Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18816

18816 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-27826 MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers — mcp-atlassianCWE-918 8.2 High2026-03-10
CVE-2025-13901 Schneider Electric多款产品 安全漏洞 — Modicon M241/M251CWE-404 5.3AIMediumAI2026-03-10
CVE-2026-30958 OneUptime: Path Traversal — Arbitrary File Read (No Auth) — oneuptimeCWE-22 7.2 High2026-03-10
CVE-2025-54659 Fortinet FortiSOAR Agent Communication Bridge 路径遍历漏洞 — FortiSOAR Agent Communication BridgeCWE-22 5.5 Medium2026-03-10
CVE-2026-24017 Fortinet FortiWeb 安全漏洞 — FortiWebCWE-799 7.3 High2026-03-10
CVE-2026-25972 Fortinet FortiSIEM 跨站脚本漏洞 — FortiSIEMCWE-79 4.1 Medium2026-03-10
CVE-2025-68482 Fortinet FortiManager和Fortinet FortiAnalyzer 信任管理问题漏洞 — FortiAnalyzerCWE-295 6.3 Medium2026-03-10
CVE-2025-48840 Fortinet FortiWeb 安全漏洞 — FortiWebCWE-290 5.0 Medium2026-03-10
CVE-2026-22627 Fortinet FortiSwitchAXFixed 安全漏洞 — FortiSwitchAXFixedCWE-120 7.7 High2026-03-10
CVE-2025-54820 Fortinet FortiManager 安全漏洞 — FortiManagerCWE-121 7.0 High2026-03-10
CVE-2026-30941 Parse Server has a NoSQL injection via token type in password reset and email verification endpoints — parse-serverCWE-943 9.8AICriticalAI2026-03-10
CVE-2026-30939 Parse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution — parse-serverCWE-1321 7.5AIHighAI2026-03-10
CVE-2026-2742 Unauthorized session creation via reserved framework path access — vaadinCWE-284 9.1AICriticalAI2026-03-10
CVE-2026-2724 Unlimited Elements For Elementor <= 2.0.5 - Unauthenticated Stored Cross-Site Scripting via Form Entry Fields — Unlimited Elements For ElementorCWE-79 7.2 High2026-03-10
CVE-2026-1261 MetForm Pro <= 3.9.6 - Unauthenticated Stored Cross-Site Scripting — MetForm ProCWE-79 7.2 High2026-03-10
CVE-2025-41712 Incorrect Permission Assignment on power analyzer — UMG 96RM-E 24V(5222063)CWE-732 6.5 Medium2026-03-10
CVE-2025-41711 Use of a Broken or Risky Cryptographic Algorithm for firmware images of power analyzer — UMG 96RM-E 24V(5222063)CWE-327 5.3 Medium2026-03-10
CVE-2025-41710 Use of Hard-coded Credentials in power analyzer — UMG 96RM-E 24V(5222063)CWE-798 6.5 Medium2026-03-10
CVE-2025-41709 Command injection in power analyzer via Modbus-TCP and Modbus-RTU — UMG 96RM-E 24V(5222063)CWE-78 9.8 Critical2026-03-10
CVE-2026-0953 Tutor LMS Pro <= 3.9.5 - Authentication Bypass via Social Login — Tutor LMS ProCWE-287 9.8 Critical2026-03-10
CVE-2026-1919 Booktics <= 1.0.16 - Missing Authorization to Get Items via REST API endpoints — Booktics – Booking Calendar for Appointments and Service BusinessesCWE-306 5.3 Medium2026-03-10
CVE-2026-1920 Booktics <= 1.0.16 - Missing Authorization to Addon Plugin Installation — Booktics – Booking Calendar for Appointments and Service BusinessesCWE-306 5.3 Medium2026-03-10
CVE-2026-24317 DLL Hijacking vulnerability in SAP GUI for Windows with active GuiXT — SAP GUI for Windows with active GuiXTCWE-427 5.0 Medium2026-03-10
CVE-2026-0489 DOM-based Cross-Site Scripting (XSS) Vulnerability in SAP Business One (Job Service) — SAP Business One (Job Service)CWE-79 6.1 Medium2026-03-10
CVE-2026-30885 WWBN AVideo - Unauthenticated IDOR - Playlist Information Disclosure — AVideoCWE-306 5.3AIMediumAI2026-03-09
CVE-2026-31816 Budibase Universal Auth Bypass via Webhook Query Param Injection — budibaseCWE-74 9.1 Critical2026-03-09
CVE-2026-3814 UTT HiPER 810G getOneApConfTempEntry strcpy buffer overflow — HiPER 810GCWE-120 8.8 High2026-03-09
CVE-2026-3813 opencc JFlow WF_CCForm.java Calculate injection — JFlowCWE-74 6.3 Medium2026-03-09
CVE-2025-41772 wwwupdate.cgi Session token in URL — UBR-01 Mk IICWE-598 7.5 High2026-03-09
CVE-2025-41762 Secret leak with wwwdnload.cgi — UBR-01 Mk IICWE-328 6.2 Medium2026-03-09

Vulnerabilities classified as access:pre-auth represent 18816 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.