Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-108620 — JeecgBoot through 3.9.5 Missing Authorization via /sys/position/deleteBatch

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController deleteBatch handler that allows any authenticated user to delete organizational positions. Low-priv…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-108619 — JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate deleteBatch Endpoint

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to delete message templates via the DELETE /sys/message/sysMessageTemplate/delete…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108618 — JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate Edit Endpoint

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to modify message templates via PUT /sys/message/sysMessageTemplate/edit. Attacke…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108617 — JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate/add Endpoint

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to create message templates by calling POST /sys/message/sysMessageTemplate/add. …

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-108616 — JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/deleteBatch

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController deleteBatch handler that allows any authenticated user to delete AI evaluator records. Low-privile…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-108615 — JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/delete

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController delete handler that allows low-privileged authenticated users to delete AI evaluator records. Atta…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108614 — JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/exportXls

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController exportXls handler that allows any authenticated user to export AI evaluator data. Low-privileged a…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-108613 — JeecgBoot through 3.9.5 Missing Authorization via /airag/app/release Endpoint

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragAppController release handler that allows any authenticated user to publish or unpublish other users' AI application…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-108612 — JeecgBoot through 3.9.5 Missing Authorization via /airag/word/deleteBatch

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AigcWordTemplateController deleteBatch handler that allows low-privileged authenticated users to delete word templates. A…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-108611 — JeecgBoot through 3.9.5 Missing Authorization via /airag/word/delete Endpoint

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AigcWordTemplateController delete handler that allows any authenticated user to delete word templates. Low-privileged att…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108610 — JeecgBoot through 3.9.5 Missing Authorization via /airag/word/edit Endpoint

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AigcWordTemplateController edit handler that allows any authenticated user to modify word templates. Low-privileged attac…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108609 — JeecgBoot through 3.9.5 IDOR via /airag/voice/listByUser userId Parameter

JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to read other users' AI voice generation history via the userId parameter of GET /ai…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108608 — JeecgBoot through 3.9.5 IDOR via deleteVoiceRecord userId Parameter

JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to delete other users' AI voice records by supplying an arbitrary userId to DELETE /…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108607 — JeecgBoot through 3.9.5 IDOR via deleteVideoRecord userId Parameter

JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to delete other users' AI video generation records by supplying arbitrary userId val…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-108606 — JeecgBoot through 3.9.5 Missing Authorization via /airag/ocr/deleteById

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController deleteById handler that allows any authenticated user to delete OCR records. Low-privileged attackers can…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108605 — JeecgBoot through 3.9.5 Missing Authorization via /airag/ocr/edit Endpoint

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController updateById handler that allows any authenticated user to modify global OCR templates. Low-privileged atta…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.9 MEDIUM
CVE-2026-97853 — Unbounded allocation in decimal Decimal.round/3 driven by the places argument enables DoS

Memory Allocation with Excessive Size Value vulnerability in ericmj decimal allows Denial of Service. Decimal.round/3 builds the full result for the requested number of decimal places before the con…

decimal | Denial of Service
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-81797 — WordPress Buzz Stone | Magazine & Viral Blog WordPress Theme theme <= 1.0.2 - PHP Object …

Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme <= 1.0.2 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-78535 — WordPress Photolia theme <= 1.0.3 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-78534 — WordPress Educavo theme <= 3.4.2 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Educavo <= 3.4.2 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Showing 20 of 14137 Results