Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18816

18816 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2019-25676 Ask Expert Script 3.0.5 Cross Site Scripting SQL Injection — Ask Expert ScriptCWE-79 8.2 High2026-04-05
CVE-2019-25674 CMSsite 1.0 SQL Injection via post Parameter — CMSsiteCWE-89 8.2 High2026-04-05
CVE-2019-25672 PilusCart 1.4.1 SQL Injection via send Parameter — PilusCartCWE-89 8.2 High2026-04-05
CVE-2019-25668 News Website Script 2.0.5 SQL Injection via index.php — News Website ScriptCWE-89 8.2 High2026-04-05
CVE-2019-25662 ResourceSpace 8.6 SQL Injection via watched_searches.php — ResourceSpaceCWE-89 8.2 High2026-04-05
CVE-2026-5526 Tenda 4G03 Pro httpd access control — 4G03 ProCWE-284 7.3 High2026-04-04
CVE-2018-25246 Wikipedia 12.0 Denial of Service via Search — WikipediaCWE-306 7.5 High2026-04-04
CVE-2018-25244 Eco Search 1.0.2.0 Denial of Service — Eco SearchCWE-1312 6.2 Medium2026-04-04
CVE-2018-25241 VPN Browser+ 1.1.0.0 Denial of Service — VPN Browser+CWE-306 7.5 High2026-04-04
CVE-2016-20053 Redaxo CMS 5.2 Cross-Site Request Forgery via users endpoint — Redaxo CMSCWE-352 5.3 Medium2026-04-04
CVE-2016-20051 Snews CMS 1.7 Cross-Site Request Forgery via changeup — Snews CMS Cross Site Request ForgeryCWE-352 5.3 Medium2026-04-04
CVE-2016-20052 Snews CMS 1.7 Unrestricted File Upload via snews_files — Snews CMS upload shellerCWE-434 9.8 Critical2026-04-04
CVE-2026-2936 Visitor Traffic Real Time Statistics <= 8.4 - Unauthenticated Stored Cross-Site Scripting — Visitor Traffic Real Time StatisticsCWE-79 7.2 High2026-04-04
CVE-2026-1233 Text to Speech (TTS) by Mementor <= 1.9.8 - Use of Hardcoded Password to Unauthenticated Remote Database Access — Text to Speech – TTSWPCWE-798 7.5 High2026-04-04
CVE-2025-14938 Listeo-Core - Directory Plugin by Purethemes <= 2.0.27 - Unauthenticated Arbitrary Media Upload — Listeo-Core - Directory Plugin by PurethemesCWE-434 5.3 Medium2026-04-04
CVE-2026-3309 Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Unauthenticated Arbitrary Shortcode Execution via Checkout Billing Fields — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePressCWE-94 6.5 Medium2026-04-04
CVE-2026-5425 Widgets for Social Photo Feed <= 1.7.9 - Unauthenticated Stored Cross-Site Scripting via feed_data — Widgets for Social Photo FeedCWE-79 7.2 High2026-04-04
CVE-2026-3571 Pie Register – User Registration, Profiles & Content Restriction <= 3.8.4.8 - Missing Authorization to Unauthenticated Registration Form Status Modification — Pie Register – User Registration, Profiles & Content RestrictionCWE-862 6.5 Medium2026-04-04
CVE-2026-35616 Fortinet FortiClientEms 安全漏洞 — FortiClientEMSCWE-284 9.1 Critical2026-04-04
CVE-2017-20235 ProSoft Technology ICX35-HWC Authentication Bypass — ICX35-HWC Cellular GatewayCWE-287 8.8 Critical2026-04-03
CVE-2017-20234 GarrettCom Magnum 6K and 10K Authentication Bypass via Hardcoded String — GarrettCom Magnum 6K and 10K Managed SwitchesCWE-798 9.8 Critical2026-04-03
CVE-2018-25236 Hirschmann HiOS HiSecOS Authentication Bypass via HTTP Management — Hirschmann HiOSCWE-287 9.8 Critical2026-04-03
CVE-2026-34824 Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service — mesopCWE-125 7.5 High2026-04-03
CVE-2015-10148 Hirschmann HiLCOS Hard-coded Credentials SSH SSL Keys — Hirschmann HiLCOSCWE-321 7.5 High2026-04-03
CVE-2026-27833 Piwigo: Unauthenticated Information Disclosure via pwg.history.search API — PiwigoCWE-862 7.5 High2026-04-03
CVE-2026-27634 Piwigo: Pre-auth SQL injection via date filter parameters in ws_std_image_sql_filter — PiwigoCWE-89 7.5AIHighAI2026-04-03
CVE-2026-27481 Discourse: Hidden tag visibility bypass on tag routes — discourseCWE-200 5.3AIMediumAI2026-04-03
CVE-2026-34980 OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network — cupsCWE-20 9.8AICriticalAI2026-04-03
CVE-2017-20237 Hirschmann Industrial HiVision Authentication Bypass Remote Code Execution — Hirschmann Industrial HiVisionCWE-287 9.8 Critical2026-04-03
CVE-2026-28798 Arbitrary internal service access via /v1/sys/proxy when Cloudflare Tunnel is enabled on ZimaOS — ZimaOSCWE-918 9.1 Critical2026-04-03

Vulnerabilities classified as access:pre-auth represent 18816 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.