Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18802

18802 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPaused
CVE-2026-33337 Firebird has a buffer overflow when parsing corrupted slice packets — firebirdCWE-120 7.5 High2026-04-17
CVE-2026-28224 Firebird Null Pointer Dereference via CryptCallback causes DOS — firebirdCWE-476 8.2 High2026-04-17
CVE-2026-27890 Firebird has Pre-Auth DOS when Processing Out of Order CNCT_specific_data Segments — firebirdCWE-119 8.2 High2026-04-17
CVE-2026-28212 Firebird has potential server crash via null pointer dereference when processing op_slice packet — firebirdCWE-476 7.5 High2026-04-17
CVE-2026-5710 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 - Unauthenticated Limited Arbitrary File Read via mfile Field — Drag and Drop Multiple File Upload for Contact Form 7CWE-22 7.5 High2026-04-17
CVE-2026-5718 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass — Drag and Drop Multiple File Upload for Contact Form 7CWE-434 8.1 High2026-04-17
CVE-2026-6497 prasathmani TinyFileManager File Upload filemanager.php server-side request forgery — TinyFileManagerCWE-918 6.3 Medium2026-04-17
CVE-2025-15625 Unauthenticated execution of arbitrary SQL queries in Sparx Pro Cloud Server — Sparx Pro Cloud ServerCWE-89 9.8AICriticalAI2026-04-17
CVE-2025-15623 Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user — Sparx Pro Cloud ServerCWE-359 7.5AIHighAI2026-04-17
CVE-2026-6494 Aap-mcp-server: aap mcp server: log injection allows social engineering attacks via unsanitized input — Red Hat Ansible Automation Platform 2CWE-117 5.3 Medium2026-04-17
CVE-2026-6451 CMS für Motorrad Werkstätten <= 1.0.0 - Cross-Site Request Forgery — Plugin: CMS für Motorrad WerkstättenCWE-352 4.3 Medium2026-04-17
CVE-2026-23853 Dell PowerProtect Data Domain 安全漏洞 — PowerProtect Data DomainCWE-1391 8.4 High2026-04-17
CVE-2026-5797 Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields — Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-74 5.3 Medium2026-04-17
CVE-2026-5234 LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID — LatePoint – Calendar Booking Plugin for Appointments and EventsCWE-639 5.3 Medium2026-04-17
CVE-2026-5807 Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations — VaultCWE-770 7.5 High2026-04-17
CVE-2026-5231 WP Statistics <= 14.16.4 - Unauthenticated Stored Cross-Site Scripting via 'utm_source' Parameter — WP Statistics – Simple, privacy-friendly Google Analytics alternativeCWE-79 7.2 High2026-04-17
CVE-2026-37749 CodeAstro Simple Attendance Management System 安全漏洞 — n/a 9.8AICriticalAI2026-04-17
CVE-2026-40265 Note Mark has Broken Access Control on Asset Download — note-markCWE-862 5.9 Medium2026-04-16
CVE-2026-40263 Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel — note-markCWE-208 3.7 Low2026-04-16
CVE-2026-40248 free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions — free5gcCWE-285 7.5AIHighAI2026-04-16
CVE-2026-40247 free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions — free5gcCWE-285 5.3AIMediumAI2026-04-16
CVE-2026-40246 free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions — free5gcCWE-285 5.3AIMediumAI2026-04-16
CVE-2026-40308 My Calendar: Unauthenticated Information Disclosure (IDOR) via Multisite switch_to_blog — my-calendarCWE-639 7.5AIHighAI2026-04-16
CVE-2026-39313 MCP-Framework: Unbounded memory allocation in readRequestBody allows denial of service via HTTP transport — mcp-frameworkCWE-770 7.5AIHighAI2026-04-16
CVE-2025-36579 Dell Client Platform BIOS 安全漏洞 — Dell Pro 14 Essential PV14250CWE-640 5.1 Medium2026-04-16
CVE-2026-6270 @fastify/middie vulnerable to middleware authentication bypass in child plugin scopes — @fastify/middieCWE-436 9.1 Critical2026-04-16
CVE-2026-6410 @fastify/static vulnerable to path traversal in directory listing — @fastify/staticCWE-22 5.3 Medium2026-04-16
CVE-2026-4160 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form BuilderCWE-639 5.3 Medium2026-04-16
CVE-2026-31843 Для национальных платежных систем в Узбекистане 安全漏洞 — pay-uzCWE-284 9.8 Critical2026-04-16
CVE-2026-3489 DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.26 - Unauthenticated SQL Injection via 'packages' — DirectoryPress – Business Directory And Classified Ad ListingCWE-89 7.5 High2026-04-16

Vulnerabilities classified as access:pre-auth represent 18802 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.