Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18835

18835 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-21894 n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks — n8nCWE-290 6.5 Medium2026-01-08
CVE-2026-21874 NiceGUI has Redis connection leak via tab storage causes service degradation — niceguiCWE-772 5.3 Medium2026-01-08
CVE-2019-25296 WP Cost Estimation <= 9.642 - Missing Authorization to Arbitrary File Upload/Delete — WP Cost Estimation & Payment Forms BuilderCWE-434 9.8 Critical2026-01-08
CVE-2025-65518 Plesk Obsidian 安全漏洞 — n/a 7.5 -2026-01-08
CVE-2025-67090 GL.iNet AX1800 安全漏洞 — n/a 8.0 -2026-01-08
CVE-2025-67325 QloApps 安全漏洞 — n/a 9.8 -2026-01-08
CVE-2025-68715 Panda Wireless PWRU0 安全漏洞 — n/a 9.8 -2026-01-08
CVE-2025-68717 KAYSUS KS-WR3600 安全漏洞 — n/a 9.8 -2026-01-08
CVE-2026-21858 n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling — n8nCWE-20 10.0 Critical2026-01-07
CVE-2019-25290 INIM Electronics Smartliving SmartLAN/G/SI <=6.x Unauthenticated SSRF via GetImage — Smartliving SmartLAN/G/SICWE-918 5.3 Medium2026-01-07
CVE-2017-20216 FLIR Thermal Camera PT-Series firmware version 8.0.0.64 Unauthenticated Remote Command Injection — FLIR Thermal Camera PT-SeriesCWE-78 9.8 Critical2026-01-07
CVE-2017-20212 FLIR Thermal Camera F/FC/PT/D 8.0.0.64 Information Disclosure via File Reading — FLIR Thermal Camera F/FC/PT/DCWE-22 6.2 Medium2026-01-07
CVE-2017-20213 FLIR Thermal Camera F/FC/PT/D Stream 8.0.0.64 Unauthenticated Stream Disclosure — FLIR Thermal Camera F/FC/PT/D StreamCWE-306 7.5 High2026-01-07
CVE-2026-21854 Tarkov Data Manager Authentication Bypass vulnerability — tarkov-data-managerCWE-287 9.8 Critical2026-01-07
CVE-2026-22539 INFORMATION DISCLOSURE VIA CURL REQUESTS (OCPP) — QC 60/90/120CWE-201 5.3 -2026-01-07
CVE-2026-20026 Multiple Cisco Products Snort 3 DCERPC Vulnerabilities — Cisco Secure Firewall Threat Defense (FTD) SoftwareCWE-415 5.8 Medium2026-01-07
CVE-2026-20027 Cisco Snort DCERPC Stub Data Out of Bounds Read — Cisco Secure Firewall Threat Defense (FTD) SoftwareCWE-200 5.3 Medium2026-01-07
CVE-2025-14077 Simcast <= 1.0.0 - Cross-Site Request Forgery to Settings Update — SimcastCWE-352 4.3 Medium2026-01-07
CVE-2025-14460 Piraeus Bank WooCommerce Payment Gateway <= 3.1.4 - Missing Authorization to Unauthenticated Arbitrary Order Status Change — Piraeus Bank WooCommerce Payment GatewayCWE-862 5.3 Medium2026-01-07
CVE-2025-13801 Yoco Payments <= 3.9.0 - Unauthenticated Arbitrary File Read — Yoco PaymentsCWE-22 7.5 High2026-01-07
CVE-2025-13990 Mamurjor Employee Info <= 1.0.0 - Cross-Site Request Forgery to Arbitrary Employee and Related Data Manipulation — Mamurjor Employee InfoCWE-352 4.3 Medium2026-01-07
CVE-2025-13419 Guest posting / Frontend Posting / Front Editor – WP Front User Submit <= 5.0.0 - Missing Authorization to Unauthenticated Media Deletion — Guest posting / Frontend Posting / Front Editor – WP Front User SubmitCWE-862 5.3 Medium2026-01-07
CVE-2025-14465 Sticky Action Buttons <= 1.1 - Cross-Site Request Forgery to Plugin Settings Update — Sticky Action ButtonsCWE-352 4.3 Medium2026-01-07
CVE-2025-14131 WP Widget Changer <= 1.2.5 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — WP Widget ChangerCWE-79 6.1 Medium2026-01-07
CVE-2025-14130 Post Like Dislike <= 1.0 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — Post Like DislikeCWE-79 6.1 Medium2026-01-07
CVE-2025-14352 Awesome Hotel Booking <= 1.0.3 - Incorrect Authorization to Unauthenticated Arbitrary Booking Modification — Awesome Hotel BookingCWE-863 5.3 Medium2026-01-07
CVE-2025-14118 Starred Review <= 1.4.2 - Reflected Cross-Site Scripting via PHP_SELF Variable — Starred ReviewCWE-79 6.1 Medium2026-01-07
CVE-2025-14127 Testimonial Master <= 0.2.1 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — Testimonial MasterCWE-79 6.1 Medium2026-01-07
CVE-2025-14128 Stumble! for WordPress <= 1.1.1 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — Stumble! for WordPressCWE-79 6.1 Medium2026-01-07
CVE-2025-13694 AA Block country <= 1.0.1 - Unauthenticated IP Address Spoofing via X-Forwarded-For Header — AA Block countryCWE-348 5.3 Medium2026-01-07

Vulnerabilities classified as access:pre-auth represent 18835 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.