Export limit exceeded: 404235 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404235 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-108639 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to permanently delete data dictionaries via the deletePhysic handler of SysDictController. Low-privileged attackers can send DELETE requests to /sys/dict/deletePhysic/{id} to irreversibly remove active dictionaries and all their items, bypassing the recycle bin. | ||||
| CVE-2026-108638 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to remove group memberships via the deleteGroupUser handler in SysUserController. Attackers can send DELETE requests with arbitrary groupId and userId values to remove any user from any administrator-maintained user group without ownership or tenant checks. | ||||
| CVE-2026-108637 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to remove user group members by calling DELETE /sys/user/deleteUserGroupBatch. Attackers can supply any groupId and comma-separated userIds to delete sys_ugroup_user rows without permission or tenant checks, tampering with administrator-maintained groups. | ||||
| CVE-2026-108635 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the GET /sys/sysDepart/getDepartmentHead endpoint of SysDepartController that allows any authenticated user to list department staff. Low-privileged attackers can enumerate departId values to retrieve staff names, avatars, posts, and mobile and telephone numbers, including contacts marked hidden. | ||||
| CVE-2026-108633 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to create department permission bindings via POST /sys/sysDepartPermission/add. Attackers can submit arbitrary departId, permissionId and dataRuleIds fields to attach menu, button and data rule grants to any department for delegation to its roles. | ||||
| CVE-2026-108632 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartPermissionController queryById handler that allows any authenticated user to read department permission records. Low-privileged attackers can request GET /sys/sysDepartPermission/queryById with arbitrary ids to retrieve depart_id, permission_id and data_rule_ids for any department. | ||||
| CVE-2026-108631 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartPermissionController delete handler that allows low-privileged authenticated users to delete department permission bindings. Attackers can obtain row ids from the unguarded list endpoint and send DELETE requests with the id parameter to remove menus or buttons departments can grant their roles. | ||||
| CVE-2026-108630 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in SysDepartPermissionController that allows any authenticated user to modify department permission records by calling the edit endpoint. Low-privileged attackers can obtain row ids from the unguarded list endpoint and overwrite depart_id, permission_id and data_rule_ids to alter which menus and data rules departments may delegate. | ||||
| CVE-2026-108628 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 8.1 High |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDeptRolePermission endpoint of SysDepartPermissionController that allows any authenticated user to modify department role permissions. Low-privileged attackers can submit roleId and permissionIds values to grant arbitrary menu or button permissions, escalating privileges or revoking other users' permissions. | ||||
| CVE-2026-108627 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the loadDatarule handler of SysRoleController that lets any authenticated user query role data rules. Low-privileged attackers can request GET /sys/role/datarule/{permissionId}/{roleId} to read rule names, columns, conditions, values and bound rule ids for any role. | ||||
| CVE-2026-108626 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController queryById handler that allows low-privileged authenticated users to read any message push record. Attackers can supply arbitrary record ids to GET /sys/message/sysMessage/queryById to disclose message content and receiver addresses of other users. | ||||
| CVE-2026-108625 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to modify message push records by calling PUT /sys/message/sysMessage/edit. Attackers can submit a request body naming any sys_sms record id to overwrite its title, content, receiver address and send status without ownership checks. | ||||
| CVE-2026-108624 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController deleteBatch handler that allows low-privileged authenticated users to delete message records. Attackers can obtain record ids from the unguarded list endpoint and submit them to deleteBatch to remove any message push records, including pending queued messages. | ||||
| CVE-2026-108623 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 7.1 High |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysLogController deleteBatch handler that allows any authenticated user to delete system audit log entries. Low-privileged attackers can send a DELETE request with ids set to allclear to wipe the entire sys_log table, erasing all users' audit trails. | ||||
| CVE-2026-108622 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysLogController delete handler that allows any authenticated user to delete audit log entries. Low-privileged attackers can obtain log ids from the unguarded /sys/log/list endpoint and delete chosen sys_log records to erase traces of their actions. | ||||
| CVE-2026-108621 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController edit handler that allows any authenticated user to modify organizational positions. Low-privileged attackers can obtain position ids from the unguarded list endpoint and send PUT or POST requests to /sys/position/edit to alter position names, codes, and ranks. | ||||
| CVE-2026-108619 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to delete message templates via the DELETE /sys/message/sysMessageTemplate/deleteBatch endpoint. Attackers can supply comma-separated template ids from the unguarded list endpoint to delete all sys_sms_template rows, breaking template-based notifications such as workflow reminders. | ||||
| CVE-2026-108618 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to modify message templates via PUT /sys/message/sysMessageTemplate/edit. Attackers can obtain template ids from the unguarded list endpoint and overwrite system notification titles and content, delivering attacker-supplied text or links to other users. | ||||
| CVE-2026-108617 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to create message templates by calling POST /sys/message/sysMessageTemplate/add. Attackers holding only minimal roles can insert arbitrary notification templates with chosen codes and content into the shared sys_sms_template library used for system, e-mail, SMS and IM notifications. | ||||
| CVE-2026-108615 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController delete handler that allows low-privileged authenticated users to delete AI evaluator records. Attackers can send DELETE requests to /airag/extData/delete with any id parameter to remove other users' AI evaluator or test-tracking records without owner or tenant checks. | ||||