Export limit exceeded: 404240 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (404240 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-108663 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController deleteApply handler that allows any authenticated user to reject tenant administrator applications. Low-privileged attackers can send PUT requests with chosen tenantId, packId and userId values to delete pending applications in any tenant and notify applicants of rejection.
CVE-2026-108660 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to modify tenant settings by calling PUT /sys/tenant/updateApplyStatus. Low-privileged attackers can supply any tenant id to overwrite its applyStatus field, enabling or disabling tenant administrator applications across tenants.
CVE-2026-108659 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController listPackByTenantUserId handler that allows any authenticated user to query tenant product packs. Low-privileged attackers can supply arbitrary tenantId and userId parameters to enumerate any tenant's product pack configuration and reveal which users are tenant administrators.
CVE-2026-108657 1 Jeecg 1 Jeecg Boot 2026-10-10 8.1 High
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController passApply handler that allows any authenticated user to approve tenant administrator applications. Attackers can file a pending application via doApplyTenantPackUser and approve it through PUT /sys/tenant/passApply to gain tenant administrator pack permissions in any tenant.
CVE-2026-108655 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the QuartzJobController queryById handler that allows low-privileged authenticated users to read scheduled job records. Attackers can request GET /sys/quartzJob/queryById with a job id to retrieve job class names, cron expressions, job parameters and status reserved for administrators.
CVE-2026-108652 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SystemApiController updateAvatar handler that allows any authenticated user to change other users' avatars. Low-privileged attackers can send PUT requests with a target user id and an arbitrary value, such as an attacker-controlled image URL, to replace administrators' avatars.
CVE-2026-108648 1 Jeecg 1 Jeecg Boot 2026-10-10 6.5 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the GET /sys/api/getDynamicDbSourceByCode endpoint of SystemApiController, which lacks Shiro permission or role annotations. Any authenticated low-privileged user can supply datasource codes in the dbSourceCode parameter to retrieve JDBC URLs, usernames and decrypted cleartext database passwords.
CVE-2026-108646 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCategoryController importExcel handler that allows any authenticated user to import category dictionary entries. Low-privileged attackers can upload crafted Excel workbooks to bulk insert arbitrary nodes into the system-wide sys_category dictionary, including under existing parent nodes.
CVE-2026-108644 1 Jeecg 1 Jeecg Boot 2026-10-10 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCategoryController delete handler that allows any authenticated user to delete category dictionary nodes. Low-privileged attackers can obtain node ids from the unguarded rootList and childList endpoints and delete entire sys_category subtrees, breaking dependent forms and dictionary fields.
CVE-2026-108643 1 Jeecg 1 Jeecg Boot 2026-10-10 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to delete category dictionary entries via DELETE /sys/category/deleteBatch. Attackers can obtain node ids from the unguarded rootList and childList endpoints and submit them to recursively delete entire sys_category subtrees, breaking dependent forms and dictionary fields.
CVE-2026-108640 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartRoleController queryById handler that lacks Shiro permission annotations. Low-privileged authenticated attackers can request GET /sys/sysDepartRole/queryById with any id to read department role names, codes, descriptions and audit fields.
CVE-2026-108639 1 Jeecg 1 Jeecg Boot 2026-10-10 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to permanently delete data dictionaries via the deletePhysic handler of SysDictController. Low-privileged attackers can send DELETE requests to /sys/dict/deletePhysic/{id} to irreversibly remove active dictionaries and all their items, bypassing the recycle bin.
CVE-2026-108638 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to remove group memberships via the deleteGroupUser handler in SysUserController. Attackers can send DELETE requests with arbitrary groupId and userId values to remove any user from any administrator-maintained user group without ownership or tenant checks.
CVE-2026-108635 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the GET /sys/sysDepart/getDepartmentHead endpoint of SysDepartController that allows any authenticated user to list department staff. Low-privileged attackers can enumerate departId values to retrieve staff names, avatars, posts, and mobile and telephone numbers, including contacts marked hidden.
CVE-2026-108633 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to create department permission bindings via POST /sys/sysDepartPermission/add. Attackers can submit arbitrary departId, permissionId and dataRuleIds fields to attach menu, button and data rule grants to any department for delegation to its roles.
CVE-2026-108632 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartPermissionController queryById handler that allows any authenticated user to read department permission records. Low-privileged attackers can request GET /sys/sysDepartPermission/queryById with arbitrary ids to retrieve depart_id, permission_id and data_rule_ids for any department.
CVE-2026-108631 1 Jeecg 1 Jeecg Boot 2026-10-10 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartPermissionController delete handler that allows low-privileged authenticated users to delete department permission bindings. Attackers can obtain row ids from the unguarded list endpoint and send DELETE requests with the id parameter to remove menus or buttons departments can grant their roles.
CVE-2026-108630 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in SysDepartPermissionController that allows any authenticated user to modify department permission records by calling the edit endpoint. Low-privileged attackers can obtain row ids from the unguarded list endpoint and overwrite depart_id, permission_id and data_rule_ids to alter which menus and data rules departments may delegate.
CVE-2026-108628 1 Jeecg 1 Jeecg Boot 2026-10-10 8.1 High
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDeptRolePermission endpoint of SysDepartPermissionController that allows any authenticated user to modify department role permissions. Low-privileged attackers can submit roleId and permissionIds values to grant arbitrary menu or button permissions, escalating privileges or revoking other users' permissions.
CVE-2026-108626 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController queryById handler that allows low-privileged authenticated users to read any message push record. Attackers can supply arbitrary record ids to GET /sys/message/sysMessage/queryById to disclose message content and receiver addresses of other users.