Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18829

18829 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-28775 Unauthenticated RCE via SNMP Default Writable Community String — SFX2100 Series SuperFlex SatelliteReceiverCWE-1188 9.8AICriticalAI2026-03-04
CVE-2026-2025 Mail Mint < 1.19.5 - Unauthenticated Emails Disclosure — Mail Mint 5.3AIMediumAI2026-03-04
CVE-2026-1980 WPBookit <= 1.0.8 - Missing Authorization to Unauthenticated Sensitive Customer Data Exposure — WPBookitCWE-200 5.3 Medium2026-03-04
CVE-2026-1945 WPBookit <= 1.0.8 - Unauthenticated Stored Cross-Site Scripting via 'wpb_user_name' and 'wpb_user_email' Parameters — WPBookitCWE-79 7.2 High2026-03-04
CVE-2025-70342 erase-install 安全漏洞 — n/a 7.5AIHighAI2026-03-04
CVE-2025-69969 SRK Powertech Pebble Prism Ultra 安全漏洞 — n/a 8.8AIHighAI2026-03-04
CVE-2026-27971 Qwik affected by unauthenticated RCE via server$ Deserialization — qwikCWE-502 9.8AICriticalAI2026-03-03
CVE-2026-27932 joserfc PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS) — joserfcCWE-770 7.5 High2026-03-03
CVE-2026-3266 Improper access control vulnerability has been discovered in OpenText™ Filr. — FilrCWE-862 9.1AICriticalAI2026-03-03
CVE-2026-24898 OpenEMR has an Unauthenticated MedEx Token Disclosure — openemrCWE-287 10.0 Critical2026-03-03
CVE-2026-3224 Devolutions Server 安全漏洞 — ServerCWE-287 9.8AICriticalAI2026-03-03
CVE-2026-1775 Missing Authentication for Critical Function in Labkotec LID-3300IP — LID-3300IPCWE-306 9.8AICriticalAI2026-03-03
CVE-2026-2568 WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.5 - Unauthenticated Stored Cross-Site Scripting — WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja FormsCWE-79 7.2 High2026-03-03
CVE-2026-1492 User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration — User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login BuilderCWE-269 9.8 Critical2026-03-03
CVE-2026-2628 All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login <= 2.2.5 - Authentication Bypass — All-in-One Microsoft 365 & Entra ID / Azure AD SSO LoginCWE-288 9.8 Critical2026-03-03
CVE-2024-55019 Weintek cMT 安全漏洞 — n/a 7.5AIHighAI2026-03-03
CVE-2026-1336 AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.5 - Missing Authorization to Unauthenticated API Key Modification — AI ChatBot with ChatGPT and Content Generator by AYSCWE-862 5.3 Medium2026-03-02
CVE-2026-3338 PKCS7_verify Signature Validation Bypass in AWS-LC — AWS-LCCWE-347 7.5 High2026-03-02
CVE-2026-3337 Timing Side-Channel in AES-CCM Tag Verification in AWS-LC — AWS-LCCWE-208 5.9 Medium2026-03-02
CVE-2026-3336 PKCS7_verify Certificate Chain Validation Bypass in AWS-LC — AWS-LCCWE-295 7.5 High2026-03-02
CVE-2026-3180 Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection — Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & StripeCWE-89 7.5 High2026-03-02
CVE-2024-50337 Chamilo: Potential unauthenticated blind SSRF via openid function — chamilo-lmsCWE-918 5.3 Medium2026-03-02
CVE-2026-3432 Sim Studio AI - Unauthenticated OAuth Token Theft — simCWE-862 7.5AIHighAI2026-03-02
CVE-2026-3431 Sim Studio AI - MongoDB SSRF and Arbitrary Document Deletion — simCWE-862 9.8 Critical2026-03-02
CVE-2025-14532 Remote Code Execution via Unrestricted File Upload in DobryCMS — DobryCMSCWE-434 9.8AICriticalAI2026-03-02
CVE-2025-12462 Blind SQL Injection in DobryCMS — DobryCMSCWE-89 9.8AICriticalAI2026-03-02
CVE-2026-2584 SQL Injection in Ciser System SL firmware — CSIP firmwareCWE-89 5.3AIMediumAI2026-03-02
CVE-2026-3422 e-Excellence|U-Office Force - Insecure Deserialization — U-Office ForceCWE-502 9.8 Critical2026-03-02
CVE-2026-3000 Changing|IDExpert Windows Logon Agent - Remote Code Execution — IDExpert Windows Logon AgentCWE-494 9.8 Critical2026-03-02
CVE-2026-2999 Changing|IDExpert Windows Logon Agent - Remote Code Execution — IDExpert Windows Logon AgentCWE-494 9.8 Critical2026-03-02

Vulnerabilities classified as access:pre-auth represent 18829 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.