Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22866

22866 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2026-67620 Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List — FlowiseCWE-918 7.7 High2026-08-08
CVE-2026-14526 AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route — AI Copilot – Content GeneratorCWE-269 9.8 Critical2026-08-08
CVE-2026-16953 AI Engine < 3.6.4 - Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie — AI Engine--2026-08-08
CVE-2026-16608 Download Monitor < 5.2.6 - Unauthenticated Download Log Injection — Download Monitor--2026-08-08
CVE-2026-16595 WP Directory Kit < 1.5.5 - Subscriber+ User and Unpublished Listing Disclosure — WP Directory Kit--2026-08-08
CVE-2026-16578 Admin Safety Guard < 1.4.0 - Unauthenticated User Data Disclosure via 2fa/app/users REST Route — Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection--2026-08-08
CVE-2026-16535 Link Library < 7.9.4 - Reflected XSS via Thumbs-Rating likelabel — Link Library--2026-08-08
CVE-2026-16267 Newsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form Field — Newsletters--2026-08-08
CVE-2026-16282 Appointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost Parameter — Appointment Hour Booking--2026-08-08
CVE-2026-16269 Newsletters < 4.16 - Unauthenticated API Authentication Bypass via Type Juggling — Newsletters--2026-08-08
CVE-2026-52880 Klever-Go: REST API slow-header connection exhaustion via Gin Engine.Run — klever-goCWE-400 7.5 High2026-08-07
CVE-2026-46405 OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens — openbaoCWE-770 5.3 Medium2026-08-07
CVE-2026-54338 JupyterHub: Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login — jupyterhubCWE-400 5.3 Medium2026-08-07
CVE-2026-61808 LightRAG: Missing Authentication for Critical API Functions in Default Configuration — LightRAGCWE-306 9.8 Critical2026-08-07
CVE-2026-48039 Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token — meta-ads-mcpCWE-287 9.1 Critical2026-08-07
CVE-2026-19113 Unauthenticated denial of service via unbounded request body processing — ConsulCWE-400 5.3 Medium2026-08-07
CVE-2026-15972 Unauthenticated denial of service via unbounded external gRPC connection acceptance — ConsulCWE-770 7.5 High2026-08-07
CVE-2026-11430 Grav CMS Scheduler Webhook Authentication Bypass via Null Short-Circuit — grav-plugin-scheduler-webhookCWE-303 7.3 High2026-08-07
CVE-2026-71848 Hono: Algorithmic Complexity DoS in Language Middleware — honoCWE-407 5.3 Medium2026-08-07
CVE-2026-69127 Kirby: System path exposure from error messages in the REST API — kirbyCWE-497 6.9 Medium2026-08-07
CVE-2026-64638 WordPress 4.7-7.0.2 登录页反射型XSS漏洞 — WordPressCWE-79 8.9 High2026-08-07
CVE-2026-56818 Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state — nettyCWE-401 6.5 Medium2026-08-07
CVE-2026-20348 ClamAV XAR File Format Processing Memory Corruption Vulnerability — Cisco Secure EndpointCWE-120 7.5 High2026-08-07
CVE-2026-20345 ClamAV GPT File Format Processing Memory Corruption Vulnerability — Cisco Secure EndpointCWE-121 7.5 High2026-08-07
CVE-2026-20339 ClamAV PESpin File Format Processing Integer Overflow Vulnerability — Cisco Secure EndpointCWE-190 7.5 High2026-08-07
CVE-2026-20347 ClamAV Mach-O File Format Processing Memory Corruption Vulnerability — Cisco Secure EndpointCWE-125 7.5 High2026-08-07
CVE-2026-67585 Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation — absinthe_federationCWE-770 8.7 High2026-08-07
CVE-2026-20346 ClamAV PDF File Format Processing Memory Corruption Vulnerability — Cisco Secure EndpointCWE-125 7.5 High2026-08-07
CVE-2026-20338 ClamAV ZIP File Format Processing Memory Corruption Vulnerability — Cisco Secure EndpointCWE-415 7.5 High2026-08-07
CVE-2026-20337 ClamAV ZIP File Format Processing Memory Corruption Vulnerability — Cisco Secure EndpointCWE-120 7.5 High2026-08-07

Vulnerabilities classified as access:pre-auth represent 22866 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.