Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18817

18817 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-2568 WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.5 - Unauthenticated Stored Cross-Site Scripting — WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja FormsCWE-79 7.2 High2026-03-03
CVE-2026-1492 User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration — User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login BuilderCWE-269 9.8 Critical2026-03-03
CVE-2026-2628 All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login <= 2.2.5 - Authentication Bypass — All-in-One Microsoft 365 & Entra ID / Azure AD SSO LoginCWE-288 9.8 Critical2026-03-03
CVE-2024-55019 Weintek cMT 安全漏洞 — n/a 7.5AIHighAI2026-03-03
CVE-2026-1336 AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.5 - Missing Authorization to Unauthenticated API Key Modification — AI ChatBot with ChatGPT and Content Generator by AYSCWE-862 5.3 Medium2026-03-02
CVE-2026-3338 PKCS7_verify Signature Validation Bypass in AWS-LC — AWS-LCCWE-347 7.5 High2026-03-02
CVE-2026-3337 Timing Side-Channel in AES-CCM Tag Verification in AWS-LC — AWS-LCCWE-208 5.9 Medium2026-03-02
CVE-2026-3336 PKCS7_verify Certificate Chain Validation Bypass in AWS-LC — AWS-LCCWE-295 7.5 High2026-03-02
CVE-2026-3180 Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection — Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & StripeCWE-89 7.5 High2026-03-02
CVE-2024-50337 Chamilo: Potential unauthenticated blind SSRF via openid function — chamilo-lmsCWE-918 5.3 Medium2026-03-02
CVE-2026-3432 Sim Studio AI - Unauthenticated OAuth Token Theft — simCWE-862 7.5AIHighAI2026-03-02
CVE-2026-3431 Sim Studio AI - MongoDB SSRF and Arbitrary Document Deletion — simCWE-862 9.8 Critical2026-03-02
CVE-2025-14532 Remote Code Execution via Unrestricted File Upload in DobryCMS — DobryCMSCWE-434 9.8AICriticalAI2026-03-02
CVE-2025-12462 Blind SQL Injection in DobryCMS — DobryCMSCWE-89 9.8AICriticalAI2026-03-02
CVE-2026-2584 SQL Injection in Ciser System SL firmware — CSIP firmwareCWE-89 5.3AIMediumAI2026-03-02
CVE-2026-3422 e-Excellence|U-Office Force - Insecure Deserialization — U-Office ForceCWE-502 9.8 Critical2026-03-02
CVE-2026-3000 Changing|IDExpert Windows Logon Agent - Remote Code Execution — IDExpert Windows Logon AgentCWE-494 9.8 Critical2026-03-02
CVE-2026-2999 Changing|IDExpert Windows Logon Agent - Remote Code Execution — IDExpert Windows Logon AgentCWE-494 9.8 Critical2026-03-02
CVE-2026-3378 Tenda F453 qossetting fromqossetting buffer overflow — F453CWE-120 8.8 High2026-03-01
CVE-2026-28562 wpForo Forum 2.4.14 SQL Injection via Topics ORDER BY Parameter — wpForo ForumCWE-89 8.2 High2026-02-28
CVE-2026-28559 wpForo Forum 2.4.14 Information Disclosure via Global RSS Feed — wpForo ForumCWE-200 5.3 Medium2026-02-28
CVE-2025-13673 Tutor LMS <= 3.9.6 - Unauthenticated SQL Injection via coupon_code — Tutor LMS – eLearning and online course solutionCWE-89 7.5 High2026-02-28
CVE-2026-2471 WP Mail Logging <= 1.15.0 - Unauthenticated PHP Object Injection via Email Log Message Field — WP Mail LoggingCWE-502 7.5 High2026-02-28
CVE-2026-1542 Super Stage WP <= 1.0.1 - Unauthenticated PHP Object Injection — Super Stage WP 9.8 -2026-02-28
CVE-2026-28423 Statamic Vulnerable to Server-Side Request Forgery via Glide — cmsCWE-918 6.8 Medium2026-02-27
CVE-2026-28515 openDCIM <= 23.04 Missing Authorization in install.php — openDCIMCWE-862 8.8 -2026-02-27
CVE-2026-28411 WeGIA Vulnerable to Authentication Bypass via `extract($_REQUEST)` — WeGIACWE-288 9.8 Critical2026-02-27
CVE-2026-28414 Gradio has Absolute Path Traversal on Windows with Python 3.13+ — gradioCWE-36 7.5 High2026-02-27
CVE-2026-28400 Docker Model Runner Unauthenticated Runtime Flag Injection via _configure Endpoint — model-runnerCWE-749 7.6 High2026-02-27
CVE-2026-28352 Indico missing access check in event series management API — indicoCWE-306 6.5 Medium2026-02-27

Vulnerabilities classified as access:pre-auth represent 18817 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.