Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18832

18832 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2020-36963 Intelbras Router RF 301K 1.1.2 - Authentication Bypass — Intelbras Router RF 301KCWE-306 7.5 High2026-01-28
CVE-2020-36945 WebDamn User Registration & Login System with User Panel - SQLi Auth Bypass — WebDamn User Registration & Login System with User PanelCWE-89 8.2 High2026-01-28
CVE-2025-57792 SQL Injection Vulnerability in Explorance Blue — BlueCWE-89 9.8AICriticalAI2026-01-28
CVE-2025-57793 SQL Injection Vulnerability in Explorance Blue — BlueCWE-89 9.8AICriticalAI2026-01-28
CVE-2026-1060 WP Adminify <= 4.0.7.7 - Unauthenticated Sensitive Information Exposure via 'get-addons-list' REST API — WP Adminify – White Label WordPress, Admin Menu Editor, Login CustomizerCWE-200 5.3 Medium2026-01-28
CVE-2025-14795 Stop Spammers Classic <= 2026.1 - Cross-Site Request Forgery via Email Allowlist — Stop Spammers ClassicCWE-352 4.3 Medium2026-01-28
CVE-2026-1056 Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal — Snow Monkey FormsCWE-22 9.8 Critical2026-01-28
CVE-2026-1398 Change WP URL <= 1.0 - Cross-Site Request Forgery to Settings Update — Change WP URLCWE-352 4.3 Medium2026-01-28
CVE-2025-14616 Recooty <= 1.0.6 - Cross-Site Request Forgery to Settings Update — Recooty – Job Widget (Old Dashboard)CWE-352 4.3 Medium2026-01-28
CVE-2026-1280 Frontend File Manager Plugin <= 23.5 - Missing Authorization to Unauthenticated Arbitrary File Sharing via 'file_id' Parameter — Frontend File Manager PluginCWE-862 7.5 High2026-01-28
CVE-2025-14063 SEO Links Interlinking <= 1.7.9.9.1 - Reflected Cross-Site Scripting via 'google_error' Parameter — SEO Links InterlinkingCWE-79 6.1 Medium2026-01-28
CVE-2026-1380 Bitcoin Donate Button <= 1.0 - Cross-Site Request Forgery to Settings Update — Bitcoin Donate ButtonCWE-352 4.3 Medium2026-01-28
CVE-2026-1391 Vzaar Media Management <= 1.2 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — Vzaar Media ManagementCWE-79 5.3 Medium2026-01-28
CVE-2026-1377 imwptip <= 1.1 - Cross-Site Request Forgery to Settings Update — imwptipCWE-352 4.3 Medium2026-01-28
CVE-2025-15511 Rupantorpay <= 2.0.0 - Missing Authorization to Unauthenticated Order Status Modification — RupantorpayCWE-862 5.3 Medium2026-01-28
CVE-2026-0702 VidShop – Shoppable Videos for WooCommerce <= 1.1.4 - Unauthenticated Time-Based SQL Injection via 'fields' — VidShop – Shoppable Videos for WooCommerceCWE-89 7.5 High2026-01-28
CVE-2025-40553 SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability — Web Help DeskCWE-502 9.8 Critical2026-01-28
CVE-2025-40551 SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability — Web Help DeskCWE-502 9.8 Critical2026-01-28
CVE-2025-40536 SolarWinds Web Help Desk Security Control Bypass Vulnerability — Web Help DeskCWE-693 8.1 High2026-01-28
CVE-2026-1054 RegistrationMagic <= 6.0.7.4 - Missing Authorization to Unauthenticated Arbitrary Settings Modification — RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User LoginCWE-862 5.3 Medium2026-01-28
CVE-2026-0832 New User Approve <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary User Approval, Denial, and Information Disclosure — New User ApproveCWE-862 7.3 High2026-01-28
CVE-2026-1310 Simple calendar for Elementor <= 1.6.6 - Missing Authorization to Unauthenticated Arbitrary Calendar Entry Deletion — Simple calendar for ElementorCWE-862 5.3 Medium2026-01-28
CVE-2026-0825 Database for Contact Form 7, WPforms, Elementor forms <= 1.4.5 - Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export — Database for Contact Form 7, WPforms, Elementor formsCWE-862 5.3 Medium2026-01-28
CVE-2025-13471 User Activity Log <= 2.2 - Unauthenticated Limited Arbitrary Option Update — User Activity Log 7.5AIHighAI2026-01-28
CVE-2022-40619 NETGEAR多款产品 安全漏洞 — n/a 8.8AIHighAI2026-01-28
CVE-2026-24748 Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access — kargoCWE-863 5.3AIMediumAI2026-01-27
CVE-2026-23593 Unauthenticated Limited File Read allows Data Exposure in Web Interface — HPE Aruba Networking Fabric Composer 7.5 High2026-01-27
CVE-2026-1315 Unauthenticated Denial of Service via Firmware Update Endpoint on TP-Link Tapo C220 & C520WS — Tapo C220 v1CWE-20 6.5AIMediumAI2026-01-27
CVE-2026-0919 Unauthenticated Denial of Service via Oversized URL in HTTP Parser on TP-Link Tapo C220 & C520WS — Tapo C220 v1CWE-20 7.5AIHighAI2026-01-27
CVE-2026-0918 Null Pointer Dereference in Tapo SmartCam HTTP Service on TP-Link Tapo C220 & C520WS — Tapo C220 v1CWE-476 7.5AIHighAI2026-01-27

Vulnerabilities classified as access:pre-auth represent 18832 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.