Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18829

18829 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-29787 mcp-memory-service: System Information Disclosure via Health Endpoint — mcp-memory-serviceCWE-200 5.3 Medium2026-03-07
CVE-2026-1087 The Guardian News Feed <= 1.2 - Cross-Site Request Forgery to Settings Update — The Guardian News FeedCWE-352 4.3 Medium2026-03-07
CVE-2026-1086 Font Pairing Preview For Landing Pages <= 1.3 - Cross-Site Request Forgery to Settings Update — Font Pairing Preview For Landing PagesCWE-352 4.3 Medium2026-03-07
CVE-2026-1085 True Ranker <= 2.2.9 - Cross-Site Request Forgery to Unauthorized True Ranker Disconnection — True RankerCWE-352 4.3 Medium2026-03-07
CVE-2026-1074 WP App Bar <= 1.5 - Unauthenticated Stored Cross-Site Scripting via 'app-bar-features' Parameter — WP App BarCWE-79 7.2 High2026-03-07
CVE-2026-1073 Purchase Button For Affiliate Link <= 1.0.2 - Cross-Site Request Forgery to Settings Update — Purchase Button For Affiliate LinkCWE-352 4.3 Medium2026-03-07
CVE-2026-2433 RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.11 - Unauthenticated DOM-Based Reflected Cross-Site Scripting via postMessage — RSS Aggregator – RSS Import, News Feeds, Feed to Post, and AutobloggingCWE-79 6.1 Medium2026-03-07
CVE-2026-27796 Homarr: Unauthenticated Information Disclosure (Integration Metadata Leak) — homarrCWE-200 5.3 Medium2026-03-07
CVE-2026-27797 Homarr: Unauthenticated SSRF in rssFeed.ts — homarrCWE-918 5.3 Medium2026-03-07
CVE-2026-30829 Checkmate: Unauthenticated Access to Unpublished Status Page — CheckmateCWE-200 5.3 Medium2026-03-07
CVE-2026-30824 Flowise: Missing Authentication on NVIDIA NIM Endpoints — FlowiseCWE-306 10.0 -2026-03-07
CVE-2026-30822 Flowise: Mass Assignment in `/api/v1/leads` Endpoint — FlowiseCWE-915 5.3 -2026-03-07
CVE-2026-30821 Flowise: Arbitrary File Upload via MIME Spoofing — FlowiseCWE-434 9.8 -2026-03-07
CVE-2026-2431 CM Custom Reports <= 1.2.7 - Reflected Cross-Site Scripting via 'date_from' and 'date_to' Parameters — CM Custom Reports – Flexible reporting to track what matters mostCWE-79 6.1 Medium2026-03-07
CVE-2026-1650 MDJM Event Management <= 1.7.8.1 - Missing Authorization to Unauthenticated Arbitrary Custom Event Field Deletion — MDJM Event ManagementCWE-862 5.3 Medium2026-03-07
CVE-2026-2494 ProfileGrid <= 5.9.8.2 - Cross-Site Request Forgery to Group Membership Request Approval/Denial — ProfileGrid – User Profiles, Groups and CommunitiesCWE-352 4.3 Medium2026-03-07
CVE-2025-14353 ZIP Code Based Content Protection <= 1.0.2 - Unauthenticated SQL Injection via 'zipcode' Parameter — ZIP Code Based Content ProtectionCWE-89 7.5 High2026-03-07
CVE-2026-25071 XikeStor SKS8310-8X switch_config.src Missing Authentication — XikeStor SKS8310-8XCWE-306 5.3 -2026-03-07
CVE-2026-25070 XikeStor SKS8310-8X PingTestSet Command Injection — XikeStor SKS8310-8XCWE-78 9.8 -2026-03-07
CVE-2026-1644 WP Frontend Profile <= 1.3.8 - Cross-Site Request Forgery to Unauthorized User Account Approval or Rejection — WP Frontend ProfileCWE-352 4.3 Medium2026-03-06
CVE-2026-2371 Greenshift <= 12.8.3 - Missing Authorization to Unauthenticated Private Reusable Block Disclosure via 'gspb_el_reusable_load' — Greenshift – animation and page builder blocksCWE-862 5.3 Medium2026-03-06
CVE-2026-30244 Plane: Unauthenticated Workspace Member Information Disclosure — planeCWE-284 7.5 High2026-03-06
CVE-2026-30231 Flare: Private File IDOR via raw/direct endpoints — FlareCWE-639 6.5 -2026-03-06
CVE-2026-30846 Wekan Exposes All Global Webhook Integrations through globalwebhooks Publication — WekanCWE-306 7.5 -2026-03-06
CVE-2026-30845 Wekan Exposes Sensitive Data through Lack of Field Filtering During Board Publication — WekanCWE-200 7.5 -2026-03-06
CVE-2026-29178 Lemmy: Unauthenticated SSRF via file_type query parameter injection in image endpoint — lemmyCWE-918 7.5 -2026-03-06
CVE-2026-30833 Rocket.Chat: NoSQL injection in the EE ddp-streamer-service — Rocket.ChatCWE-943 9.8 -2026-03-06
CVE-2026-26288 Everon api.everon.io Missing Authentication for Critical Function — api.everon.ioCWE-306 9.4 Critical2026-03-06
CVE-2026-2754 Navtor NavBox 安全漏洞 — NavBoxCWE-306 7.5 High2026-03-06
CVE-2026-2753 Navtor NavBox 安全漏洞 — NavBoxCWE-36 7.5 High2026-03-06

Vulnerabilities classified as access:pre-auth represent 18829 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.