Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18834

18834 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-0203 Junos OS: Receipt of a specifically malformed ICMP packet causes an FPC restart — Junos OSCWE-755 6.5 Medium2026-01-15
CVE-2025-60011 Junos OS and Junos OS Evolved: Optional transitive BGP attribute is modified before propagation to peers causing sessions to flap — Junos OSCWE-754 5.8 Medium2026-01-15
CVE-2025-60003 Junos OS and Junos OS Evolved: BGP update with a set of specific attributes causes rpd crash — Junos OSCWE-126 7.5 High2026-01-15
CVE-2026-23746 Entrust Instant Financial Issuance (IFI) SmartCardController Service .NET Remoting RCE — Instant Financial Issuance (IF)CWE-306 9.1AICriticalAI2026-01-15
CVE-2026-23511 ZITADEL has a user enumeration vulnerability in Login UIs — zitadelCWE-204 5.3 Medium2026-01-15
CVE-2026-0227 PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal — Cloud NGFWCWE-754 7.5AIHighAI2026-01-15
CVE-2025-9014 Null Pointer Dereference Vulnerability on TL-WR841N — TL-WR841N v14CWE-20 7.5AIHighAI2026-01-15
CVE-2025-62193 NOAA PMEL Live Access Server (LAS) PyFerret command injection — Live Access Server (LAS)CWE-78 9.8 Critical2026-01-15
CVE-2025-66417 GLPI has an unauthenticated SQL injection through the inventory endpoint — glpiCWE-89 7.5 High2026-01-15
CVE-2021-47777 Build Smart ERP 21.0817 - 'eidValue' SQL Injection (Unauthenticated) — Build Smart ERPCWE-89 8.2 High2026-01-15
CVE-2021-47754 Arunna 1.0.0 - 'Multiple' Cross-Site Request Forgery (CSRF) — ArunnaCWE-352 6.5 Medium2026-01-15
CVE-2021-47755 Oliver Library Server v5 - Arbitrary File Download — Oliver Library ServerCWE-22 7.5 High2026-01-15
CVE-2021-47753 phpKF CMS 3.00 Beta y6 - Remote Code Execution (RCE) (Unauthenticated) — phpKF CMSCWE-434 9.8 Critical2026-01-15
CVE-2025-12895 Kalium <= 3.29 - Missing Authorization to Unauthenticated Mail Relay via kalium_vc_contact_form_request — Kalium 3 | Creative WordPress & WooCommerce ThemeCWE-862 5.3 Medium2026-01-15
CVE-2026-22645 SICK Incoming Goods Suite 安全漏洞 — Incoming Goods SuiteCWE-200 5.3 Medium2026-01-15
CVE-2025-14457 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthenticated File Deletion — Drag and Drop Multiple File Upload for Contact Form 7CWE-862 3.7 Low2026-01-15
CVE-2025-67076 Omnispace Agora Project 安全漏洞 — n/a 7.5AIHighAI2026-01-15
CVE-2025-67083 InvoicePlane 安全漏洞 — n/a 7.5AIHighAI2026-01-15
CVE-2025-67822 Mitel MiVoice MX-ONE 安全漏洞 — n/a 9.8AICriticalAI2026-01-15
CVE-2025-67823 Mitel MiContact Center Business 安全漏洞 — n/a 6.1AIMediumAI2026-01-15
CVE-2025-12166 Simply Schedule Appointments <= 1.6.9.9 - Unauthenticated SQL Injection via `order` and `append_where_sql` Parameters — Appointment Booking Calendar — Simply Schedule Appointments Booking PluginCWE-89 7.5 High2026-01-14
CVE-2026-0601 Nexus Repository 3 - Cross-Site Scripting — Nexus RepositoryCWE-79 6.1AIMediumAI2026-01-14
CVE-2026-21889 Weblate leaks information via screenshots — weblateCWE-284 5.3AIMediumAI2026-01-14
CVE-2025-37184 Unauthenticated Bypass Allows Multi-Factor Authentication Circumvention — EdgeConnect SD-WAN Orchestrator 9.8 Critical2026-01-14
CVE-2026-22240 Plaintext Passwords Vulnerability in BLUVOYIX — BLUVOYIXCWE-312 9.8AICriticalAI2026-01-14
CVE-2026-22239 Email Sending Vulnerability in BLUVOYIX — BLUVOYIXCWE-400 7.2AIHighAI2026-01-14
CVE-2026-22238 Administrator Account Creation Vulnerability in BLUVOYIX — BLUVOYIXCWE-306 9.8AICriticalAI2026-01-14
CVE-2026-22237 Exposed Internal API Documentation Vulnerability in BLUVOYIX — BLUVOYIXCWE-200 9.8AICriticalAI2026-01-14
CVE-2026-22236 Improper Authentication Vulnerability in BLUVOYIX — BLUVOYIXCWE-287 9.1AICriticalAI2026-01-14
CVE-2025-15475 PayHere Payment Gateway Plugin for WooCommerce <= 2.3.9 - Missing Authorization to Unauthenticated Order Status Modification — PayHere Payment GatewayCWE-862 5.3 Medium2026-01-14

Vulnerabilities classified as access:pre-auth represent 18834 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.