Search

Search Results (404437 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-108543 1 Ag2ai 1 Ag2 2026-10-11 6.3 Medium
A vulnerability was determined in ag2ai ag2 up to 0.13.4. Affected by this issue is the function os.path.join of the component UserProxyAgent. This manipulation of the argument filename causes path traversal. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-108542 1 021is 1 Elvix-sdk 2026-10-11 6.3 Medium
A vulnerability was found in 021is elvix-sdk up to 0.10.1. Affected by this vulnerability is an unknown functionality of the file src/mcp/index.ts of the component MCP Request Handler. The manipulation of the argument path results in server-side request forgery. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-108613 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragAppController release handler that allows any authenticated user to publish or unpublish other users' AI applications. Low-privileged attackers can send POST requests to /airag/app/release to obtain share tokens exposing applications to anonymous chat access, or invalidate existing share links.
CVE-2026-108667 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to restore deleted AI prompt templates by calling the revertRecycleBin endpoint. Attackers can send PUT requests to /airag/prompts/revertRecycleBin with chosen template ids to clear deleted flags, undoing administrator removals.
CVE-2026-108669 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the embeddingSearch handler of AiragKnowledgeController that lacks Shiro permission annotations. Low-privileged authenticated attackers can supply knowledge base ids to the GET /airag/knowledge/embedding/search endpoint to read document text chunks from unauthorized knowledge bases.
CVE-2026-108541 1 Highwarden 1 Super Store Finder 2026-10-11 6.3 Medium
A vulnerability has been found in highwarden Super Store Finder up to 3.8. Affected is an unknown function of the file /products/superstorefinder/index.php. The manipulation of the argument lat/lng leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 3.9 is able to address this issue. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
CVE-2026-108626 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController queryById handler that allows low-privileged authenticated users to read any message push record. Attackers can supply arbitrary record ids to GET /sys/message/sysMessage/queryById to disclose message content and receiver addresses of other users.
CVE-2026-98376 1 Linux 1 Linux Kernel 2026-10-11 7.0 High
In the Linux kernel, the following vulnerability has been resolved: bpf: Use array_map_meta_equal for percpu array inner map replacement percpu_array_map_ops.map_meta_equal points to the generic bpf_map_meta_equal(), which does not compare max_entries. When a percpu array serves as an inner map, replacing it with one that has fewer max_entries bypasses the check. Since percpu_array_map_gen_lookup() inlines the original template's index_mask as a JIT immediate, a lookup on the replacement map can access pptrs[] out of bounds. Point percpu_array_map_ops.map_meta_equal to array_map_meta_equal(), which already enforces the max_entries equality check. Add a selftest to verify that replacing a percpu array inner map with a differently-sized one is rejected.
CVE-2026-108633 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to create department permission bindings via POST /sys/sysDepartPermission/add. Attackers can submit arbitrary departId, permissionId and dataRuleIds fields to attach menu, button and data rule grants to any department for delegation to its roles.
CVE-2026-108670 2 Jeecg, Jeecgboot 3 Jeecg-boot, Jeecg Boot, Jeecgboot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the promptExperiment handler of AiragPromptsController that allows any authenticated user to run AI prompt experiments. Low-privileged attackers can supply other users' prompt template and dataset ids to trigger large language model evaluation runs, write result rows into airag_ext_data, and change dataset status.
CVE-2026-108540 1 Openspug 1 Spug 2026-10-11 9.9 Critical
A flaw has been found in OpenSpug Spug up to 3.4.0/4.0.1. This impacts an unknown function of the file /exec/transfer of the component File Transfer. Executing a manipulation can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-108606 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController deleteById handler that allows any authenticated user to delete OCR records. Low-privileged attackers can obtain record ids from the unguarded GET /airag/ocr/list endpoint and repeatedly delete every shared OCR prompt record stored in Redis.
CVE-2026-108630 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in SysDepartPermissionController that allows any authenticated user to modify department permission records by calling the edit endpoint. Low-privileged attackers can obtain row ids from the unguarded list endpoint and overwrite depart_id, permission_id and data_rule_ids to alter which menus and data rules departments may delegate.
CVE-2026-108639 2 Jeecg, Jeecgboot 3 Jeecg-boot, Jeecg Boot, Jeecgboot 2026-10-11 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to permanently delete data dictionaries via the deletePhysic handler of SysDictController. Low-privileged attackers can send DELETE requests to /sys/dict/deletePhysic/{id} to irreversibly remove active dictionaries and all their items, bypassing the recycle bin.
CVE-2026-108678 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryUserRoles handler of SystemApiController that lets authenticated users read any user's role codes. Low-privileged attackers can send GET requests to /sys/api/queryUserRoles with an arbitrary username to enumerate role assignments and identify administrator accounts.
