Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18816

18816 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-2431 CM Custom Reports <= 1.2.7 - Reflected Cross-Site Scripting via 'date_from' and 'date_to' Parameters — CM Custom Reports – Flexible reporting to track what matters mostCWE-79 6.1 Medium2026-03-07
CVE-2026-1650 MDJM Event Management <= 1.7.8.1 - Missing Authorization to Unauthenticated Arbitrary Custom Event Field Deletion — MDJM Event ManagementCWE-862 5.3 Medium2026-03-07
CVE-2026-2494 ProfileGrid <= 5.9.8.2 - Cross-Site Request Forgery to Group Membership Request Approval/Denial — ProfileGrid – User Profiles, Groups and CommunitiesCWE-352 4.3 Medium2026-03-07
CVE-2025-14353 ZIP Code Based Content Protection <= 1.0.2 - Unauthenticated SQL Injection via 'zipcode' Parameter — ZIP Code Based Content ProtectionCWE-89 7.5 High2026-03-07
CVE-2026-25071 XikeStor SKS8310-8X switch_config.src Missing Authentication — XikeStor SKS8310-8XCWE-306 5.3 -2026-03-07
CVE-2026-25070 XikeStor SKS8310-8X PingTestSet Command Injection — XikeStor SKS8310-8XCWE-78 9.8 -2026-03-07
CVE-2026-1644 WP Frontend Profile <= 1.3.8 - Cross-Site Request Forgery to Unauthorized User Account Approval or Rejection — WP Frontend ProfileCWE-352 4.3 Medium2026-03-06
CVE-2026-2371 Greenshift <= 12.8.3 - Missing Authorization to Unauthenticated Private Reusable Block Disclosure via 'gspb_el_reusable_load' — Greenshift – animation and page builder blocksCWE-862 5.3 Medium2026-03-06
CVE-2026-30244 Plane: Unauthenticated Workspace Member Information Disclosure — planeCWE-284 7.5 High2026-03-06
CVE-2026-30231 Flare: Private File IDOR via raw/direct endpoints — FlareCWE-639 6.5 -2026-03-06
CVE-2026-30846 Wekan Exposes All Global Webhook Integrations through globalwebhooks Publication — WekanCWE-306 7.5 -2026-03-06
CVE-2026-30845 Wekan Exposes Sensitive Data through Lack of Field Filtering During Board Publication — WekanCWE-200 7.5 -2026-03-06
CVE-2026-29178 Lemmy: Unauthenticated SSRF via file_type query parameter injection in image endpoint — lemmyCWE-918 7.5 -2026-03-06
CVE-2026-30833 Rocket.Chat: NoSQL injection in the EE ddp-streamer-service — Rocket.ChatCWE-943 9.8 -2026-03-06
CVE-2026-26288 Everon api.everon.io Missing Authentication for Critical Function — api.everon.ioCWE-306 9.4 Critical2026-03-06
CVE-2026-2754 Navtor NavBox 安全漏洞 — NavBoxCWE-306 7.5 High2026-03-06
CVE-2026-2753 Navtor NavBox 安全漏洞 — NavBoxCWE-36 7.5 High2026-03-06
CVE-2026-2752 Navtor NavBox 安全漏洞 — NavBoxCWE-209 5.3 Medium2026-03-06
CVE-2026-26051 Mobiliti e-mobi.hu Missing Authentication for Critical Function — e-mobi.huCWE-306 9.4 Critical2026-03-06
CVE-2018-25200 OOP CMS BLOG 1.0 Cross-Site Request Forgery via addUser.php — OOP CMS BLOGCWE-352 5.3 Medium2026-03-06
CVE-2018-25199 OOP CMS BLOG 1.0 SQL Injection via search parameter — OOP CMS BLOGCWE-89 8.2 High2026-03-06
CVE-2018-25197 PlayJoom 0.10.1 SQL Injection via catid Parameter — PlayJoomCWE-89 8.2 High2026-03-06
CVE-2018-25196 ServerZilla 1.0 SQL Injection via email Parameter — ServerZillaCWE-89 8.2 High2026-03-06
CVE-2018-25194 Nominas 0.27 SQL Injection via username Parameter — NominasCWE-22 8.2 High2026-03-06
CVE-2018-25192 GPS Tracking System 2.12 SQL Injection via username Parameter — GPS Tracking SystemCWE-89 8.2 High2026-03-06
CVE-2018-25190 Easyndexer 1.0 Cross-Site Request Forgery via createuser.php — EasyndexerCWE-352 5.3 Medium2026-03-06
CVE-2018-25189 Data Center Audit 2.6.2 SQL Injection via username Parameter — Data Center AuditCWE-89 8.2 High2026-03-06
CVE-2018-25188 Webiness Inventory 2.3 SQL Injection via WsModelGrid.php — Webiness InventoryCWE-89 8.2 High2026-03-06
CVE-2018-25187 Tina4 Stack 1.0.3 SQL Injection and Database File Download — Tina4 StackCWE-89 8.2 High2026-03-06
CVE-2018-25186 Tina4 Stack 1.0.3 Cross-Site Request Forgery via profile — Tina4 StackCWE-352 5.3 Medium2026-03-06

Vulnerabilities classified as access:pre-auth represent 18816 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.