads by calling PUT /sys/user/changeDepartChargePerson. Low-privileged attackers can supply arbitrary userId, department id, and status values to make any user a department head, widening department-scoped views, or demote existing heads. | ||||
| CVE-2026-108868 | 1 Jeecg | 1 Jeecg Boot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to publish templated system announcements via POST /sys/api/sendBusTemplateAnnouncement. Low-privileged attackers can supply templateCode, toUser, and a forged fromUser to send notifications to arbitrary users through WebSocket, DingTalk, WeCom, Feishu and UniPush channels. | ||||
| CVE-2026-108867 | 1 Jeecg | 1 Jeecg Boot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SystemApiController getUserRoleSetById handler that allows any authenticated user to read other users' role assignments. Low-privileged attackers can supply an arbitrary userId parameter to retrieve assigned role codes and identify administrator accounts without the system:user:queryUserRole permission. | ||||
| CVE-2026-108683 | 1 Zhayujie | 1 Cowagent | 2026-10-11 | 4.3 Medium |
| A security vulnerability has been detected in zhayujie CowAgent up to 2.1.9. The impacted element is an unknown function of the component Media Download Handler. Such manipulation leads to uncontrolled memory allocation. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.2.0 is sufficient to resolve this issue. The name of the patch is b7967210268fc4c0afea1078223e74e7e96a8a54. You should upgrade the affected component. | ||||
| CVE-2026-85118 | 2026-10-11 | 9.8 Critical | ||
| The AI Content Generator Marketing WordPress plugin through 1.0.0 does not enforce a nonce or capability check on some of its AJAX actions, allowing unauthenticated users to update and delete arbitrary WordPress options, which can be used to gain administrator access to the site. | ||||
| CVE-2026-108682 | 1 Zhayujie | 1 Cowagent | 2026-10-11 | 5.4 Medium |
| A weakness has been identified in zhayujie CowAgent up to 2.1.6. The affected element is the function read of the file /upload of the component Web Console. This manipulation causes denial of service. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-108747 | 1 Lightdash | 1 Lightdash | 2026-10-11 | 4.2 Medium |
| Lightdash through 2.556.0 contains an authorization bypass vulnerability that allows authenticated organization members to delete other users' personal access tokens by supplying their UUID. Attackers can send DELETE requests to the personal-access-tokens route with a victim's token UUID, even across organizations, to revoke it and break API integrations. | ||||
| CVE-2026-108752 | 2 Jupyter, Jupyterhub | 2 Jupyterhub, Jupyterhub | 2026-10-11 | 4.2 Medium |
| JupyterHub through 6.0.1 contains an identifier collision vulnerability that allows authenticated users to overwrite another user's named-server OAuth client by registering a hyphenated username. Attackers holding a name like alice-prod can overwrite the client for alice's server prod, breaking OAuth login and revoking tokens by stopping their own server. | ||||