Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-108913 — Omarchy Arbitrary Code Execution Vulnerability

omarchy-theme-set in Omarchy 4 before 4.0.1 allows code execution via a third-party theme because the files placed into ~/.local/state/omarchy/current/theme may include executable content from an unt…

Remote | Supply Chain
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-107761 — Channel tokens and organization API key exposed in API responses

Several Postiz endpoints return the complete database row of the record they operate on instead of only the fields the client needs. Two of them include secrets the caller is not meant to receive. T…

postiz | Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.7 HIGH
CVE-2026-108905 — pH7Builder before 18.6.0 Hard-Coded API Key Bypass via Host Header

pH7Builder (pH7 Social Dating CMS) before 18.6.0 contains a hard-coded API key vulnerability in Tool.class.php that allows unauthenticated attackers to bypass API access checks by spoofing the Host h…

Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.1 HIGH
CVE-2026-108904 — pH7Builder before 18.5.0 Sensitive Data Exposure via Member API UserController

pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an information disclosure vulnerability that allows API clients to obtain sensitive member data because UserController::users() and user() re…

Remote | Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.9 MEDIUM
CVE-2026-108903 — pH7Builder before 19.3.0 CAPTCHA Bypass via Client-Chosen Form ID

pH7Builder (pH7 Social Dating CMS) before 19.3.0 contains a CAPTCHA bypass vulnerability that allows unauthenticated attackers to skip form validation by supplying a client-chosen form ID to PFBC For…

Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.1 HIGH
CVE-2026-108902 — pH7Builder before 18.5.0 Path Traversal Arbitrary File Deletion via picture_link

pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains a path traversal vulnerability in the picture module deletePhoto() action that allows authenticated members to delete arbitrary files. Attack…

Remote | Path Traversal
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108891 — JeecgBoot through 3.9.5 Missing Authorization via /sys/user/getUserDetailByUserId

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController getUserDetailByUserId handler that allows any authenticated user to read other users' details. Low-priv…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108888 — JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartRole/exportXls

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartRoleController exportXls handler that allows any authenticated user to export department roles. Low-privileged a…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108887 — JeecgBoot through 3.9.5 Missing Authorization via /sys/comment/exportXls

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCommentController exportXls handler that allows any authenticated user to export all comments. Low-privileged attacker…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108886 — JeecgBoot through 3.9.5 Missing Authorization via /sys/user/queryChildrenByUsername

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController queryChildrenByUsername handler that allows any authenticated user to retrieve other users' account rec…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.4 MEDIUM
CVE-2026-108885 — JeecgBoot through 3.9.5 Missing Authorization via /sys/message/sysMessage/delete

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController delete handler that allows low-privileged authenticated users to delete message records. Attackers c…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.4 MEDIUM
CVE-2026-108884 — JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate Delete Endpoint

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageTemplateController delete handler that allows any authenticated user to delete message templates. Low-privilege…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.1 HIGH
CVE-2026-108883 — JeecgBoot through 3.9.5 Missing Authorization via /sys/thirdApp/editThirdAppConfig

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the editThirdAppConfig handler that allows any authenticated user to modify third-party application configurations. Low-privi…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.4 MEDIUM
CVE-2026-108882 — JeecgBoot through 3.9.5 Missing Authorization via /sys/position/removePositionUser

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController removeUserPosition handler that allows any authenticated user to remove position members. Low-privi…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108881 — JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/getTenantPackInfo

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the getTenantPackInfo handler that allows any authenticated user to read other tenants' product pack membership. Low-privileg…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108880 — JeecgBoot through 3.9.5 Missing Authorization via /sys/dict/editDictByLowAppId

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the PUT /sys/dict/editDictByLowAppId endpoint that allows any authenticated user to modify low-code application dictionaries.…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108879 — JeecgBoot through 3.9.5 IDOR via /airag/api/getChatVariable Username Parameter

JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability in AiragBaseApiController that allows authenticated users to read other users' AI chat variables via the username pa…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108878 — JeecgBoot through 3.9.5 Missing Authorization via /airag/app/queryById

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragAppController queryById handler that allows low-privileged authenticated users to read any AI application configurat…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.4 MEDIUM
CVE-2026-108877 — JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/delete

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in AiragPromptsController that allows any authenticated user to delete AI prompt templates by calling DELETE /airag/prompts/dele…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108876 — JeecgBoot through 3.9.5 Missing Authorization via /sys/user/putCancelQuit

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the putCancelQuit handler of SysUserController, allowing any authenticated user to cancel user resignations. Low-privileged a…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
Showing 20 of 14179 Results