Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18834

18834 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-14757 Cost Calculator Builder <= 3.6.9 - Missing Authorization to Unauthenticated Payment Status Bypass — Cost Calculator BuilderCWE-862 5.3 Medium2026-01-16
CVE-2026-1004 Essential Addons for Elementor <= 6.5.5 - Missing Authorization to Unauthenticated Sensitive Information Exposure — Essential Addons for Elementor – Popular Elementor Templates & WidgetsCWE-862 5.3 Medium2026-01-16
CVE-2025-14375 RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Reflected Cross-Site Scripting via className — RSS Aggregator – RSS Import, News Feeds, Feed to Post, and AutobloggingCWE-79 6.1 Medium2026-01-16
CVE-2025-14853 LEAV Last Email Address Validator <= 1.7.1 - Cross-Site Request Forgery to Plugin Settings Update — LEAV Last Email Address ValidatorCWE-352 4.3 Medium2026-01-16
CVE-2026-0939 Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit <= 5.1.2 - Unauthenticated Order Status Manipulation — Rede Itaú for WooCommerce — Payment PIX, Credit Card and DebitCWE-345 5.3 Medium2026-01-16
CVE-2026-0942 Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit <= 5.1.5 - Missing Authorization to Unauthenticated Rede Order Logs Deletion — Rede Itaú for WooCommerce — Payment PIX, Credit Card and DebitCWE-306 5.3 Medium2026-01-16
CVE-2025-12641 Awesome Support – WordPress HelpDesk & Support Plugin <= 6.3.6 - Missing Authorization to Unauthenticated Role Demotion — Awesome Support – WordPress HelpDesk & Support PluginCWE-862 6.5 Medium2026-01-16
CVE-2025-15526 Fancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Full Path Disclosure via 'pdf' Parameter — Fancy Product DesignerCWE-209 5.3 Medium2026-01-16
CVE-2026-1023 Gotac|Statistics Database System - Missing Authentication — Statistics Database SystemCWE-306 7.5 High2026-01-16
CVE-2026-1022 Gotac|Statistics Database System - Arbitrary File Read — Statistics Database SystemCWE-23 7.5 High2026-01-16
CVE-2026-1021 Gotac|Police Statistics Database System - Arbitrary File Upload — Police Statistics Database SystemCWE-434 9.8 Critical2026-01-16
CVE-2026-1020 Gotac|Police Statistics Database System - Absolute Path Traversal — Police Statistics Database SystemCWE-36 5.3 Medium2026-01-16
CVE-2026-1019 Gotac|Police Statistics Database System - Missing Authentication — Police Statistics Database SystemCWE-306 9.8 Critical2026-01-16
CVE-2026-1018 Gotac|Police Statistics Database System - Arbitrary File Read — Police Statistics Database SystemCWE-36 7.5 High2026-01-16
CVE-2025-61937 AVEVA Process Optimization Code Injection — Process OptimizationCWE-94 10.0 Critical2026-01-16
CVE-2021-47812 GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2) — GravCMSCWE-862 9.8 Critical2026-01-15
CVE-2021-47800 b2evolution 7.2.2 - 'edit account details' Cross-Site Request Forgery (CSRF) — b2evolutionCWE-352 5.3 Medium2026-01-15
CVE-2021-47796 Denver Smart Wifi Camera SHC-150 - 'Telnet' Remote Code Execution (RCE) — Smart Wifi CameraCWE-798 9.8 Critical2026-01-15
CVE-2026-22045 Traefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stall — traefikCWE-770 5.9 Medium2026-01-15
CVE-2011-10041 Uploadify <= 1.0 Unauthenticated Arbitrary File Upload — UploadifyCWE-434 9.8AICriticalAI2026-01-15
CVE-2026-21920 Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crash — Junos OSCWE-252 7.5 High2026-01-15
CVE-2026-21918 Junos OS: SRX and MX Series: When TCP packets occur in a specific sequence flowd crashes — Junos OSCWE-415 7.5 High2026-01-15
CVE-2026-21917 Junos OS: SRX Series: Specifically malformed SSL packet causes FPC crash — Junos OSCWE-1286 7.5 High2026-01-15
CVE-2026-21914 Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crash — Junos OSCWE-667 7.5 High2026-01-15
CVE-2026-21913 Junos OS: EX4000: A high volume of traffic destined to the device leads to a crash and restart — Junos OSCWE-1419 7.5 High2026-01-15
CVE-2026-21911 Junos OS Evolved: Flapping management interface causes MAC learning on label-switched interfaces to stop — Junos OS EvolvedCWE-682 6.5 Medium2026-01-15
CVE-2026-21910 Junos OS: EX4k Series, QFX5k Series: In an EVPN-VXLAN configuration link flaps cause Inter-VNI traffic drop — Junos OSCWE-754 6.5 Medium2026-01-15
CVE-2026-21909 Junos OS and Junos OS Evolved: Receipt of specific IS-IS update packet causes memory leak leading to RPD crash — Junos OSCWE-401 6.5 Medium2026-01-15
CVE-2026-21906 Junos OS: SRX Series: With GRE performance acceleration enabled, receipt of a specific ICMP packet causes the PFE to crash — Junos OSCWE-755 7.5 High2026-01-15
CVE-2026-21905 Junos OS: SRX Series, MX Series with MX-SPC3 or MS-MPC: Receipt of multiple specific SIP messages results in flow management process crash — Junos OSCWE-835 7.5 High2026-01-15

Vulnerabilities classified as access:pre-auth represent 18834 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.