Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18817

18817 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-31831 Tautulli: Unauthenticated Path Traversal in `/newsletter/image/images` endpoint — TautulliCWE-23 7.5 -2026-03-30
CVE-2026-31804 Tautulli: Unauthenticated pms_image_proxy endpoint proxies arbitrary HTTP requests through the Plex Media Server — TautulliCWE-918 4.0 Medium2026-03-30
CVE-2026-33032 Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover — nginx-uiCWE-306 9.8 Critical2026-03-30
CVE-2026-3321 Authorization Bypass in ON24 Q&A chat — ON24 Q&A chatCWE-639 7.5 -2026-03-30
CVE-2026-4415 GIGABYTE|Gigabyte Control Center - Arbitrary File Write — Gigabyte Control CenterCWE-23 8.1 High2026-03-30
CVE-2026-3945 Tinyproxy 安全漏洞 — tinyproxyCWE-190 7.5 High2026-03-30
CVE-2026-2328 Backend Access Due to Insufficient Input Validation — Device SphereCWE-790 7.5 High2026-03-30
CVE-2026-3124 Download Monitor <= 5.1.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' — Download MonitorCWE-639 7.5 High2026-03-30
CVE-2026-34472 ZTE ZXHN H188A 安全漏洞 — n/a 8.4 -2026-03-30
CVE-2026-29872 Awesome LLM Apps 安全漏洞 — n/a 7.5 -2026-03-30
CVE-2026-29909 MRCMS 安全漏洞 — n/a 5.3 -2026-03-30
CVE-2026-0558 Unauthenticated File Upload in parisneo/lollms — parisneo/lollmsCWE-287 9.8 -2026-03-29
CVE-2026-32980 OpenClaw < 2026.3.13 - Resource Exhaustion via Unauthenticated Telegram Webhook Request — OpenClawCWE-770 7.5 High2026-03-29
CVE-2026-32974 OpenClaw < 2026.3.12 - Forged Event Injection via Feishu Webhook Verification Token — OpenClawCWE-347 8.6 High2026-03-29
CVE-2018-25225 SIPP 3.3 Stack-Based Buffer Overflow via Configuration File — SIPPCWE-306 8.4 High2026-03-28
CVE-2018-25224 PMS 0.42 Stack-Based Buffer Overflow via Configuration File — PMSCWE-306 8.4 High2026-03-28
CVE-2026-2442 Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email' — Page Builder: Pagelayer – Drag and Drop website builderCWE-93 5.3 Medium2026-03-28
CVE-2025-12886 Oxygen <= 6.0.8 - Unauthenticated Server-Side Request Forgery via route_path — Oxygen - WooCommerce WordPress ThemeCWE-918 7.2 High2026-03-28
CVE-2026-4987 SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id' — SureForms – Contact Form, Payment Form & Other Custom Form BuilderCWE-20 7.5 High2026-03-28
CVE-2026-33981 Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters — changedetection.ioCWE-200 7.5 -2026-03-27
CVE-2026-33885 Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential — cmsCWE-601 6.1 Medium2026-03-27
CVE-2026-33868 Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>' — mastodonCWE-601 4.3 Medium2026-03-27
CVE-2026-33654 Zero-Click Indirect Prompt Injection and Authentication Bypass via Email Polling — nanobotCWE-94 10.0 -2026-03-27
CVE-2026-34205 Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mode — Home Assistant Operating SystemCWE-923 9.7 Critical2026-03-27
CVE-2026-26061 Fleet's unbounded request body read allows remote Denial of Service — fleetCWE-770 7.5 -2026-03-27
CVE-2026-34369 AVIdeo has Video Password Protection Bypass via API Endpoints Returning Full Playback Sources Without Password Verification — AVideoCWE-862 5.3 Medium2026-03-27
CVE-2026-34411 Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIs — AppsmithCWE-306 5.3 Medium2026-03-27
CVE-2026-5022 Langflow - Missing Authorization on download_image Endpoint — langflowCWE-862 5.3 -2026-03-27
CVE-2026-33763 AVideo has an Unauthenticated Video Password Brute-Force Vulnerability via Unrate-Limited Boolean Oracle — AVideoCWE-307 5.3 Medium2026-03-27
CVE-2026-33761 AVideo: Unauthenticated Access to Scheduler Plugin Endpoints Leaks Scheduled Tasks, Email Content, and User Mappings — AVideoCWE-862 5.3 Medium2026-03-27

Vulnerabilities classified as access:pre-auth represent 18817 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.