JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to delete other users' AI voice records by supplying an arbitrary userId to DELETE /airag/voice/deleteVo…
CVSS 4.3
JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to delete other users' AI video generation records by supplying arbitrary userId values to DELETE /airag…
CVSS 4.3
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController deleteById handler that allows any authenticated user to delete OCR records. Low-privileged attackers can obtain record ids f…
CVSS 5.4
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController updateById handler that allows any authenticated user to modify global OCR templates. Low-privileged attackers can send PUT r…
CVSS 4.3
Memory Allocation with Excessive Size Value vulnerability in ericmj decimal allows Denial of Service. Decimal.round/3 builds the full result for the requested number of decimal places before the context precision (34 di…
Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme <= 1.0.2 versions.
CVSS 9.8
Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.
CVSS 9.8
Unauthenticated Cross Site Scripting (XSS) in Educavo <= 3.4.2 versions.
CVSS 7.1
Unauthenticated PHP Object Injection in Qwery <= 3.6.1 versions.
CVSS 9.8
Unauthenticated Cross Site Scripting (XSS) in LMS <= 8.3 versions.
CVSS 7.1
Unauthenticated PHP Object Injection in Jacqueline <= 2.22 versions.
CVSS 9.8
Subscriber Arbitrary File Deletion in FoodBakery <= 4.6 versions.
CVSS 7.7