Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18816

18816 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-1900 Link Whisper Free < 0.9.1 - Unauthenticated Settings and User Meta Update — Link Whisper Free 5.3AIMediumAI2026-04-07
CVE-2025-15611 Popup Box AYS Pro < 5.5.0 - Admin+ Stored Cross-Site Scripting (XSS) via CSRF — Popup Box 7.1AIHighAI2026-04-07
CVE-2026-0740 Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload — Ninja Forms - File UploadsCWE-434 9.8 Critical2026-04-07
CVE-2025-56015 GenieACS 安全漏洞 — n/a 9.8AICriticalAI2026-04-07
CVE-2026-31271 production_ssm 安全漏洞 — n/a 9.8AICriticalAI2026-04-07
CVE-2026-31272 MRCMS 安全漏洞 — n/a 9.8AICriticalAI2026-04-07
CVE-2026-35449 WWBN AVideo has Unauthenticated Information Disclosure via Disabled CLI Guard in install/test.php — AVideoCWE-200 5.3 Medium2026-04-06
CVE-2026-35413 Directus GraphQL Schema SDL Disclosure Setting — directusCWE-200 5.3 Medium2026-04-06
CVE-2026-22675 OCS Inventory NG Server Stored XSS via User-Agent — OCS Inventory NG ServerCWE-79 5.4 Medium2026-04-06
CVE-2026-35185 HAX CMS's public /server-status endpoint exposes authentication tokens, user activity, and client IP addresses — HAXiamCWE-284 7.5AIHighAI2026-04-06
CVE-2026-35179 WWBN AVideo Unauthenticated Instagram Graph API Proxy via publishInstagram.json.php — AVideoCWE-862 5.3 Medium2026-04-06
CVE-2026-35036 Ech0 Affected by Unauthenticated Server-Side Request Forgery in Website Preview Feature — Ech0CWE-918 7.5 High2026-04-06
CVE-2026-35030 LiteLLM has an authentication bypass via OIDC userinfo cache key collision — litellmCWE-287 6.5AIMediumAI2026-04-06
CVE-2026-34981 whisperX REST API: SSRF in download_from_url() — URL validation happens after HTTP request, extension bypass via .mp3 — whisperX-FastAPICWE-918 5.8 Medium2026-04-06
CVE-2026-34977 Aperi'Solve Affected by Unauthenticated RCE via JPSeek Analyzer Command — AperiSolveCWE-78 9.8AICriticalAI2026-04-06
CVE-2026-34976 Dgraph Affected by Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization — dgraphCWE-862 10.0 Critical2026-04-06
CVE-2026-34756 vLLM Affected by Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server — vllmCWE-770 6.5 Medium2026-04-06
CVE-2026-33403 Pi-hole has a Reflected XSS / HTML injection in taillog.js — webCWE-79 6.1 Medium2026-04-06
CVE-2026-26263 GLPI has an Unauthenticated SQL Injection via Search engine — glpiCWE-89 8.1 High2026-04-06
CVE-2026-26027 GLPI has an Unauthenticated Stored XSS via inventory — glpiCWE-79 7.5 High2026-04-06
CVE-2026-30613 AZIOT 1 Node Smart Switch 安全漏洞 — n/a 4.6AIMediumAI2026-04-06
CVE-2026-4272 CVE-2026-4272 - Bluetooth Remote Execution of System Commands Vulnerability — Barcode ScannersCWE-306 8.1 High2026-04-05
CVE-2019-25675 eDirectory All Versions SQL Injection Authentication Bypass — eDirectoryCWE-89 8.2 High2026-04-05
CVE-2019-25694 Kados R10 GreenBee SQL Injection via user2reset — Kados R10 GreenBeeCWE-89 8.2 High2026-04-05
CVE-2019-25688 Kados R10 GreenBee SQL Injection via menu_lev1 Parameter — Kados GreenBeeCWE-89 8.2 High2026-04-05
CVE-2019-25687 Pegasus CMS 1.0 Remote Code Execution via extra_fields.php — Pegasus CMSCWE-22 9.8 Critical2026-04-05
CVE-2019-25686 Core FTP 2.0 build 653 PBSZ Unauthenticated Denial of Service — Core FTPCWE-306 7.5 High2026-04-05
CVE-2019-25684 OpenDocMan 1.3.4 SQL Injection via where Parameter — OpenDocManCWE-89 8.2 High2026-04-05
CVE-2019-25680 Advance Gift Shop Pro Script 2.0.3 SQL Injection via search — Advance Gift Shop Pro ScriptCWE-89 8.2 High2026-04-05
CVE-2019-25678 C4G BLIS 3.4 SQL Injection via users_select.php — Basic Laboratory Information SystemCWE-306 8.2 High2026-04-05

Vulnerabilities classified as access:pre-auth represent 18816 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.