Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18816

18816 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-27005 Chartbrew: SQL injection in date-type variable handling (applyMysqlOrPostgresVariables) — chartbrewCWE-89 9.1 -2026-03-06
CVE-2026-28501 WWBN AVideo: Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php — AVideoCWE-89 9.8 Critical2026-03-06
CVE-2026-28497 TinyWeb: Integer Overflow in `_Val` (HTTP Request Smuggling) — TinyWebCWE-190 6.5 -2026-03-06
CVE-2026-3612 Wavlink WL-NU516U1 OTA Online Upgrade adm.cgi sub_405AF4 command injection — WL-NU516U1CWE-77 7.2 High2026-03-06
CVE-2025-70363 Ibexa eZ Platform 安全漏洞 — n/a 5.3 -2026-03-06
CVE-2026-2589 Greenshift – animation and page builder blocks <= 12.8.3 - Unauthenticated Sensitive Information Exposure via Settings Backup — Greenshift – animation and page builder blocksCWE-200 5.3 Medium2026-03-05
CVE-2026-22552 ePower epower.ie Missing Authentication for Critical Function — epower.ieCWE-306 9.4 Critical2026-03-05
CVE-2026-29613 OpenClaw < 2026.2.12 - Webhook Authentication Bypass via Loopback remoteAddress Trust — OpenClawCWE-306 5.9 Medium2026-03-05
CVE-2026-29606 OpenClaw < 2026.2.14 - Webhook Signature Verification Bypass via ngrok Loopback Compatibility — OpenClawCWE-306 6.5 Medium2026-03-05
CVE-2026-28485 OpenClaw 2026.1.5 < 2026.2.12 - Missing Authentication in Browser Control HTTP Endpoints — OpenClawCWE-306 8.4 High2026-03-05
CVE-2026-28478 OpenClaw < 2026.2.13 - Denial of Service via Unbounded Webhook Request Body Buffering — OpenClawCWE-770 7.5 High2026-03-05
CVE-2026-28454 OpenClaw < 2026.2.2 - Authorization Bypass via Unauthenticated Telegram Webhook — OpenClawCWE-345 7.5 High2026-03-05
CVE-2026-28450 OpenClaw < 2026.2.12 - Unauthenticated Profile Tampering via Nostr Plugin HTTP Endpoints — OpenClaw 6.8 Medium2026-03-05
CVE-2026-28790 OliveTin: Unauthenticated Action Termination via KillAction When Guests Must Login — OliveTinCWE-284 7.5 High2026-03-05
CVE-2026-28789 OliveTin: Unauthenticated DoS via concurrent map writes in OAuth2 state handling — OliveTinCWE-362 7.5 High2026-03-05
CVE-2026-28342 OliveTin: Unauthenticated Denial of Service via Memory Exhaustion in PasswordHash API Endpoint — OliveTinCWE-770 7.5 High2026-03-05
CVE-2026-3459 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.5 - Unauthenticated Arbitrary File Upload — Drag and Drop Multiple File Upload for Contact Form 7CWE-434 8.1 High2026-03-05
CVE-2026-27944 Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosure — nginx-uiCWE-311 9.8 Critical2026-03-05
CVE-2026-29054 Traefik: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`) — traefikCWE-178 7.5 High2026-03-05
CVE-2026-26999 Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (slowloris doS) — traefikCWE-400 7.5 High2026-03-05
CVE-2026-2599 Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 - Unauthenticated PHP Object Injection via 'download_csv' — Database for Contact Form 7, WPforms, Elementor formsCWE-502 9.8 Critical2026-03-05
CVE-2026-21628 Extension - astroidframe.work - Unauthenticated Remote Code Execution in Astroid Framework 2.0.0 - 3.3.10 for Joomla — Astroid Template FrameworkCWE-434 9.8 -2026-03-05
CVE-2026-1321 Membership Plugin – Restrict Content <= 3.2.20 - Unauthenticated Privilege Escalation via 'rcp_level' — Membership Plugin – Restrict ContentCWE-862 8.1 High2026-03-05
CVE-2026-2418 Login with Salesforce <= 1.0.2 - Unauthenticated Authentication Bypass — Login with Salesforce 9.8 -2026-03-05
CVE-2026-2899 Fluent Forms Pro Add On Pack <= 6.1.17 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion — Fluent Forms Pro Add On PackCWE-862 6.5 Medium2026-03-05
CVE-2026-2365 Fluent Forms Pro <= 6.1.17 - Unauthenticated Stored Cross-Site Scripting via Draft Form Submission — Fluent Forms Pro Add On PackCWE-79 7.2 High2026-03-05
CVE-2025-69534 Python-Markdown 安全漏洞 — n/a 7.5 -2026-03-05
CVE-2026-20023 Cisco Secure Firewall Adaptive Security Appliance和Cisco Secure Firewall Threat Defense 缓冲区错误漏洞 — Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-787 6.1 Medium2026-03-04
CVE-2026-20022 Cisco Secure Firewall Adaptive Security Appliance和Cisco Secure Firewall Threat Defense 安全漏洞 — Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-823 6.1 Medium2026-03-04
CVE-2026-20020 Cisco Secure Firewall Adaptive Security Appliance和Cisco Secure Firewall Threat Defense 输入验证错误漏洞 — Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-20 6.8 Medium2026-03-04

Vulnerabilities classified as access:pre-auth represent 18816 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.