Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18832

18832 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-1117 Improper Access Control in parisneo/lollms — parisneo/lollmsCWE-284 8.1AIHighAI2026-02-02
CVE-2025-15030 User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset — User Profile Builder 8.1AIHighAI2026-02-02
CVE-2026-1746 JeecgBoot Online Report API loadDictItemByKeyword sql injection — JeecgBootCWE-89 6.3 Medium2026-02-02
CVE-2026-25201 SAMSUNG MagicINFO 9 Server 安全漏洞 — MagicINFO 9 ServerCWE-434 8.8 High2026-02-02
CVE-2026-25200 SAMSUNG MagicINFO 9 Server 安全漏洞 — MagicINFO 9 ServerCWE-434 9.8 Critical2026-02-02
CVE-2026-1742 EFM ipTIME A8004T VPN Service timepro.cgi commit_vpncli_file_upload unrestricted upload — ipTIME A8004TCWE-434 4.7 Medium2026-02-02
CVE-2026-1739 Free5GC pcf smpolicy.go HandleCreateSmPolicyRequest null pointer dereference — pcfCWE-476 5.3 Medium2026-02-02
CVE-2026-1738 Open5GS SGWC context.c sgwc_tunnel_add assertion — Open5GSCWE-617 5.3 Medium2026-02-02
CVE-2026-1736 Open5GS SGWC s11-handler.c assertion — Open5GSCWE-617 5.3 Medium2026-02-02
CVE-2022-50950 Webile 1.0.1 Directory Traversal Vulnerability via Web Application — WebileCWE-22 6.5 Medium2026-02-01
CVE-2026-25069 SunFounder Pironman Dashboard <= 1.3.13 Path Traversal Arbitrary File Read/Deletion — Pironman Dashboard (pm_dashboard)CWE-22 9.8AICriticalAI2026-01-31
CVE-2026-1165 Popup Box <= 6.1.1 - Cross-Site Request Forgery to Popup Status Change — Popup Box – Create Countdown, Coupon, Video, Contact Form PopupsCWE-352 4.3 Medium2026-01-31
CVE-2025-14554 Sell BTC - Cryptocurrency Selling Calculator <= 1.5 - Unauthenticated Stored Cross-Site Scripting via 'orderform_data' AJAX Action — Sell BTC – Cryptocurrency Selling CalculatorCWE-79 7.2 High2026-01-31
CVE-2025-15525 Ajax Load More – Infinite Scroll, Lazy Load & Load More <= 7.8.1 - Incorrect Authorization to Unauthenticated Private/Draft Post Title and Excerpt Exposure — Ajax Load More – Infinite Scroll, Load More, & Lazy LoadCWE-863 5.3 Medium2026-01-31
CVE-2026-1431 Booking Calendar <= 10.14.13 - Missing Authorization to Unauthenticated Booking Details Exposure — Booking CalendarCWE-862 5.3 Medium2026-01-31
CVE-2025-15510 NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposure — NEX-Forms – Ultimate Forms Plugin for WordPressCWE-862 5.3 Medium2026-01-31
CVE-2020-37052 AirControl 1.4.2 - PreAuth Remote Code Execution — AirControlCWE-94 9.8 Critical2026-01-30
CVE-2020-37041 OpenCTI 3.3.1 - Directory Traversal — OpenCTICWE-22 7.5 High2026-01-30
CVE-2020-37027 Sickbeard 0.1 - Remote Command Injection — SickbeardCWE-78 9.8 Critical2026-01-30
CVE-2026-1498 WatchGuard Firebox LDAP Injection — Fireware OSCWE-90 7.5AIHighAI2026-01-30
CVE-2025-51958 runcommand 安全漏洞 — n/a 9.8AICriticalAI2026-01-30
CVE-2026-25116 Runtipi vulnerable to unauthenticated docker-compose.yml Overwrite via Path Traversal — runtipiCWE-22 7.6 High2026-01-29
CVE-2026-1340 Ivanti Endpoint Manager Mobile 代码注入漏洞 — Endpoint Manager MobileCWE-94 9.8 Critical2026-01-29
CVE-2026-1281 Ivanti Endpoint Manager Mobile 代码注入漏洞 — Endpoint Manager MobileCWE-94 9.8 Critical2026-01-29
CVE-2026-1453 Missing Authentication for Critical Function in KiloView Encoder Series — Encoder Series E1 hardware Version 1.4CWE-306 9.8 Critical2026-01-29
CVE-2020-37012 Tea LaTex 1.0 - Remote Code Execution — Tea LaTexCWE-78 9.8 Critical2026-01-29
CVE-2020-37015 Ruijie Networks Switch eWeb S29_RGOS 11.4 - Directory Traversal — Ruijie Networks Switch eWeb S29_RGOSCWE-22 7.5 High2026-01-29
CVE-2025-14975 Custom Login Page Customizer < 2.5.4 - Unauthenticated Arbitrary Password Reset — Custom Login Page Customizer 8.1AIHighAI2026-01-29
CVE-2026-25067 SmarterTools SmarterMail < Build 9518 Unauthenticated background-of-the-day Path Coercion — SmarterMailCWE-706 9.8AICriticalAI2026-01-29
CVE-2026-1544 D-Link DIR-823X set_mode sub_41E2A0 os command injection — DIR-823XCWE-78 6.3 Medium2026-01-28

Vulnerabilities classified as access:pre-auth represent 18832 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.