Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18832

18832 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-14629 Alchemist Ajax Upload <= 1.1 - Missing Authorization to Unauthenticated Arbitrary Media File Deletion — Alchemist Ajax UploadCWE-862 5.3 Medium2026-01-24
CVE-2025-13374 Kalrav AI Agent <= 2.3.3 - Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action — Kalrav AI AgentCWE-434 9.8 Critical2026-01-24
CVE-2025-14906 WP Youtube Video Gallery <= 1.0 - Cross-Site Request Forgery to Plugin Settings Update — WP Youtube Video GalleryCWE-352 4.3 Medium2026-01-24
CVE-2026-1076 Star Review Manager <= 1.2.2 - Cross-Site Request Forgery to Settings Update — Star Review ManagerCWE-352 4.3 Medium2026-01-24
CVE-2026-0807 Frontis Blocks <= 1.1.6 - Unauthenticated Server-Side Request Forgery via 'url' Parameter — Frontis Blocks — Block Library for the Block EditorCWE-918 7.2 High2026-01-24
CVE-2026-1070 Alex User Counter <= 6.0 - Cross-Site Request Forgery to Settings Update — Alex User CounterCWE-352 4.3 Medium2026-01-24
CVE-2025-14903 Simple Crypto Shortcodes <= 1.0.2 - Cross-Site Request Forgery to Plugin Settings Update — Simple Crypto ShortcodesCWE-352 4.3 Medium2026-01-24
CVE-2026-24469 C++ HTTP Server has Critical Path Traversal Vulnerability in RequestHandler Allowing Arbitrary File Read — http-serverCWE-22 7.5 High2026-01-24
CVE-2026-24136 Saleor has an Insecure Direct Object Reference (IDOR) in GraphQL API — saleorCWE-639 7.5 -2026-01-23
CVE-2025-14947 All-in-One Video Gallery <= 4.6.4 - Missing Authorization to Unauthenticated Bunny Stream Video Creation/Deletion — All-in-One Video GalleryCWE-862 6.5 Medium2026-01-23
CVE-2026-24423 SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API — SmarterMailCWE-306 9.8 -2026-01-23
CVE-2026-22274 Dell ECS 安全漏洞 — ObjectScaleCWE-319 6.5 Medium2026-01-23
CVE-2026-22271 Dell ECS 安全漏洞 — ObjectScaleCWE-319 7.5 High2026-01-23
CVE-2026-1364 JNC|IAQS and I6 - Missing Authentication — IAQSCWE-306 9.8 Critical2026-01-23
CVE-2026-1363 JNC|IAQS and I6 - Client-Side Enforcement of Server-Side Security — IAQSCWE-603 9.8 Critical2026-01-23
CVE-2024-11976 BuddyPress <= 14.3.3 - Unauthenticated Arbitrary Shortcode Execution — BuddyPressCWE-94 7.3 High2026-01-23
CVE-2026-0927 KiviCare – Clinic & Patient Management System (EHR) <= 3.6.15 - Missing Authorization to Unauthenticated Limited Arbitrary File Upload — KiviCare – Clinic & Patient Management System (EHR)CWE-862 5.3 Medium2026-01-23
CVE-2026-24138 FOG vulnerable to unauthenticated SSRF via `/fog/service/getversion.php` — fogprojectCWE-918 7.5 High2026-01-23
CVE-2025-52022 Aptsys gemscms POS Platform 安全漏洞 — n/a 5.3 -2026-01-23
CVE-2025-52023 Aptsys gemscms POS Platform 安全漏洞 — n/a 5.3 -2026-01-23
CVE-2025-52024 Aptsys gemscms POS Platform 安全漏洞 — n/a 9.4 -2026-01-23
CVE-2025-52026 Aptsys gemscms POS Platform 安全漏洞 — n/a 9.8 -2026-01-23
CVE-2025-67229 ToDesktop Builder 安全漏洞 — n/a 7.5 -2026-01-23
CVE-2025-69907 Newgen OmniDocs 安全漏洞 — n/a 5.3 -2026-01-23
CVE-2025-69908 Newgen OmniApp 安全漏洞 — n/a 5.3 -2026-01-23
CVE-2025-70457 SourceCodester Modern Image Gallery App 安全漏洞 — n/a 9.8 -2026-01-23
CVE-2022-25369 DynamicWeb 安全漏洞 — n/a 9.8 -2026-01-23
CVE-2026-21520 Copilot Studio Information Disclosure Vulnerability — Microsoft Copilot StudioCWE-77 7.5 High2026-01-22
CVE-2026-24124 Dragonfly Manager Job API Allows Unauthenticated Access — dragonflyCWE-306 9.8 -2026-01-22
CVE-2025-68609 Authentication bypass in Aries due to misconfiguration — com.palantir.aries:ariesCWE-305 6.6 Medium2026-01-22

Vulnerabilities classified as access:pre-auth represent 18832 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.