Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18829

18829 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2018-25163 BitZoom 1.0 SQL Injection via rollno Parameter — BitZoomCWE-89 8.2 High2026-03-06
CVE-2026-3589 WooCommerce < 10.5.3 - Arbitrary Admin User Creation via CSRF — WooCommerce 8.8 -2026-03-06
CVE-2026-2331 CVE-2026-2331 — SICK Lector85xCWE-552 9.8 Critical2026-03-06
CVE-2026-2330 CVE-2026-2330 — SICK Lector85xCWE-552 9.4 Critical2026-03-06
CVE-2026-2830 WP All Import <= 4.0.0 - Reflected Cross-Site Scripting via 'filepath' — WP All Import – Drag & Drop Import for CSV, XML, Excel & Google SheetsCWE-94 6.1 Medium2026-03-06
CVE-2026-29183 SiYuan: Unauthenticated reflected SVG XSS in `/api/icon/getDynamicIcon` (`type=8`) enables arbitrary JavaScript execution — siyuanCWE-79 9.3 Critical2026-03-06
CVE-2026-29059 Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly — windmillCWE-22 7.5 -2026-03-06
CVE-2026-29058 AVideo: Unauthenticated OS Command Injection via base64Url in objects/getImage.php — AVideo-EncoderCWE-78 9.8 Critical2026-03-06
CVE-2026-2446 Powerpack for LearnDash < 1.3.0 - Unauthenticated Arbitrary Option Update — PowerPack for LearnDash 9.8 -2026-03-06
CVE-2026-28794 oRPC: Prototype Pollution in `@orpc/client` via `StandardRPCJsonSerializer` Deserialization — orpcCWE-1321 9.8 -2026-03-06
CVE-2026-28428 Talishar: Authentication Bypass via Empty authKey Parameter Allows Unauthenticated Game Actions — TalisharCWE-287 5.3 Medium2026-03-06
CVE-2026-28508 Idno: Unauthenticated SSRF via URL Unfurl Endpoint — idnoCWE-918 6.5 -2026-03-06
CVE-2026-27603 Chartbrew: Unauthenticated Chart Filter Endpoint: POST /project/:project_id/chart/:chart_id/filter missing verifyToken + checkPermissions — chartbrewCWE-306 5.3 -2026-03-06
CVE-2026-27005 Chartbrew: SQL injection in date-type variable handling (applyMysqlOrPostgresVariables) — chartbrewCWE-89 9.1 -2026-03-06
CVE-2026-28501 WWBN AVideo: Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php — AVideoCWE-89 9.8 Critical2026-03-06
CVE-2026-28497 TinyWeb: Integer Overflow in `_Val` (HTTP Request Smuggling) — TinyWebCWE-190 6.5 -2026-03-06
CVE-2026-3612 Wavlink WL-NU516U1 OTA Online Upgrade adm.cgi sub_405AF4 command injection — WL-NU516U1CWE-77 7.2 High2026-03-06
CVE-2025-70363 Ibexa eZ Platform 安全漏洞 — n/a 5.3 -2026-03-06
CVE-2026-2589 Greenshift – animation and page builder blocks <= 12.8.3 - Unauthenticated Sensitive Information Exposure via Settings Backup — Greenshift – animation and page builder blocksCWE-200 5.3 Medium2026-03-05
CVE-2026-22552 ePower epower.ie Missing Authentication for Critical Function — epower.ieCWE-306 9.4 Critical2026-03-05
CVE-2026-29613 OpenClaw < 2026.2.12 - Webhook Authentication Bypass via Loopback remoteAddress Trust — OpenClawCWE-306 5.9 Medium2026-03-05
CVE-2026-29606 OpenClaw < 2026.2.14 - Webhook Signature Verification Bypass via ngrok Loopback Compatibility — OpenClawCWE-306 6.5 Medium2026-03-05
CVE-2026-28485 OpenClaw 2026.1.5 < 2026.2.12 - Missing Authentication in Browser Control HTTP Endpoints — OpenClawCWE-306 8.4 High2026-03-05
CVE-2026-28478 OpenClaw < 2026.2.13 - Denial of Service via Unbounded Webhook Request Body Buffering — OpenClawCWE-770 7.5 High2026-03-05
CVE-2026-28454 OpenClaw < 2026.2.2 - Authorization Bypass via Unauthenticated Telegram Webhook — OpenClawCWE-345 7.5 High2026-03-05
CVE-2026-28450 OpenClaw < 2026.2.12 - Unauthenticated Profile Tampering via Nostr Plugin HTTP Endpoints — OpenClaw 6.8 Medium2026-03-05
CVE-2026-28790 OliveTin: Unauthenticated Action Termination via KillAction When Guests Must Login — OliveTinCWE-284 7.5 High2026-03-05
CVE-2026-28789 OliveTin: Unauthenticated DoS via concurrent map writes in OAuth2 state handling — OliveTinCWE-362 7.5 High2026-03-05
CVE-2026-28342 OliveTin: Unauthenticated Denial of Service via Memory Exhaustion in PasswordHash API Endpoint — OliveTinCWE-770 7.5 High2026-03-05
CVE-2026-3459 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.5 - Unauthenticated Arbitrary File Upload — Drag and Drop Multiple File Upload for Contact Form 7CWE-434 8.1 High2026-03-05

Vulnerabilities classified as access:pre-auth represent 18829 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.