CVE database
Vulnerabilities with CVSS and EPSS scoring, updated daily.
| CVE | Summary | Severity | Published |
|---|---|---|---|
| CVE-2026-108680 | JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendTemplateAnnouncement | MEDIUM | 2026-10-10 |
| CVE-2026-108679 | JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendBusAnnouncement | MEDIUM | 2026-10-10 |
| CVE-2026-108678 | JeecgBoot through 3.9.5 Missing Authorization via /sys/api/queryUserRoles | MEDIUM | 2026-10-10 |
| CVE-2026-108677 | JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserByName | HIGH | 2026-10-10 |
| CVE-2026-108676 | JeecgBoot through 3.9.5 Missing Authorization via /sys/annountCement/downLoadFiles | MEDIUM | 2026-10-10 |
| CVE-2026-108675 | JeecgBoot through 3.9.5 Missing Authorization via /sys/annountCement/editIzTop | MEDIUM | 2026-10-10 |
| CVE-2026-108674 | JeecgBoot through 3.9.5 Missing Authorization via /openapi/queryById | MEDIUM | 2026-10-10 |
| CVE-2026-108673 | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/exportXls | MEDIUM | 2026-10-10 |
| CVE-2026-108672 | JeecgBoot through 3.9.5 Authorization Bypass via /airag/video/listByUser | MEDIUM | 2026-10-10 |
| CVE-2026-108671 | JeecgBoot through 3.9.5 Missing Authorization via /airag/airagMcp/queryById | HIGH | 2026-10-10 |
| CVE-2026-108670 | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/experiment | MEDIUM | 2026-10-10 |
| CVE-2026-108669 | JeecgBoot through 3.9.5 Missing Authorization via /airag/knowledge/embedding/search | MEDIUM | 2026-10-10 |
| CVE-2026-108668 | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteRecycleBin | MEDIUM | 2026-10-10 |
| CVE-2026-108667 | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/revertRecycleBin | MEDIUM | 2026-10-10 |
| CVE-2026-108666 | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteBatch | MEDIUM | 2026-10-10 |
| CVE-2026-108665 | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/edit | MEDIUM | 2026-10-10 |
| CVE-2026-108664 | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/queryById | MEDIUM | 2026-10-10 |
| CVE-2026-108663 | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/deleteApply | MEDIUM | 2026-10-10 |
| CVE-2026-108662 | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/deleteTenantPackUser | MEDIUM | 2026-10-10 |
| CVE-2026-108661 | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/changeOwenUserTenant | HIGH | 2026-10-10 |
| CVE-2026-108660 | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/updateApplyStatus | MEDIUM | 2026-10-10 |
| CVE-2026-108659 | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/listPackByTenantUserId | MEDIUM | 2026-10-10 |
| CVE-2026-108658 | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/queryTenantAuthInfo | MEDIUM | 2026-10-10 |
| CVE-2026-108657 | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/passApply | HIGH | 2026-10-10 |
| CVE-2026-108656 | JeecgBoot through 3.9.5 Missing Authorization via getTenantPackApplyUsers Endpoint | MEDIUM | 2026-10-10 |
| CVE-2026-108655 | JeecgBoot through 3.9.5 Missing Authorization via /sys/quartzJob/queryById | MEDIUM | 2026-10-10 |
| CVE-2026-108654 | JeecgBoot through 3.9.5 Missing Authorization via /sys/oss/file/queryById | MEDIUM | 2026-10-10 |
| CVE-2026-108653 | JeecgBoot through 3.9.5 Missing Authorization via GET /openapi/list | MEDIUM | 2026-10-10 |
| CVE-2026-108652 | JeecgBoot through 3.9.5 Missing Authorization via /sys/api/updateAvatar | MEDIUM | 2026-10-10 |
| CVE-2026-108651 | JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getRolesByUserId | MEDIUM | 2026-10-10 |
| CVE-2026-108650 | JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserPermissionSet | MEDIUM | 2026-10-10 |
| CVE-2026-108649 | JeecgBoot through 3.9.5 Missing Authorization via /sys/api/queryUserRolesById | MEDIUM | 2026-10-10 |
| CVE-2026-108648 | JeecgBoot through 3.9.5 Missing Authorization via getDynamicDbSourceByCode Endpoint | HIGH | 2026-10-10 |
| CVE-2026-108647 | JeecgBoot through 3.9.5 Missing Authorization via /sys/checkRule/importExcel | MEDIUM | 2026-10-10 |
| CVE-2026-108646 | JeecgBoot through 3.9.5 Missing Authorization via /sys/category/importExcel | MEDIUM | 2026-10-10 |
| CVE-2026-108645 | JeecgBoot through 3.9.5 Missing Authorization via /sys/category/edit | MEDIUM | 2026-10-10 |
| CVE-2026-108644 | JeecgBoot through 3.9.5 Missing Authorization via /sys/category/delete | MEDIUM | 2026-10-10 |
| CVE-2026-108643 | JeecgBoot through 3.9.5 Missing Authorization via /sys/category/deleteBatch | MEDIUM | 2026-10-10 |
| CVE-2026-108642 | JeecgBoot through 3.9.5 IDOR via PUT /sys/sysAnnouncementSend/edit | MEDIUM | 2026-10-10 |
| CVE-2026-108641 | JeecgBoot through 3.9.5 IDOR via /sys/sysAnnouncementSend/getOne | MEDIUM | 2026-10-10 |
| CVE-2026-108640 | JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartRole/queryById | MEDIUM | 2026-10-10 |
| CVE-2026-108639 | JeecgBoot through 3.9.5 Missing Authorization via /sys/dict/deletePhysic/{id} | MEDIUM | 2026-10-10 |
| CVE-2026-108638 | JeecgBoot through 3.9.5 Missing Authorization via /sys/user/deleteGroupUser | MEDIUM | 2026-10-10 |
| CVE-2026-108637 | JeecgBoot through 3.9.5 Missing Authorization via deleteUserGroupBatch Endpoint | MEDIUM | 2026-10-10 |
| CVE-2026-108636 | JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepart/appImportExcel | MEDIUM | 2026-10-10 |
| CVE-2026-108635 | JeecgBoot through 3.9.5 Missing Authorization via getDepartmentHead Endpoint | MEDIUM | 2026-10-10 |
| CVE-2026-108634 | JeecgBoot through 3.9.5 Missing Authorization via sysDepartPermission deleteBatch Endpoint | MEDIUM | 2026-10-10 |
| CVE-2026-108633 | JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartPermission/add | MEDIUM | 2026-10-10 |
| CVE-2026-108632 | JeecgBoot through 3.9.5 Missing Authorization via sysDepartPermission queryById Endpoint | MEDIUM | 2026-10-10 |
| CVE-2026-108631 | JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartPermission/delete | MEDIUM | 2026-10-10 |