Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18834

18834 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-0919 Unauthenticated Denial of Service via Oversized URL in HTTP Parser on TP-Link Tapo C220 & C520WS — Tapo C220 v1CWE-20 7.5AIHighAI2026-01-27
CVE-2026-0918 Null Pointer Dereference in Tapo SmartCam HTTP Service on TP-Link Tapo C220 & C520WS — Tapo C220 v1CWE-476 7.5AIHighAI2026-01-27
CVE-2025-69418 Unauthenticated/unencrypted trailing bytes with low-level OCB function calls — OpenSSLCWE-325 9.1AICriticalAI2026-01-27
CVE-2025-15469 'openssl dgst' one-shot codepath silently truncates inputs >16MB — OpenSSLCWE-347 9.1AICriticalAI2026-01-27
CVE-2025-68670 xrdp improperly checks bounds of domain string length, which leads to Stack-based Buffer Overflow — xrdpCWE-121 9.1 Critical2026-01-27
CVE-2021-47900 Gila CMS < 2.0.0 - Remote Code Execution — Gila CMSCWE-98 9.8 Critical2026-01-27
CVE-2020-36939 Cassandra Web 0.5.0 - Remote File Read — Cassandra WebCWE-22 7.5 High2026-01-27
CVE-2025-12386 Missing Authentication for Critical Endpoint in Pix-Link LV-WR21Q — LV-WR21QCWE-306 7.5AIHighAI2026-01-27
CVE-2025-14971 Link Invoice Payment for WooCommerce <= 2.8.0 - Missing Authorization to Unauthenticated Arbitrary Partial Payment Creation/Cancellation — Link Invoice Payment for WooCommerceCWE-862 5.3 Medium2026-01-27
CVE-2026-24477 AnythingLLM has key leak in `systemSettings.js` — anything-llmCWE-201 9.1AICriticalAI2026-01-26
CVE-2025-59472 Next.js 安全漏洞 — next 5.9 Medium2026-01-26
CVE-2025-57785 Double free in XSLT in 'show_index' — Hiawatha Web server 9.8AICriticalAI2026-01-26
CVE-2025-57783 Improper header parsing may lead to request smuggling — Hiawatha Web server 8.2AIHighAI2026-01-26
CVE-2026-24656 Apache Karaf: Decanter log-socket collector has deserialization vulnerability — Apache KarafCWE-502 9.1AICriticalAI2026-01-26
CVE-2025-6461 CubeWP – All-in-One Dynamic Content Framework <= 1.1.27 - Unauthenticated Post Disclosure in class-cubewp-search-ajax-hooks.php — CubeWP FrameworkCWE-200 4.3 Medium2026-01-25
CVE-2026-0862 Save as PDF Plugin by PDFCrowd <= 4.5.5 - Reflected Cross-Site Scripting via options — Save as PDF Plugin by PDFCrowdCWE-79 6.1 Medium2026-01-24
CVE-2025-13920 WP Directory Kit <= 1.4.9 - Unauthenticated Email Exposure via wdk_public_action — WP Directory KitCWE-200 5.3 Medium2026-01-24
CVE-2025-13205 SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 2.5.2 - Cross-Site Request Forgery to Survey Cloning — SurveyJS: Drag & Drop Form BuilderCWE-352 4.3 Medium2026-01-24
CVE-2026-1127 Timeline Event History <= 3.2 - Reflected Cross-Site Scripting — Timeline Event HistoryCWE-79 6.1 Medium2026-01-24
CVE-2025-13194 SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 2.5.2 - Cross-Site Request Forgery to Survey Renaming — SurveyJS: Drag & Drop Form BuilderCWE-352 4.3 Medium2026-01-24
CVE-2026-1208 Friendly Functions for Welcart <= 1.2.5 - Cross-Site Request Forgery to Settings Update — Friendly Functions for WelcartCWE-352 4.3 Medium2026-01-24
CVE-2025-13139 SurveyJS: Drag & Drop WordPress Form Builder <= 2.5.2 - Cross-Site Request Forgery to Survey Creation — SurveyJS: Drag & Drop Form BuilderCWE-352 4.3 Medium2026-01-24
CVE-2026-0633 MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 4.1.0 - Unauthenticated Form Submission Exposure via Forgeable Cookie Value — MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for ElementorCWE-287 3.7 Low2026-01-24
CVE-2025-14630 AdminQuickbar <= 1.9.3 - Cross-Site Request Forgery to Settings Update — AdminQuickbarCWE-352 4.3 Medium2026-01-24
CVE-2025-14907 Moderate Selected Posts <= 1.4 - Cross-Site Request Forgery to Plugin Settings Update — Moderate Selected PostsCWE-352 4.3 Medium2026-01-24
CVE-2026-0800 User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20251210 - Unauthenticated Stored Cross-Site Scripting via Custom Field — User Submitted Posts – Enable Users to Submit Posts from the Front EndCWE-79 7.2 High2026-01-24
CVE-2026-1088 Login Page Editor <= 1.2 - Cross-Site Request Forgery to Settings Update — Login Page EditorCWE-352 4.3 Medium2026-01-24
CVE-2025-13676 JustClick registration plugin <= 0.1 - Reflected Cross-Site Scripting via PHP_SELF — JustClick registration pluginCWE-79 6.1 Medium2026-01-24
CVE-2025-14609 Wise Analytics <= 1.1.9 - Missing Authorization to Unauthenticated Arbitrary Analytics Database Disclosure via 'name' Parameter — Wise AnalyticsCWE-862 5.3 Medium2026-01-24
CVE-2025-14843 Wizit Gateway for WooCommerce <= 1.2.9 - Missing Authentication to Unauthenticated Arbitrary Order Cancellation — Wizit Gateway for WooCommerceCWE-862 5.3 Medium2026-01-24

Vulnerabilities classified as access:pre-auth represent 18834 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.