Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18817

18817 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2019-25504 NCrypted Jobgator Lastest SQL Injection via agents Find-Jobs — NCrypted JobgatorCWE-89 8.2 High2026-03-04
CVE-2019-25503 PHPads 2.0 SQL Injection via click.php3 bannerID — PHPadsCWE-89 7.1 High2026-03-04
CVE-2019-25502 Simple Job Script Cross-Site Scripting via job_type_value Parameter — Simple Job ScriptCWE-79 6.1 Medium2026-03-04
CVE-2019-25500 Simple Job Script SQL Injection via register-recruiters endpoint — Simple Job ScriptCWE-89 8.2 High2026-03-04
CVE-2019-25499 Simple Job Script SQL Injection via get_job_applications_ajax.php — Simple Job ScriptCWE-89 8.2 High2026-03-04
CVE-2019-25498 Simple Job Script SQL Injection via searched Endpoint — Simple Job ScriptCWE-89 8.2 High2026-03-04
CVE-2026-20009 Cisco Secure Firewall Adaptive Security Appliance SSH Partial Private Key Authentication Bypass Vulnerability — Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-138 5.3 Medium2026-03-04
CVE-2026-20005 Cisco多款产品 安全漏洞 — Cisco Secure Firewall Threat Defense (FTD) SoftwareCWE-392 5.8 Medium2026-03-04
CVE-2026-29069 Craft has an unauthenticated activation email trigger with potential user enumeration — cmsCWE-639 8.1AIHighAI2026-03-04
CVE-2026-28696 Craft affected by IDOR via GraphQL @parseRefs — cmsCWE-639 5.3AIMediumAI2026-03-04
CVE-2026-25907 Dell PowerScale OneFS 安全漏洞 — PowerScale OneFSCWE-645 5.3 Medium2026-03-04
CVE-2026-1706 All-in-One Video Gallery <= 4.7.1 - Reflected Cross-Site Scripting via 'vi' Parameter — All-in-One Video GalleryCWE-79 6.1 Medium2026-03-04
CVE-2023-7337 JS Help Desk – AI-Powered Support & Ticketing System 2.8.2 - Unauthenticated SQL Injection via 'js-support-ticket-token-tkstatus' Cookie — JS Help Desk – AI-Powered Support & Ticketing SystemCWE-89 7.5 High2026-03-04
CVE-2026-27446 Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation — Apache ArtemisCWE-306 6.5 -2026-03-04
CVE-2026-29119 Hardcoded and Insecure Credentials for "Admin" Account providing Telnet Access on IDC SFX2100 Satellite Receiver — SFX2100 Series SuperFlex SatelliteReceiverCWE-798 9.8AICriticalAI2026-03-04
CVE-2026-28778 Hardcoded FTP Credentials and LPE(via Insecure Permissions) for `xd` Local Account on IDC SFX2100 — IDC SFX2100 SuperFlex Satellite ReceiverCWE-798 9.8AICriticalAI2026-03-04
CVE-2026-28777 Hardcoded and Insecure Credentials for "User" Local Account with SSH Access On IDC SFX2100 Satellite Receiver — SFX2100 Satellite ReceiverCWE-798 9.8AICriticalAI2026-03-04
CVE-2026-28776 Hardcoded and Insecure Credentials for "monitor" account with SSH Access On IDC SFX2100 Satellite Receiver — IDC SFX2100 SuperFlex Satellite ReceiverCWE-798 9.8AICriticalAI2026-03-04
CVE-2026-28775 Unauthenticated RCE via SNMP Default Writable Community String — SFX2100 Series SuperFlex SatelliteReceiverCWE-1188 9.8AICriticalAI2026-03-04
CVE-2026-2025 Mail Mint < 1.19.5 - Unauthenticated Emails Disclosure — Mail Mint 5.3AIMediumAI2026-03-04
CVE-2026-1980 WPBookit <= 1.0.8 - Missing Authorization to Unauthenticated Sensitive Customer Data Exposure — WPBookitCWE-200 5.3 Medium2026-03-04
CVE-2026-1945 WPBookit <= 1.0.8 - Unauthenticated Stored Cross-Site Scripting via 'wpb_user_name' and 'wpb_user_email' Parameters — WPBookitCWE-79 7.2 High2026-03-04
CVE-2025-70342 erase-install 安全漏洞 — n/a 7.5AIHighAI2026-03-04
CVE-2025-69969 SRK Powertech Pebble Prism Ultra 安全漏洞 — n/a 8.8AIHighAI2026-03-04
CVE-2026-27971 Qwik affected by unauthenticated RCE via server$ Deserialization — qwikCWE-502 9.8AICriticalAI2026-03-03
CVE-2026-27932 joserfc PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS) — joserfcCWE-770 7.5 High2026-03-03
CVE-2026-3266 Improper access control vulnerability has been discovered in OpenText™ Filr. — FilrCWE-862 9.1AICriticalAI2026-03-03
CVE-2026-24898 OpenEMR has an Unauthenticated MedEx Token Disclosure — openemrCWE-287 10.0 Critical2026-03-03
CVE-2026-3224 Devolutions Server 安全漏洞 — ServerCWE-287 9.8AICriticalAI2026-03-03
CVE-2026-1775 Missing Authentication for Critical Function in Labkotec LID-3300IP — LID-3300IPCWE-306 9.8AICriticalAI2026-03-03

Vulnerabilities classified as access:pre-auth represent 18817 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.