Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18829

18829 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-2428 Fluent Forms Pro Add On Pack <= 6.1.17 - Missing Authorization to Unauthenticated Payment Status modification — Fluent Forms Pro Add On PackCWE-345 7.5 High2026-02-27
CVE-2026-20797 Copeland XWEB and XWEB Pro Stack-based Buffer Overflow — Copeland XWEB 300D PRO 4.3 Medium2026-02-27
CVE-2026-22877 Copeland XWEB and XWEB Pro Path Traversal — Copeland XWEB 300D PROCWE-22 3.7 Low2026-02-27
CVE-2026-24663 Copeland XWEB and XWEB Pro OS Command Injection — Copeland XWEB 300D PROCWE-78 9.0 Critical2026-02-27
CVE-2026-27028 Mobility46 mobility46.se Missing Authentication for Critical Function — mobility46.seCWE-306 9.4 Critical2026-02-27
CVE-2026-27772 EV Energy ev.energy Missing Authentication for Critical Function — ev.energyCWE-306 9.4 Critical2026-02-27
CVE-2026-27767 SWITCH EV swtchenergy.com Missing Authentication for Critical Function — swtchenergy.comCWE-306 9.4 Critical2026-02-26
CVE-2026-24731 EV2GO ev2go.io Missing Authentication for Critical Function — ev2go.ioCWE-306 9.4 Critical2026-02-26
CVE-2026-3269 psi-probe PSI Probe Session ExpireSessionsController.java handleRequestInternal denial of service — PSI ProbeCWE-404 4.3 Medium2026-02-26
CVE-2026-20781 CloudCharge cloudcharge.se Missing Authentication for Critical Function — cloudcharge.seCWE-306 9.4 Critical2026-02-26
CVE-2026-25851 Chargemap chargemap.com Missing Authentication for Critical Function — chargemap.comCWE-306 9.4 Critical2026-02-26
CVE-2026-3268 psi-probe PSI Probe Session Attribute RemoveSessAttributeController.java access control — PSI ProbeCWE-284 5.4 Medium2026-02-26
CVE-2026-28276 Initiative Allows Unauthenticated Access to Uploaded Documents via Public /uploads/ Endpoint — initiativeCWE-200 7.5 High2026-02-26
CVE-2026-28230 In SteVe, any authenticated charger can terminate any other charger's active transaction (missing ownership verification on StopTransaction) — steveCWE-284 5.7AIMediumAI2026-02-26
CVE-2026-28215 hoppscotch Vulnerable to Unauthenticated Onboarding Config Takeover — hoppscotchCWE-284 9.1 Critical2026-02-26
CVE-2026-27449 Umbraco.Engage.Forms Allows Unauthorized Access to Multiple API Endpoints — Umbraco.Engage.FormsCWE-284 7.5 High2026-02-26
CVE-2026-22207 OpenViking Missing root_api_key Allows Anonymous ROOT Access — OpenVikingCWE-306 9.8 Critical2026-02-26
CVE-2026-22205 SPIP < 4.4.10 Authentication Bypass via PHP Type Juggling — SPIPCWE-288 7.5 High2026-02-26
CVE-2026-27509 Unitree Go2 Missing DDS Authentication Enables Adjacent RCE — Unitree Go2CWE-306 8.0 High2026-02-26
CVE-2026-23750 Golioth Pouch < [INSERT FIXED VERSION] BLE GATT Heap-based Buffer Overflow — PouchCWE-122 8.1 High2026-02-26
CVE-2026-26077 Discourse doesn't ensure webhooks require a token — discourseCWE-287 6.5 Medium2026-02-26
CVE-2026-24004 Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpoint — fleetCWE-862 8.2AIHighAI2026-02-26
CVE-2026-27975 Ajenti has a potential Remote Code Execution — ajentiCWE-284 9.8AICriticalAI2026-02-26
CVE-2026-2356 User Registration & Membership <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion — User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login BuilderCWE-284 5.3 Medium2026-02-26
CVE-2026-1779 User Registration & Membership <= 5.1.2 - Authentication Bypass — User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login BuilderCWE-288 8.1 High2026-02-26
CVE-2026-1557 WP Responsive Images <= 1.0 - Unauthenticated Path Traversal to Arbitrary File Read via src — WP Responsive ImagesCWE-22 7.5 High2026-02-26
CVE-2026-2506 EM Cost Calculator <= 2.3.1 - Unauthenticated Stored Cross-Site Scripting via 'customer_name' — EM Cost CalculatorCWE-79 6.1 Medium2026-02-26
CVE-2026-27903 minimatch has a ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments — minimatchCWE-407 7.5 High2026-02-26
CVE-2026-27804 Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter — parse-serverCWE-327 9.8AICriticalAI2026-02-25
CVE-2026-27633 TinyWeb has Unbounded Content-Length Memory Exhaustion (DoS) — TinyWebCWE-400 7.5AIHighAI2026-02-25

Vulnerabilities classified as access:pre-auth represent 18829 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.