Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18829

18829 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-1796 StyleBidet <= 1.0.0 - Reflected Cross-Site Scripting — StyleBidetCWE-79 6.1 Medium2026-02-14
CVE-2026-1932 Appointment Booking Calendar Plugin <= 1.0.2 - Missing Authorization to Unauthenticated Arbitrary Appointment Status Modification — Appointment Booking Calendar Plugin – BookrCWE-862 5.3 Medium2026-02-14
CVE-2026-0692 BlueSnap Payment Gateway for WooCommerce <= 3.4.0 - Missing Authorization to Unauthenticated Arbitrary Order Status Manipulation — BlueSnap Payment Gateway for WooCommerceCWE-862 7.5 High2026-02-14
CVE-2026-1983 SEATT: Simple Event Attendance <= 1.5.0 - Cross-Site Request Forgery to Arbitrary Event Deletion — SEATT: Simple Event AttendanceCWE-352 4.3 Medium2026-02-14
CVE-2026-1754 personal-authors-category <= 0.3 - Reflected Cross-Site Scripting — personal-authors-categoryCWE-79 6.1 Medium2026-02-14
CVE-2026-2144 Magic Login Mail or QR Code <= 2.05 - Unauthenticated Privilege Escalation via Insecure QR Code File Storage — Magic Login Mail or QR CodeCWE-269 8.1 High2026-02-14
CVE-2025-13973 StickEasy Protected Contact Form <= 1.0.1 - Unauthenticated Information Disclosure — StickEasy Protected Contact FormCWE-200 5.3 Medium2026-02-14
CVE-2026-26273 Known affected by Account Takeover via Password Reset Token Leakage — knownCWE-200 9.8AICriticalAI2026-02-13
CVE-2026-1841 PixelYourSite <= 11.2.0 - Unauthenticated Stored Cross-Site Scripting — PixelYourSite – Your smart PIXEL (TAG) & API ManagerCWE-79 7.2 High2026-02-13
CVE-2026-1844 PixelYourSite PRO <= 12.4.0.2 - Unauthenticated Stored Cross-Site Scripting — PixelYourSite Pro – Your smart PIXEL (TAG) ManagerCWE-79 7.2 High2026-02-13
CVE-2026-26333 Calero VeraSMART < 2022 R1 .NET Remoting Arbitrary File Read Leading to ViewState RCE — VeraSMARTCWE-306 9.1AICriticalAI2026-02-13
CVE-2026-26190 Milvus Allows Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise — milvusCWE-306 9.8 Critical2026-02-13
CVE-2026-26221 Hyland OnBase Timer Services Unauthenticated .NET Remoting RCE — OnBase Workflow Timer ServiceCWE-502 9.8 Critical2026-02-13
CVE-2025-69633 PrestaShop 安全漏洞 — n/a 9.8AICriticalAI2026-02-13
CVE-2019-25333 Bullwark Momentum Series JAWS 1.0 - 'Momentum Series JAWS' Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') — Momentum Series JAWSCWE-22 7.5 High2026-02-12
CVE-2019-25325 Thrive Smart Home 1.1 - 'Smart Home' Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') — Smart HomeCWE-89 8.2 High2026-02-12
CVE-2026-1358 Airleader Master Unrestricted Upload of File with Dangerous Type — Airleader MasterCWE-434 9.8 Critical2026-02-12
CVE-2026-26011 Critical Heap Out-of-bounds Access in `pf_cluster_stats()` via Malicious /initialpose Covariance -- Potential Remote Code Execution — navigation2CWE-787 8.8AIHighAI2026-02-12
CVE-2026-25949 Traefik: TCP readTimeout bypass via STARTTLS on Postgres — traefikCWE-400 7.5 High2026-02-12
CVE-2026-26218 newbee-mall Default Seeded Administrator Credentials Allow Account Takeover — newbee-mallCWE-798 9.8 Critical2026-02-12
CVE-2026-26217 Crawl4AI < 0.8.0 Docker API Local File Inclusion via file URL Handling — Crawl4AICWE-22 8.6 High2026-02-12
CVE-2026-26216 Crawl4AI < 0.8.0 Docker API Unauthenticated Remote Code Execution via Hooks Parameter — Crawl4AICWE-94 10.0 Critical2026-02-12
CVE-2026-1320 Secure Copy Content Protection and Content Locking <= 4.9.8 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header — Secure Copy Content Protection and Content LockingCWE-79 7.2 High2026-02-12
CVE-2026-1316 Customer Reviews for WooCommerce <= 5.97.0 - Unauthenticated Stored Cross-Site Scripting via media[].href Parameter — Customer Reviews for WooCommerceCWE-79 7.2 High2026-02-12
CVE-2026-1356 Converter for Media – Optimize images | Convert WebP & AVIF <= 6.5.1 - Unauthenticated Server-Side Request Forgery via src — Converter for Media – Optimize images | Convert WebP & AVIFCWE-918 4.8 Medium2026-02-12
CVE-2025-15577 Valmet DNA Web server arbitrary file read access — Valmet DNA Web ToolsCWE-22 7.5AIHighAI2026-02-12
CVE-2026-26235 JUNG Smart Visu Server 1.1.1050 - 'JUNG Smart Visu Server' Missing Authentication — JUNG Smart Visu ServerCWE-306 7.5 High2026-02-12
CVE-2026-26234 JUNG Smart Visu Server - Improper Neutralization of HTTP Headers for Scripting Syntax — JUNG Smart Visu ServerCWE-644 8.8 High2026-02-12
CVE-2026-1537 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure — LatePoint – Calendar Booking Plugin for Appointments and EventsCWE-862 5.3 Medium2026-02-12
CVE-2026-1729 AdForest <= 6.0.12 - Authentication Bypass — AdForestCWE-306 9.8 Critical2026-02-12

Vulnerabilities classified as access:pre-auth represent 18829 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.