Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18829

18829 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-25123 Homarr affected by Unauthenticated SSRF / Port-Scan Primitive via widget.app.ping — homarrCWE-918 5.3 Medium2026-02-06
CVE-2026-25544 Payload has an SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters — payloadCWE-89 9.8 Critical2026-02-06
CVE-2026-2067 UTT 进取 520W formTimeGroupConfig strcpy buffer overflow — 进取 520WCWE-120 8.8 High2026-02-06
CVE-2026-25593 OpenClaw Affected by Unauthenticated Local RCE via WebSocket config.apply — openclawCWE-78 8.4 High2026-02-06
CVE-2026-2066 UTT 进取 520W formIpGroupConfig strcpy buffer overflow — 进取 520WCWE-120 8.8 High2026-02-06
CVE-2026-1709 Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication — Red Hat Enterprise Linux 10CWE-322 9.4 Critical2026-02-06
CVE-2026-25751 FUXA Unauthenticated Exposure of Plaintext Database Credentials — FUXACWE-306 9.8AICriticalAI2026-02-06
CVE-2026-25752 FUXA Unauthenticated Remote Arbitrary Device Tag Write — FUXACWE-862 7.5AIHighAI2026-02-06
CVE-2026-2058 mathurvishal CloudClassroom-PHP-Project Post Query Details postquerypublic.php sql injection — CloudClassroom-PHP-ProjectCWE-89 7.3 High2026-02-06
CVE-2026-2057 SourceCodester Medical Center Portal Management System login.php sql injection — Medical Center Portal Management SystemCWE-89 7.3 High2026-02-06
CVE-2026-2017 IP-COM W30AP POST Request wx3auth R7WebsSecurityHandler stack-based overflow — W30APCWE-121 9.8 Critical2026-02-06
CVE-2026-1499 WP Duplicate <= 1.1.8 - Authenticated (Subscriber+) Arbitrary File Upload via 'process_add_site' AJAX Action — WP Duplicate – WordPress Migration PluginCWE-862 8.8 High2026-02-06
CVE-2026-1785 Code Snippets <= 3.9.4 - Cross-Site Request Forgery to Cloud Snippet Download/Update Actions — Code SnippetsCWE-352 4.3 Medium2026-02-06
CVE-2026-21643 Fortinet FortiClientEMS SQL注入漏洞 — FortiClientEMSCWE-89 9.1 Critical2026-02-06
CVE-2025-10753 OAuth Single Sign On – SSO (OAuth Client) <= 6.26.14 - Missing Authorization — OAuth Single Sign On – SSO (OAuth Client)CWE-862 5.3 Medium2026-02-06
CVE-2026-0521 Reflected Cross-Site Scripting in PDF Export Error Message — MAP+CWE-79 6.1AIMediumAI2026-02-06
CVE-2026-1975 Free5GC pfcp_reports.go identityTriggerType null pointer dereference — Free5GCCWE-476 5.3 Medium2026-02-06
CVE-2026-1301 Out-of-bounds Write in o6 Automation GmbH Open62541 — Open62541CWE-787 9.1AICriticalAI2026-02-05
CVE-2020-37150 Edimax Technology EW-7438RPn-v3 Mini 1.27 - Unauthorized Access: Wi-Fi Password Disclosure — EW-7438RPn MiniCWE-201 7.5 High2026-02-05
CVE-2020-37125 Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution — EW-7438RPn MiniCWE-78 9.8 Critical2026-02-05
CVE-2026-1294 All In One Image Viewer Block <= 1.0.2 - Unauthenticated Server-Side Request Forgery via image-proxy Endpoint — All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlinkCWE-918 7.2 High2026-02-05
CVE-2026-1654 Peter's Date Countdown <= 2.0.0 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — Peter’s Date CountdownCWE-79 6.1 Medium2026-02-05
CVE-2025-15080 Information Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability in Mitsubishi Electric proprietary protocol communication and SLMP communication for FA products — MELSEC iQ-R Series R08PCPUCWE-1284 9.8AICriticalAI2026-02-05
CVE-2025-13192 Popup builder with Gamification <= 2.2.0 - Unauthenticated SQL Injection via Multiple REST API Endpoints — Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce TriggersCWE-89 8.2 High2026-02-04
CVE-2026-25575 NavigaTUM has a Path Traversal Vulnerability in the propose_edits functionality — NavigaTUMCWE-23 7.5AIHighAI2026-02-04
CVE-2026-1884 ZenTao Webhook model.php fetchHook server-side request forgery — ZenTaoCWE-918 4.7 Medium2026-02-04
CVE-2025-13375 IBM Common Cryptographic Architecture Arbitrary Command Execution — Common Cryptographic ArchitectureCWE-250 9.8 Critical2026-02-04
CVE-2026-25139 RIOT Vulnerable to Multiple Out-of-Bounds Read When Processing Received 6LoWPAN SFR Fragments — RIOTCWE-125 9.1AICriticalAI2026-02-04
CVE-2026-25055 n8n Arbitrary File Write on Remote Systems via SSH Node — n8nCWE-22 10.0AICriticalAI2026-02-04
CVE-2026-20119 Cisco TelePresence Collaboration Endpoint Software and RoomOS Software Denial of Service Vulnerability — Cisco RoomOS SoftwareCWE-1287 7.5 High2026-02-04

Vulnerabilities classified as access:pre-auth represent 18829 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.