Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18802

18802 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-5963 Digiwin|EasyFlow .NET - SQL Injection — EasyFlow .NETCWE-89 9.8 Critical2026-04-20
CVE-2026-6604 modelscope agentscope Cloud Metadata Endpoint _openai_tools.py openai_audio_to_text server-side request forgery — agentscopeCWE-918 7.3 High2026-04-20
CVE-2026-32957 Silex SD-330AC和Silex AMC Manager 安全漏洞 — SD-330ACCWE-306 5.3 Medium2026-04-20
CVE-2026-32962 Silex SD-330AC和Silex AMC Manager 安全漏洞 — SD-330ACCWE-306 5.3 Medium2026-04-20
CVE-2026-39109 PHPGurukul Apartment Visitors Management System 安全漏洞 — n/a 7.5AIHighAI2026-04-20
CVE-2026-39110 PHPGurukul Apartment Visitors Management System 安全漏洞 — n/a 7.5AIHighAI2026-04-20
CVE-2026-39111 PHPGurukul Apartment Visitors Management System 安全漏洞 — n/a 9.1AICriticalAI2026-04-20
CVE-2025-66954 Buffalo LinkStation 安全漏洞 — n/a 5.3AIMediumAI2026-04-20
CVE-2026-6571 kodcloud KodExplorer systemRole.class.php roleGroupAction authorization — KodExplorerCWE-639 6.3 Medium2026-04-19
CVE-2026-1838 Hostel <= 1.1.6 - Reflected Cross-Site Scripting via 'shortcode_id' Parameter — HostelCWE-79 6.1 Medium2026-04-18
CVE-2026-40485 ChurchCRM: Username Enumeration via Differential Response in Public Login API — CRMCWE-307 5.3 Medium2026-04-17
CVE-2026-2262 Easy Appointments <= 3.12.21 - Unauthenticated Sensitive Information Exposure via REST API — Easy AppointmentsCWE-200 7.5 High2026-04-17
CVE-2026-40481 monetr: Unauthenticated Stripe webhook reads attacker-sized request bodies before signature validation — monetrCWE-400 7.5AIHighAI2026-04-17
CVE-2026-40478 Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf — thymeleafCWE-917 9.1 Critical2026-04-17
CVE-2026-40477 Improper restriction of the scope of accessible objects in Thymeleaf expressions — thymeleafCWE-917 9.1 Critical2026-04-17
CVE-2026-40321 DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload — Dnn.PlatformCWE-87 8.1 High2026-04-17
CVE-2026-40351 FastGPT: NoSQL Injection in loginByPassword leads to Authentication Bypass — FastGPTCWE-943 9.8 Critical2026-04-17
CVE-2026-40303 zrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsing — zrokCWE-400 7.5 High2026-04-17
CVE-2026-33689 xrdp: Pre-authentication out-of-bounds reads in channel parsers — xrdpCWE-125 8.2AIHighAI2026-04-17
CVE-2026-32624 xrdp: Heap buffer overflow in xrdp_sec_process_logon_info() via incorrect g_strncat length calculation — xrdpCWE-122 9.8AICriticalAI2026-04-17
CVE-2026-33516 xrdp: Pre-authentication out-of-bounds reads in RDP capability and channel parsers — xrdpCWE-125 9.1AICriticalAI2026-04-17
CVE-2026-40066 Anviz Products Download of Code Without Integrity Check — Anviz CX7 FirmwareCWE-494 8.8 High2026-04-17
CVE-2026-35546 Anviz Products Missing Authentication for Critical Function — Anviz CX7 FirmwareCWE-306 9.8 Critical2026-04-17
CVE-2026-40461 Anviz Products Missing Authentication for Critical Function — Anviz CX7 FirmwareCWE-306 7.5 High2026-04-17
CVE-2026-32648 Anviz Products Missing Authorization — Anviz CX7 FirmwareCWE-862 5.3 Medium2026-04-17
CVE-2026-32105 xrdp: RDP MAC signature (dataSignature) never verified on receive — integrity bypass in non-TLS mode — xrdpCWE-354 5.9AIMediumAI2026-04-17
CVE-2026-35061 Anviz Products Missing Authorization — Anviz CX7 FirmwareCWE-862 5.3 Medium2026-04-17
CVE-2026-33093 Anviz Products Missing Authorization — Anviz CX7 FirmwareCWE-862 5.3 Medium2026-04-17
CVE-2026-35215 Firebird: DoS via malicious slice descriptor in slice packet — firebirdCWE-369 7.5 High2026-04-17
CVE-2026-34232 Firebird: DoS via `op_response` packet from client — firebirdCWE-228 7.5 High2026-04-17

Vulnerabilities classified as access:pre-auth represent 18802 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.