Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-108660 — JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/updateApplyStatus

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to modify tenant settings by calling PUT /sys/tenant/updateApplyStatus. Low-privileged attack…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108659 — JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/listPackByTenantUserId

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController listPackByTenantUserId handler that allows any authenticated user to query tenant product packs. Low-…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108658 — JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/queryTenantAuthInfo

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController queryTenantAuthInfo handler that allows any authenticated user to read other tenants' records. Low-pr…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.6 HIGH
CVE-2026-108657 — JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/passApply

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController passApply handler that allows any authenticated user to approve tenant administrator applications. At…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108656 — JeecgBoot through 3.9.5 Missing Authorization via getTenantPackApplyUsers Endpoint

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController GET /sys/tenant/getTenantPackApplyUsers endpoint that allows any authenticated user to read tenant ad…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108655 — JeecgBoot through 3.9.5 Missing Authorization via /sys/quartzJob/queryById

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the QuartzJobController queryById handler that allows low-privileged authenticated users to read scheduled job records. Attac…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108654 — JeecgBoot through 3.9.5 Missing Authorization via /sys/oss/file/queryById

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the OssFileController queryById handler that allows low-privileged authenticated users to read object storage file records. A…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108653 — JeecgBoot through 3.9.5 Missing Authorization via GET /openapi/list

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryPageList handler of OpenApiController that allows any authenticated user to list OpenAPI registry definitions. Low-p…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108652 — JeecgBoot through 3.9.5 Missing Authorization via /sys/api/updateAvatar

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SystemApiController updateAvatar handler that allows any authenticated user to change other users' avatars. Low-privilege…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108651 — JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getRolesByUserId

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the getRolesByUserId handler of SystemApiController that allows authenticated users to retrieve any user's role codes. Low-pr…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108650 — JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserPermissionSet

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the getUserPermissionSet handler of SystemApiController that allows any authenticated user to read other users' permission co…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108649 — JeecgBoot through 3.9.5 Missing Authorization via /sys/api/queryUserRolesById

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryUserRolesById handler of SystemApiController that lets authenticated users read any user's role codes. Low-privilege…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-108648 — JeecgBoot through 3.9.5 Missing Authorization via getDynamicDbSourceByCode Endpoint

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the GET /sys/api/getDynamicDbSourceByCode endpoint of SystemApiController, which lacks Shiro permission or role annotations. …

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108647 — JeecgBoot through 3.9.5 Missing Authorization via /sys/checkRule/importExcel

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to create validation rules through the SysCheckRuleController importExcel handler…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108646 — JeecgBoot through 3.9.5 Missing Authorization via /sys/category/importExcel

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCategoryController importExcel handler that allows any authenticated user to import category dictionary entries. Low-p…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108645 — JeecgBoot through 3.9.5 Missing Authorization via /sys/category/edit

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in SysCategoryController that allows any authenticated user to edit category dictionary nodes via /sys/category/edit. Low-privil…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-108644 — JeecgBoot through 3.9.5 Missing Authorization via /sys/category/delete

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCategoryController delete handler that allows any authenticated user to delete category dictionary nodes. Low-privileg…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-108643 — JeecgBoot through 3.9.5 Missing Authorization via /sys/category/deleteBatch

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to delete category dictionary entries via DELETE /sys/category/deleteBatch. Attac…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108642 — JeecgBoot through 3.9.5 IDOR via PUT /sys/sysAnnouncementSend/edit

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in SysAnnouncementSendController that allows authenticated users to modify other users' message delivery records. Attackers can …

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108641 — JeecgBoot through 3.9.5 IDOR via /sys/sysAnnouncementSend/getOne

JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to read other users' in-application messages via the getOne handler of SysAnnounceme…

jeecg_boot | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Showing 20 of 14131 Results