CVE-2026-98260 1 Linux 1 Linux Kernel 2026-10-11 7.8 High
In the Linux kernel, the following vulnerability has been resolved: exec: Cleanup POSIX timers right after de_thread() A per-thread CPU timer holds a reference to the PID of the thread it is attached to and, while it is armed, its node is queued in that thread's posix_cputimers. The task is looked up by that PID. When a non-leader thread exec()s, de_thread() changes which task owns that PID. pid_task(timer->it.cpu.pid, PIDTYPE_PID) then returns NULL, but the node is still queued on tsk, which is alive. timer_lock_sighand() takes a failed lookup to mean that the node is already dequeued, so it has nothing to undo. begin_new_exec() calls posix_cpu_timers_exit(me) right after exec_task_namespaces() and that removes the leftover node, so the state normally stays invisible. But bprm->point_of_no_return is set before de_thread(), so if unshare_files(), set_mm_exe_file(), exec_mmap() or exec_task_namespaces() fails, the task dies before it gets there. exit_itimers() then frees the k_itimer while its node is still queued, and reaping tsk later erases that freed node from the rbtree. In short: the non-leader thread B the parent timer_create(CLOCK_THREAD_CPUTIME_ID) timer_settime() arm_timer() // the node is queued on B execve() de_thread(B) exchange_tids(B, leader) // B's PID now belongs to the leader release_task(leader) __exit_signal(leader) posix_cpu_timers_exit(leader) // cleans leader's queue, not B's __unhash_process(leader) // that PID has no task anymore exec_mmap() mmap_read_lock_killable(old_mm) kill(B, SIGKILL) // -EINTR get_signal() do_exit() exit_itimers() posix_timer_delete() posix_cpu_timer_del() posix_timer_unhash_and_free() // freed while still queued wait4() release_task(B) posix_cpu_timers_exit(B) cleanup_timerqueue() timerqueue_del() // use-after-free Move the POSIX timer cleanup right after de_thread() before any of the later failure conditions brings the task into do_exit(). [ tglx: Move the cleanup right after de_thread() ]
CVE-2026-108627 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the loadDatarule handler of SysRoleController that lets any authenticated user query role data rules. Low-privileged attackers can request GET /sys/role/datarule/{permissionId}/{roleId} to read rule names, columns, conditions, values and bound rule ids for any role.
CVE-2026-98281 1 Linux 1 Linux Kernel 2026-10-11 7.8 High
In the Linux kernel, the following vulnerability has been resolved: futex: Also allocate private hash on vfork() As Jann demonstrated, it is entirely feasible to access the mm through vfork(). Therefore we need to allocate a private hash on vfork() as well as any other CLONE_VM user. Specifically, it must be avoided to have (private) futex waiters before allocating the private hash.
CVE-2026-98284 1 Linux 1 Linux Kernel 2026-10-11 7.0 High
In the Linux kernel, the following vulnerability has been resolved: netlink: do not free nlk->groups while lockless readers can use it netlink_realloc_groups() uses krealloc() under netlink_table_grab(). Whenever NLGRPSZ(groups) lands in a different kmalloc bucket, the old bitmap is freed immediately. Two readers of nlk->groups / nlk->ngroups do not hold the netlink table lock: 1) sk_diag_dump_groups(). Hashed (bound) sockets are dumped from the rhashtable walk in __netlink_diag_dump(), which only holds RCU. Only the mc_list part of the dump takes nl_table_lock. 2) netlink_native_seq_show() (/proc/net/netlink), whose walk has been lockless since commit 21e4902aea80 ("netlink: Lockless lookup with RCU grace period in socket release"). Both can read a freed buffer, and sk_diag_dump_groups() can also read past the end of the old (smaller) buffer if it happens to load the old @groups pointer together with the new @ngroups value, copying the result into a NETLINK_DIAG_GROUPS attribute. This is the same class of bug that commit f773608026ee ("netlink: access nlk groups safely in netlink bind and getname") fixed for bind() and getname(); these two readers were missed. Simply grabbing the table lock in sk_diag_dump_groups() is not an option, because it is also called with nl_table_lock already held from the mc_list section of the dump. Make the lockless readers safe instead: - Allocate a new bitmap and free the old one after an RCU grace period, instead of relying on the implicit kfree() done by krealloc(). - Publish @groups before @ngroups, both with release semantics, and have the lockless readers load @ngroups first. A reader can then never pair the new (bigger) size with the old (smaller) buffer, and a reader picking up the new pointer while still seeing the old size is guaranteed to see the initialized bitmap. netlink_realloc_groups() is called from process context (bind() and setsockopt()), so kfree_rcu_mightsleep() can be used, once the table has been released.
CVE-2026-98319 1 Linux 1 Linux Kernel 2026-10-11 5.5 Medium
In the Linux kernel, the following vulnerability has been resolved: drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr When an out_fence_ptr is provided but DRM_MODE_PAGE_FLIP_EVENT is not set, a drm_pending_vblank_event will be allocated. If later, there is an allocation failure or another failure at setup_out_fence(), that event will not have base.fence set and it will not be released at complete_signaling(). Release the event and set crtc_state->event to NULL just like in the DRM_MODE_PAGE_FLIP_EVENT case when there is a failure at drm_event_reserve_init(). That is, prepare_signaling() releases the event and there is nothing to be done at complete_signaling(). Use drm_event_cancel_free() as that will also undo drm_event_reserve_init() in case it has been called.