Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18816

18816 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-3823 Atop Technologies|EHG2408 series switch - Stack-based Buffer Overflow — EHG2408CWE-121 8.8 High2026-03-09
CVE-2026-3822 Taipower|Taipower APP(Android) - Improper Certificate Validation — Taipower APPCWE-295 6.5 Medium2026-03-09
CVE-2025-70973 Sensorweb ScadaBR 安全漏洞 — n/a 8.8AIHighAI2026-03-09
CVE-2026-30140 Tenda W15E 安全漏洞 — n/a 9.8AICriticalAI2026-03-09
CVE-2026-3725 1024-lab/lab1024 SmartAdmin FreeMarker Template MailService.java freemarkerResolverContent special elements used in a template engine — SmartAdminCWE-1336 6.3 Medium2026-03-08
CVE-2026-3701 H3C Magic B1 aspForm Edit_BasicSSID_5G buffer overflow — Magic B1CWE-120 8.8 High2026-03-08
CVE-2026-3704 Wavlink NU516U1 Incomplete Fix CVE-2025-10959 firewall.cgi sub_405B2C command injection — NU516U1CWE-77 4.7 Medium2026-03-08
CVE-2026-3697 Planet ICG-2510 Language Package Configuration httpd sub_40C8E4 stack-based overflow — ICG-2510CWE-121 6.3 Medium2026-03-08
CVE-2026-3696 Totolink N300RH CGI cstecgi.cgi setWiFiWpsConfig os command injection — N300RHCWE-78 7.3 High2026-03-08
CVE-2026-3682 welovemedia FFmate ffmpeg.go Execute argument injection — FFmateCWE-88 6.3 Medium2026-03-07
CVE-2026-3679 Tenda FH451 QuickIndex formQuickIndex stack-based overflow — FH451CWE-121 8.8 High2026-03-07
CVE-2026-30861 WeKnora: Remote Code Execution (RCE) via Command Injection in MCP Stdio Configuration Validation — WeKnoraCWE-78 10.0 Critical2026-03-07
CVE-2026-30860 WeKnora: Remote Code Execution via SQL Injection Bypass in AI Database Query Tool — WeKnoraCWE-89 10.0 Critical2026-03-07
CVE-2026-30858 WeKnora: DNS Rebinding Vulnerability in web_fetch Tool Allows SSRF to Internal Resources — WeKnoraCWE-918 6.5 Medium2026-03-07
CVE-2026-30855 WeKnora: Broken Access Control in Tenant Management — WeKnoraCWE-284 8.8 High2026-03-07
CVE-2026-30854 Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled — parse-serverCWE-863 5.3 -2026-03-07
CVE-2026-30848 Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory — parse-serverCWE-22 7.5 -2026-03-07
CVE-2026-29787 mcp-memory-service: System Information Disclosure via Health Endpoint — mcp-memory-serviceCWE-200 5.3 Medium2026-03-07
CVE-2026-1087 The Guardian News Feed <= 1.2 - Cross-Site Request Forgery to Settings Update — The Guardian News FeedCWE-352 4.3 Medium2026-03-07
CVE-2026-1086 Font Pairing Preview For Landing Pages <= 1.3 - Cross-Site Request Forgery to Settings Update — Font Pairing Preview For Landing PagesCWE-352 4.3 Medium2026-03-07
CVE-2026-1085 True Ranker <= 2.2.9 - Cross-Site Request Forgery to Unauthorized True Ranker Disconnection — True RankerCWE-352 4.3 Medium2026-03-07
CVE-2026-1074 WP App Bar <= 1.5 - Unauthenticated Stored Cross-Site Scripting via 'app-bar-features' Parameter — WP App BarCWE-79 7.2 High2026-03-07
CVE-2026-1073 Purchase Button For Affiliate Link <= 1.0.2 - Cross-Site Request Forgery to Settings Update — Purchase Button For Affiliate LinkCWE-352 4.3 Medium2026-03-07
CVE-2026-2433 RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.11 - Unauthenticated DOM-Based Reflected Cross-Site Scripting via postMessage — RSS Aggregator – RSS Import, News Feeds, Feed to Post, and AutobloggingCWE-79 6.1 Medium2026-03-07
CVE-2026-27796 Homarr: Unauthenticated Information Disclosure (Integration Metadata Leak) — homarrCWE-200 5.3 Medium2026-03-07
CVE-2026-27797 Homarr: Unauthenticated SSRF in rssFeed.ts — homarrCWE-918 5.3 Medium2026-03-07
CVE-2026-30829 Checkmate: Unauthenticated Access to Unpublished Status Page — CheckmateCWE-200 5.3 Medium2026-03-07
CVE-2026-30824 Flowise: Missing Authentication on NVIDIA NIM Endpoints — FlowiseCWE-306 10.0 -2026-03-07
CVE-2026-30822 Flowise: Mass Assignment in `/api/v1/leads` Endpoint — FlowiseCWE-915 5.3 -2026-03-07
CVE-2026-30821 Flowise: Arbitrary File Upload via MIME Spoofing — FlowiseCWE-434 9.8 -2026-03-07

Vulnerabilities classified as access:pre-auth represent 18816 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.