Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-108869 — JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendSysAnnouncement

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to send system announcements by calling POST /sys/api/sendSysAnnouncement. Attack…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108868 — JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendBusTemplateAnnouncement

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to publish templated system announcements via POST /sys/api/sendBusTemplateAnnouncement. Low-…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108867 — JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserRoleSetById

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SystemApiController getUserRoleSetById handler that allows any authenticated user to read other users' role assignments. …

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108866 — JeecgBoot through 3.9.5 Missing Authorization via /sys/api/queryUserAuths

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows authenticated users to read any account's permissions via the queryUserAuths handler. Low-privileged attackers can s…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-108683 — zhayujie CowAgent Media Download memory allocation

A security vulnerability has been detected in zhayujie CowAgent up to 2.1.9. The impacted element is an unknown function of the component Media Download Handler. Such manipulation leads to uncontroll…

cowagent | Memory Corruption
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.8 HIGH
CVE-2026-108865 — AmoyLab Unla through 0.10.0 OAuth2 Authentication Bypass via /authorize

AmoyLab Unla through 0.10.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid access tokens because the OAuth2 server never authenticates a resourc…

Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.2 MEDIUM
CVE-2026-108864 — iFlytek Astron Agent through 1.1.2 Authorization Bypass via /workflow/v1/resume Endpoint

iFlytek Astron Agent through 1.1.2 contains an insecure direct object reference vulnerability that allows authenticated applications to resume other applications' paused workflows by supplying their …

astron-agent | Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.7 HIGH
CVE-2026-108863 — Katanemo Plano through 0.4.37 Missing Authentication on Envoy Admin Interface

Katanemo Plano through 0.4.37 contains a missing authentication vulnerability that allows unauthenticated network attackers to access the Envoy admin interface, which is bound to all host interfaces …

Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.0 MEDIUM
CVE-2026-108862 — APIPark through 1.9.7-beta IDOR via application authorization endpoints

APIPark through 1.9.7-beta contains an insecure direct object reference vulnerability that allows authenticated users to read other applications' credentials by supplying a foreign authorization UUID…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108861 — Odoo MCP 1.0.0 through 1.3.2 Information Disclosure via execute_method Tool

Odoo MCP 1.0.0 through 1.3.2 contains an information disclosure vulnerability that allows MCP clients to bypass the field-level ACL by invoking the execute_method tool. Attackers or prompt-injected a…

Remote | Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
9.3 CRITICAL
CVE-2026-108860 — BotSharp through 5.2.0 Authentication Bypass via Hard-Coded JWT Signing Key

BotSharp through 5.2.0 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to forge bearer tokens using the hard-coded Jwt:Key in WebStarter appsettings.json.…

Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.7 HIGH
CVE-2026-108859 — mcp-go through 1.2.1 Denial of Service via Unbounded POST Body Buffering

mcp-go through 1.2.1 contains a denial of service vulnerability in StreamableHTTPServer.ServeHTTP that allows remote unauthenticated attackers to exhaust memory by sending oversized POST bodies. Atta…

Remote | Denial of Service
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.8 MEDIUM
CVE-2026-108858 — Predibase LoRAX through 0.12.1 API Token Exposure via Router Logs

Predibase LoRAX through 0.12.1 contains a sensitive information exposure vulnerability that writes the caller-supplied api_token from POST /generate request bodies into router logs. Attackers with ac…

| Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.8 MEDIUM
CVE-2026-108857 — Hugging Face Text Embeddings Inference through 1.9.4 Cleartext API Key Logging

Hugging Face Text Embeddings Inference through 1.9.4 contains a cleartext logging vulnerability that exposes the configured api_key because the router's Args struct lacks a redact attribute for it. A…

| Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.2 MEDIUM
CVE-2026-108856 — UnicomAI Wanwu through 0.6.5 Authorization Bypass via /v1/appspace/app/key AppKey Minting

UnicomAI Wanwu through 0.6.5 contains an authorization bypass vulnerability that allows authenticated users to mint AppKeys bound to other users' MCP servers via POST /v1/appspace/app/key. Attackers …

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.4 MEDIUM
CVE-2026-108855 — UnicomAI Wanwu through 0.6.5 Missing Authorization via DELETE /v1/appspace/app/publish

UnicomAI Wanwu through 0.6.5 contains a missing authorization vulnerability that allows any authenticated enabled user to revoke other users' AppKeys for arbitrary apps via the unpublish endpoint. At…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.4 MEDIUM
CVE-2026-108854 — Wanwu before 0.6.3 IDOR AppKey Deletion via DELETE /v1/appspace/app/key

Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows any authenticated enabled user to delete other users' legacy AppKeys by supplying a numeric apiId. Attackers …

Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.1 HIGH
CVE-2026-108853 — UnicomAI Wanwu before 0.6.3 IDOR via DELETE /v1/appspace/app

UnicomAI Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows authenticated low-privileged users to delete other tenants' agent or RAG applications by supplying t…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.7 MEDIUM
CVE-2026-108852 — Deep Chat through 2.5.1 XSS via Markdown Link Validation Bypass

Deep Chat through 2.5.1 contains a cross-site scripting vulnerability that allows attackers to inject javascript: links because RemarkableConfig.createNew disables Remarkable link validation. Attacke…

deepchat | Remote | Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.8 MEDIUM
CVE-2026-108851 — phpMyFAQ through 4.1.10 Missing Authorization via MCP Server faq_search Tool

phpMyFAQ through 4.1.10 contains a missing authorization vulnerability in the MCP server faq_search tool that allows MCP clients to read restricted FAQs because Search::searchDatabase() never applies…

phpmyfaq | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
Showing 20 of 14207 Results