Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18817

18817 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-27836 phpMyFAQ Allows Unauthenticated Account Creation via WebAuthn Prepare Endpoint — phpMyFAQCWE-862 7.5 High2026-02-27
CVE-2026-27793 Seerr has Broken Object-Level Authorization in User Profile Endpoint that Exposes Third-Party Notification Credentials — seerrCWE-639 6.5 Medium2026-02-27
CVE-2026-27707 Plex-configured Seerr instances vulnerable to unauthenticated account registration via Jellyfin authentication endpoint — seerrCWE-288 7.3 High2026-02-27
CVE-2019-25497 osCommerce 2.3.4.1 SQL Injection via currency Parameter — osCommerceCWE-89 8.2 High2026-02-27
CVE-2019-25496 osCommerce 2.3.4.1 SQL Injection via products_id Parameter — osCommerceCWE-89 8.2 High2026-02-27
CVE-2019-25495 osCommerce 2.3.4.1 SQL Injection via reviews_id Parameter — osCommerceCWE-89 8.2 High2026-02-27
CVE-2019-25494 Homey BNB V4 SQL Injection Authentication Bypass via Admin Panel — Homey BNB (Airbnb Clone Script)CWE-89 8.2 High2026-02-27
CVE-2019-25493 Homey BNB V4 SQL Injection via getrecord.php — Homey BNB (Airbnb Clone Script)CWE-89 8.2 High2026-02-27
CVE-2019-25492 Homey BNB V4 SQL Injection via getcmsdata.php — Homey BNB (Airbnb Clone Script)CWE-89 8.2 High2026-02-27
CVE-2019-25491 Homey BNB V4 SQL Injection via cms_getpagetitle.php — Homey BNB (Airbnb Clone Script)CWE-89 8.2 High2026-02-27
CVE-2019-25490 Homey BNB V4 SQL Injection via admin edit.php — Homey BNB (Airbnb Clone Script)CWE-89 8.2 High2026-02-27
CVE-2019-25489 Homey BNB V4 SQL Injection via ajax_refresh_subtotal — Homey BNB (Airbnb Clone Script)CWE-89 8.2 High2026-02-27
CVE-2025-15498 SQL Injection in Pro3W CMS — Pro3W CMSCWE-89 9.8 -2026-02-27
CVE-2026-1305 Japanized for WooCommerce <= 2.8.4 - Missing Authorization to Unauthenticated Paidy Order Manipulation — Japanized for WooCommerceCWE-287 5.3 Medium2026-02-27
CVE-2026-21659 Johnson Controls -Frick Quantum HD-Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion — Frick Controls Quantum HDCWE-23 9.8 -2026-02-27
CVE-2026-21658 Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution — Frick Controls Quantum HDCWE-94 9.8 -2026-02-27
CVE-2025-12981 Listee <= 1.1.6 - Unauthenticated Privilege Escalation — ListeeCWE-269 9.8 Critical2026-02-27
CVE-2026-1558 WP Recipe Maker <= 10.3.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Metadata Modification via 'recipeId' Parameter — WP Recipe MakerCWE-639 5.3 Medium2026-02-27
CVE-2026-2428 Fluent Forms Pro Add On Pack <= 6.1.17 - Missing Authorization to Unauthenticated Payment Status modification — Fluent Forms Pro Add On PackCWE-345 7.5 High2026-02-27
CVE-2026-20797 Copeland XWEB and XWEB Pro Stack-based Buffer Overflow — Copeland XWEB 300D PRO 4.3 Medium2026-02-27
CVE-2026-22877 Copeland XWEB and XWEB Pro Path Traversal — Copeland XWEB 300D PROCWE-22 3.7 Low2026-02-27
CVE-2026-24663 Copeland XWEB and XWEB Pro OS Command Injection — Copeland XWEB 300D PROCWE-78 9.0 Critical2026-02-27
CVE-2026-27028 Mobility46 mobility46.se Missing Authentication for Critical Function — mobility46.seCWE-306 9.4 Critical2026-02-27
CVE-2026-27772 EV Energy ev.energy Missing Authentication for Critical Function — ev.energyCWE-306 9.4 Critical2026-02-27
CVE-2026-27767 SWITCH EV swtchenergy.com Missing Authentication for Critical Function — swtchenergy.comCWE-306 9.4 Critical2026-02-26
CVE-2026-24731 EV2GO ev2go.io Missing Authentication for Critical Function — ev2go.ioCWE-306 9.4 Critical2026-02-26
CVE-2026-3269 psi-probe PSI Probe Session ExpireSessionsController.java handleRequestInternal denial of service — PSI ProbeCWE-404 4.3 Medium2026-02-26
CVE-2026-20781 CloudCharge cloudcharge.se Missing Authentication for Critical Function — cloudcharge.seCWE-306 9.4 Critical2026-02-26
CVE-2026-25851 Chargemap chargemap.com Missing Authentication for Critical Function — chargemap.comCWE-306 9.4 Critical2026-02-26
CVE-2026-3268 psi-probe PSI Probe Session Attribute RemoveSessAttributeController.java access control — PSI ProbeCWE-284 5.4 Medium2026-02-26

Vulnerabilities classified as access:pre-auth represent 18817 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.