Latest CVE Feed
Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.
omarchy-theme-set in Omarchy 4 before 4.0.1 allows code execution via a third-party theme because the files placed into ~/.local/state/omarchy/current/theme may include executable content from an unt…
Several Postiz endpoints return the complete database row of the record they operate on instead of only the fields the client needs. Two of them include secrets the caller is not meant to receive. T…
pH7Builder (pH7 Social Dating CMS) before 18.6.0 contains a hard-coded API key vulnerability in Tool.class.php that allows unauthenticated attackers to bypass API access checks by spoofing the Host h…
pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an information disclosure vulnerability that allows API clients to obtain sensitive member data because UserController::users() and user() re…
pH7Builder (pH7 Social Dating CMS) before 19.3.0 contains a CAPTCHA bypass vulnerability that allows unauthenticated attackers to skip form validation by supplying a client-chosen form ID to PFBC For…
pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains a path traversal vulnerability in the picture module deletePhoto() action that allows authenticated members to delete arbitrary files. Attack…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController getUserDetailByUserId handler that allows any authenticated user to read other users' details. Low-priv…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartRoleController exportXls handler that allows any authenticated user to export department roles. Low-privileged a…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCommentController exportXls handler that allows any authenticated user to export all comments. Low-privileged attacker…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController queryChildrenByUsername handler that allows any authenticated user to retrieve other users' account rec…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController delete handler that allows low-privileged authenticated users to delete message records. Attackers c…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageTemplateController delete handler that allows any authenticated user to delete message templates. Low-privilege…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the editThirdAppConfig handler that allows any authenticated user to modify third-party application configurations. Low-privi…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController removeUserPosition handler that allows any authenticated user to remove position members. Low-privi…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the getTenantPackInfo handler that allows any authenticated user to read other tenants' product pack membership. Low-privileg…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the PUT /sys/dict/editDictByLowAppId endpoint that allows any authenticated user to modify low-code application dictionaries.…
JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability in AiragBaseApiController that allows authenticated users to read other users' AI chat variables via the username pa…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragAppController queryById handler that allows low-privileged authenticated users to read any AI application configurat…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in AiragPromptsController that allows any authenticated user to delete AI prompt templates by calling DELETE /airag/prompts/dele…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the putCancelQuit handler of SysUserController, allowing any authenticated user to cancel user resignations. Low-privileged a…