Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18829

18829 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-3378 Tenda F453 qossetting fromqossetting buffer overflow — F453CWE-120 8.8 High2026-03-01
CVE-2026-28562 wpForo Forum 2.4.14 SQL Injection via Topics ORDER BY Parameter — wpForo ForumCWE-89 8.2 High2026-02-28
CVE-2026-28559 wpForo Forum 2.4.14 Information Disclosure via Global RSS Feed — wpForo ForumCWE-200 5.3 Medium2026-02-28
CVE-2025-13673 Tutor LMS <= 3.9.6 - Unauthenticated SQL Injection via coupon_code — Tutor LMS – eLearning and online course solutionCWE-89 7.5 High2026-02-28
CVE-2026-2471 WP Mail Logging <= 1.15.0 - Unauthenticated PHP Object Injection via Email Log Message Field — WP Mail LoggingCWE-502 7.5 High2026-02-28
CVE-2026-1542 Super Stage WP <= 1.0.1 - Unauthenticated PHP Object Injection — Super Stage WP 9.8 -2026-02-28
CVE-2026-28423 Statamic Vulnerable to Server-Side Request Forgery via Glide — cmsCWE-918 6.8 Medium2026-02-27
CVE-2026-28515 openDCIM <= 23.04 Missing Authorization in install.php — openDCIMCWE-862 8.8 -2026-02-27
CVE-2026-28411 WeGIA Vulnerable to Authentication Bypass via `extract($_REQUEST)` — WeGIACWE-288 9.8 Critical2026-02-27
CVE-2026-28414 Gradio has Absolute Path Traversal on Windows with Python 3.13+ — gradioCWE-36 7.5 High2026-02-27
CVE-2026-28400 Docker Model Runner Unauthenticated Runtime Flag Injection via _configure Endpoint — model-runnerCWE-749 7.6 High2026-02-27
CVE-2026-28352 Indico missing access check in event series management API — indicoCWE-306 6.5 Medium2026-02-27
CVE-2026-27836 phpMyFAQ Allows Unauthenticated Account Creation via WebAuthn Prepare Endpoint — phpMyFAQCWE-862 7.5 High2026-02-27
CVE-2026-27793 Seerr has Broken Object-Level Authorization in User Profile Endpoint that Exposes Third-Party Notification Credentials — seerrCWE-639 6.5 Medium2026-02-27
CVE-2026-27707 Plex-configured Seerr instances vulnerable to unauthenticated account registration via Jellyfin authentication endpoint — seerrCWE-288 7.3 High2026-02-27
CVE-2019-25497 osCommerce 2.3.4.1 SQL Injection via currency Parameter — osCommerceCWE-89 8.2 High2026-02-27
CVE-2019-25496 osCommerce 2.3.4.1 SQL Injection via products_id Parameter — osCommerceCWE-89 8.2 High2026-02-27
CVE-2019-25495 osCommerce 2.3.4.1 SQL Injection via reviews_id Parameter — osCommerceCWE-89 8.2 High2026-02-27
CVE-2019-25494 Homey BNB V4 SQL Injection Authentication Bypass via Admin Panel — Homey BNB (Airbnb Clone Script)CWE-89 8.2 High2026-02-27
CVE-2019-25493 Homey BNB V4 SQL Injection via getrecord.php — Homey BNB (Airbnb Clone Script)CWE-89 8.2 High2026-02-27
CVE-2019-25492 Homey BNB V4 SQL Injection via getcmsdata.php — Homey BNB (Airbnb Clone Script)CWE-89 8.2 High2026-02-27
CVE-2019-25491 Homey BNB V4 SQL Injection via cms_getpagetitle.php — Homey BNB (Airbnb Clone Script)CWE-89 8.2 High2026-02-27
CVE-2019-25490 Homey BNB V4 SQL Injection via admin edit.php — Homey BNB (Airbnb Clone Script)CWE-89 8.2 High2026-02-27
CVE-2019-25489 Homey BNB V4 SQL Injection via ajax_refresh_subtotal — Homey BNB (Airbnb Clone Script)CWE-89 8.2 High2026-02-27
CVE-2025-15498 SQL Injection in Pro3W CMS — Pro3W CMSCWE-89 9.8 -2026-02-27
CVE-2026-1305 Japanized for WooCommerce <= 2.8.4 - Missing Authorization to Unauthenticated Paidy Order Manipulation — Japanized for WooCommerceCWE-287 5.3 Medium2026-02-27
CVE-2026-21659 Johnson Controls -Frick Quantum HD-Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion — Frick Controls Quantum HDCWE-23 9.8 -2026-02-27
CVE-2026-21658 Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution — Frick Controls Quantum HDCWE-94 9.8 -2026-02-27
CVE-2025-12981 Listee <= 1.1.6 - Unauthenticated Privilege Escalation — ListeeCWE-269 9.8 Critical2026-02-27
CVE-2026-1558 WP Recipe Maker <= 10.3.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Metadata Modification via 'recipeId' Parameter — WP Recipe MakerCWE-639 5.3 Medium2026-02-27

Vulnerabilities classified as access:pre-auth represent 18829 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.