Latest CVE Feed
Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to assign or remove department heads by calling PUT /sys/user/changeDepartChargePerson. Low-p…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to modify any department by calling PUT /sys/user/doUpdateDepartInfo. Attackers c…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the batchEditUsers handler of SysUserController that allows any authenticated user to edit user department assignments. Low-p…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDatarule handler of SysDepartRoleController that lets low-privileged authenticated users modify department role data …
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysRoleController saveDatarule handler that allows low-privileged authenticated users to modify role data rules. Attacker…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to send system announcements by calling POST /sys/api/sendSysAnnouncement. Attack…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to publish templated system announcements via POST /sys/api/sendBusTemplateAnnouncement. Low-…
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SystemApiController getUserRoleSetById handler that allows any authenticated user to read other users' role assignments. …
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows authenticated users to read any account's permissions via the queryUserAuths handler. Low-privileged attackers can s…
A security vulnerability has been detected in zhayujie CowAgent up to 2.1.9. The impacted element is an unknown function of the component Media Download Handler. Such manipulation leads to uncontroll…
AmoyLab Unla through 0.10.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid access tokens because the OAuth2 server never authenticates a resourc…
iFlytek Astron Agent through 1.1.2 contains an insecure direct object reference vulnerability that allows authenticated applications to resume other applications' paused workflows by supplying their …
Katanemo Plano through 0.4.37 contains a missing authentication vulnerability that allows unauthenticated network attackers to access the Envoy admin interface, which is bound to all host interfaces …
APIPark through 1.9.7-beta contains an insecure direct object reference vulnerability that allows authenticated users to read other applications' credentials by supplying a foreign authorization UUID…
Odoo MCP 1.0.0 through 1.3.2 contains an information disclosure vulnerability that allows MCP clients to bypass the field-level ACL by invoking the execute_method tool. Attackers or prompt-injected a…
BotSharp through 5.2.0 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to forge bearer tokens using the hard-coded Jwt:Key in WebStarter appsettings.json.…
mcp-go through 1.2.1 contains a denial of service vulnerability in StreamableHTTPServer.ServeHTTP that allows remote unauthenticated attackers to exhaust memory by sending oversized POST bodies. Atta…
Predibase LoRAX through 0.12.1 contains a sensitive information exposure vulnerability that writes the caller-supplied api_token from POST /generate request bodies into router logs. Attackers with ac…
Hugging Face Text Embeddings Inference through 1.9.4 contains a cleartext logging vulnerability that exposes the configured api_key because the router's Args struct lacks a redact attribute for it. A…
UnicomAI Wanwu through 0.6.5 contains an authorization bypass vulnerability that allows authenticated users to mint AppKeys bound to other users' MCP servers via POST /v1/appspace/app/key. Attackers …