Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18817

18817 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-1584 Gnutls: gnutls: remote denial of service via crafted clienthello with invalid psk binder — Red Hat Enterprise Linux 10CWE-476 7.5 High2026-04-09
CVE-2026-39987 marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass — marimoCWE-306 9.8AICriticalAI2026-04-09
CVE-2026-34578 OPNsense has an LDAP Injection via Unsanitized Username in Authentication — coreCWE-90 8.2 High2026-04-09
CVE-2026-2519 Online Scheduling and Appointment Booking System – Bookly <= 27.0 - Unauthenticated Price Manipulation via 'tips' — Online Scheduling and Appointment Booking System – BooklyCWE-472 5.3 Medium2026-04-09
CVE-2026-1830 Quick Playground <= 1.3.1 - Missing Authorization to Unauthenticated Arbitrary File Upload — Quick PlaygroundCWE-862 9.8 Critical2026-04-09
CVE-2025-12664 Improper Validation of Specified Quantity in Input in GitLab — GitLabCWE-1284 7.5 High2026-04-08
CVE-2026-1092 Improper Validation of Specified Quantity in Input in GitLab — GitLabCWE-1284 7.5 High2026-04-08
CVE-2026-3438 Nexus Repository 3 - Reflected Cross-Site Scripting (XSS) in ?describe Pages — Nexus RepositoryCWE-79 6.1AIMediumAI2026-04-08
CVE-2026-39889 PraisonAI has Unauthenticated SSE Event Stream Exposes All Agent Activity in A2U Server — PraisonAICWE-200 7.5 High2026-04-08
CVE-2026-5436 MW WP Form <= 5.1.1 - Unauthenticated Arbitrary File Move via regenerate_upload_file_keys — MW WP FormCWE-22 8.1 High2026-04-08
CVE-2026-34723 Zammad has incorrect access control in getting_started_controller — zammadCWE-284 7.5AIHighAI2026-04-08
CVE-2026-0811 Advanced CF7 DB <= 2.0.9 - Cross-Site Request Forgery to Form Entry Deletion — Advanced Contact form 7 DBCWE-352 5.4 Medium2026-04-08
CVE-2026-2942 ProSolution WP Client <= 1.9.9 - Unauthenticated Arbitrary File Upload via proSol_fileUploadProcess — ProSolution WP ClientCWE-434 9.8 Critical2026-04-08
CVE-2026-33756 Saleor Affected by Denial of Service via Unbounded GraphQL Query Batching — saleorCWE-770 7.5 High2026-04-08
CVE-2025-14243 Mirror-registry: openshift mirror registry: user enumeration via authentication error messages — mirror registry for Red Hat OpenShiftCWE-209 5.3 Medium2026-04-08
CVE-2026-39393 Post-Installation Re-entry via Cache-Dependent Install Guard Bypass in ci4ms — ci4msCWE-306 8.1 High2026-04-08
CVE-2026-39390 CI4MS has Stored XSS via srcdoc attribute bypass in Google Maps iframe setting — ci4msCWE-79 5.5 Medium2026-04-08
CVE-2026-5302 Permissive Cross-domain Policy with Untrusted Domains in coolercontrold — coolercontroldCWE-942 6.3 Medium2026-04-08
CVE-2026-5300 Missing Authentication for Critical Function in coolercontrold — coolercontroldCWE-306 5.9 Medium2026-04-08
CVE-2026-5301 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in coolercontrol-ui — coolercontrol-uiCWE-79 7.6 High2026-04-08
CVE-2026-3396 WCAPF – WooCommerce Ajax Product Filter <= 4.2.3 - Unauthenticated Time-Based SQL Injection — WCAPF – Ajax Product Filter for WooCommerceCWE-89 7.5 High2026-04-08
CVE-2026-1672 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery to Product Data Modification — BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.NetCWE-352 6.5 Medium2026-04-08
CVE-2026-1673 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery to Taxonomy Term Deletion — BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.NetCWE-352 4.3 Medium2026-04-08
CVE-2026-4141 Quran Translations <= 1.7 - Cross-Site Request Forgery to Playlist Settings Form — Quran TranslationsCWE-352 4.3 Medium2026-04-08
CVE-2026-5167 Masteriyo LMS <= 2.1.7 - Unauthenticated Authorization Bypass to Arbitrary Order Completion via Stripe Webhook Endpoint — Masteriyo LMS – Online Course Builder for eLearning, LMS & EducationCWE-639 5.3 Medium2026-04-08
CVE-2026-3535 DSGVO Google Web Fonts GDPR <= 1.1 - Unauthenticated Arbitrary File Upload via 'fonturl' Parameter — DSGVO Google Web Fonts GDPRCWE-434 9.8 Critical2026-04-08
CVE-2026-3594 Riaxe Product Customizer <= 2.4 - Unauthenticated Sensitive Information Disclosure via '/orders' REST API Endpoint — Riaxe Product CustomizerCWE-200 5.3 Medium2026-04-08
CVE-2026-4338 ActivityPub Routing < 8.0.2 - Unauthenticated Drafts/Scheduled/Pending Posts Disclosure — ActivityPub 5.3AIMediumAI2026-04-08
CVE-2026-3646 LTL Freight Quotes – R+L Carriers Edition <= 3.3.13 - Missing Authorization to Unauthenticated Settings Update — LTL Freight Quotes – R+L Carriers EditionCWE-862 5.3 Medium2026-04-08
CVE-2026-4003 Users manager – PN <= 1.1.15 - Unauthenticated Privilege Escalation via Account Takeover via 'userspn_form_save' AJAX Action — Users manager – PNCWE-862 9.8 Critical2026-04-08

Vulnerabilities classified as access:pre-auth represent 18817 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.