Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 25080

25080 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE ID Title CVSS Severity Published
CVE-2026-85787 An incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs postgres-mcp-server — postgres-mcp-server CWE-184 6.5 Medium 2026-09-04
CVE-2026-55512 nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting — nebula-mesh CWE-400 5.3 Medium 2026-09-04
CVE-2026-80119 PassMark PerformanceTest, BurnInTest, and OSForensics Physical Memory Disclosure via DirectIo64.sys IOCTL — PerformanceTest CWE-73 7.8 High 2026-09-04
CVE-2026-80118 PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via DirectIo64.sys IOCTL — PerformanceTest CWE-476 7.1 High 2026-09-04
CVE-2026-9317 Nango < 0.71.6 Missing Authentication RCE via runner tRPC server — nango CWE-306 8.1 High 2026-09-04
CVE-2026-57166 PJSIP: Pre-authentication overflow in the telnet CLI error — pjproject CWE-121 6.3 Medium 2026-09-04
CVE-2026-57165 PJSIP: Pre-authentication overflow in the telnet CLI history — pjproject CWE-121 6.3 Medium 2026-09-04
CVE-2026-80893 mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() — Linux - - 2026-09-04
CVE-2026-19534 undici vulnerable to Denial of Service via unrequested WebSocket subprotocol — undici CWE-248 7.5 High 2026-09-04
CVE-2026-85024 undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression — undici CWE-248 5.9 Medium 2026-09-04
CVE-2026-18658 IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed — Operational Decision Manager CWE-89 9.8 Critical 2026-09-04
CVE-2026-82911 CSRF in Prospero Flow CRM order confirmation allows unauthorized order state changes — Prospero Flow CRM CWE-352 5.1 Medium 2026-09-04
CVE-2026-44402 Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi — SNMP Web Pro CWE-434 9.8 Critical 2026-09-04
CVE-2026-80800 nfc: llcp: bound the connect_sn TLV walk to the skb — Linux - - 2026-09-04
CVE-2026-80799 nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers — Linux - - 2026-09-04
CVE-2026-80798 nfc: llcp: reject PDUs shorter than the LLCP header — Linux - - 2026-09-04
CVE-2026-80789 nvmet-tcp: bound SGL data length before allocating command buffers — Linux - - 2026-09-04
CVE-2026-85695 FastChat Unauthenticated Worker Registration SSRF and Model Spoofing — FastChat CWE-306 9.4 Critical 2026-09-04
CVE-2026-85691 MegaParse 0.0.55 Server-Side Request Forgery via POST /v1/url — megaparse CWE-918 7.5 High 2026-09-04
CVE-2026-85688 TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer — ten-framework CWE-306 9.8 Critical 2026-09-04
CVE-2026-85687 surya 0.22.1 Unauthenticated Arbitrary File Read via screenshot server — surya CWE-73 7.5 High 2026-09-04
CVE-2026-85686 ms-swift 4.5.2 Unauthenticated SSRF via Multimodal Media URLs — ms-swift CWE-918 7.5 High 2026-09-04
CVE-2026-85684 marker through 2.0.0 Path Traversal via upload filename — marker CWE-73 9.1 Critical 2026-09-04
CVE-2026-85673 LLaMA-Factory SSRF Guard Bypass via Redirect and DNS Rebinding — LlamaFactory CWE-918 7.5 High 2026-09-04
CVE-2026-85671 QAnything 2.0.0 Unauthenticated Cross-User File Disclosure — QAnything CWE-306 7.5 High 2026-09-04
CVE-2026-85668 Xinference 3.3.0 Unauthenticated Arbitrary-Path File Read via /v1/models/llm/auto-register — inference CWE-73 7.5 High 2026-09-04
CVE-2026-85667 xiaobei through 5.5.2 Unauthenticated Webhook Message Injection — xiaobei CWE-306 9.1 Critical 2026-09-04
CVE-2026-85666 ogx 1.3.1 Server-Side Request Forgery via MCP tool server_url — ogx CWE-918 7.5 High 2026-09-04
CVE-2026-85664 Chroma 1.5.9 Unbounded HNSW Index Parameters Memory Exhaustion — chroma CWE-770 7.5 High 2026-09-04
CVE-2026-85663 Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch — aim CWE-306 9.8 Critical 2026-09-04

Vulnerabilities classified as access:pre-auth represent 25080 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.