Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 21465

21465 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2026-57476 Deloitte AI Assist for Customer unauthenticated RAG corpus read and write — AI Assist for CustomerCWE-306 4.8 Medium2026-07-10
CVE-2026-57475 Deloitte AI Assist for Customer unauthenticated configuration write — AI Assist for CustomerCWE-306 5.3 Medium2026-07-10
CVE-2026-57474 Deloitte AI Assist for Customer information disclosure — AI Assist for CustomerCWE-200 5.3 Medium2026-07-10
CVE-2026-1667 SEO Plugin by Squirrly SEO <= 14.0.0 - Unauthenticated Arbitrary Post Creation and Stored Cross-Site Scripting via savePost() — GEO Plugin by Squirrly SEOCWE-862 7.2 High2026-07-10
CVE-2026-53653 Grav: Unauthenticated denial of service via unbounded image derivative dimensions — gravCWE-770--2026-07-10
CVE-2026-54063 Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS) — excelizeCWE-770 7.5 High2026-07-10
CVE-2026-56675 9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs — 9routerCWE-287 8.3 High2026-07-10
CVE-2026-55638 9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass — 9routerCWE-862 8.6 High2026-07-10
CVE-2026-55641 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF — 9routerCWE-290 8.2 High2026-07-10
CVE-2026-8609 Pre-authentication denial of service via the OAuth login route — Grafana OSSCWE-400 5.3 Medium2026-07-10
CVE-2026-33382 Denial of service via unbounded request body size — Grafana OSSCWE-400 7.5 High2026-07-10
CVE-2026-59795 JetBrains TeamCity 跨站脚本漏洞 — TeamCityCWE-79 8.1 High2026-07-10
CVE-2026-38059 ST Engineering iDirect iQ-Series Terminals Missing authentication for critical function — Evolution iQ‑Series terminalsCWE-306 7.5 High2026-07-10
CVE-2026-29519 Lucee CFML Server Reflected XSS via URL Path Parsing — LuceeCWE-79 8.2 High2026-07-10
CVE-2026-60091 PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url — PraisonAICWE-918 7.2 High2026-07-10
CVE-2026-57994 phpMyFAQ - Information Disclosure of Inactive FAQ Content via Public API Endpoints — phpMyFAQCWE-200 5.3 Medium2026-07-10
CVE-2026-56279 Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint — CapgoCWE-862 7.5 High2026-07-10
CVE-2026-56814 Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service) — plugCWE-770--2026-07-10
CVE-2026-11990 KiviCare <= 4.4.0 - Missing Authorization to Unauthenticated Payment Bypass and Appointment Status Manipulation via /payment-success REST Endpoint — KiviCare – Clinic & Patient Management System (EHR)CWE-862 5.3 Medium2026-07-10
CVE-2026-9838 ICS Calendar <= 12.0.9 - Reflected Cross-Site Scripting via 'htmltagtitle' Parameter — ICS CalendarCWE-79 6.1 Medium2026-07-10
CVE-2026-6440 GoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential' — GoodMeet – Google Meet Integration for Webinar, Meeting & Video ConferenceCWE-352 4.3 Medium2026-07-10
CVE-2026-6802 Easy Upload Files During Checkout <= 3.0.1 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'eufdc-delete' Parameter — Easy Upload Files During CheckoutCWE-639 5.3 Medium2026-07-10
CVE-2026-40007 Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError — Apache IoTDBCWE-674--2026-07-10
CVE-2026-40006 Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver — Apache IoTDBCWE-789--2026-07-10
CVE-2026-13347 Hide My WP Lite <= 1.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'he_wrapper_js' Parameter — Hide My WP LiteCWE-22 7.5 High2026-07-10
CVE-2026-12276 LA-Studio Element Kit for Elementor < 1.6.1 - Unauthenticated Open Registration — LA-Studio Element Kit for Elementor--2026-07-10
CVE-2026-12685 EscortWP <= 3.6.2 - Content Deletion via Vendor-Authored Backdoor — escortwp--2026-07-10
CVE-2026-12123 All-in-One Video Gallery <= 4.8.5 - Authenticated (Subscriber+) Server-Side Request Forgery via 'vdl' Parameter — All-in-One Video GalleryCWE-918 6.4 Medium2026-07-10
CVE-2026-15298 TelSender <= 1.14.14 - Unauthenticated Stored Cross-Site Scripting via Telegram Chat Title — TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram botCWE-79 7.2 High2026-07-10
CVE-2026-15297 Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.77 - Reflected Cross-Site Scripting — Brevo – Email, SMS, Web Push, Chat, and more.CWE-79 6.1 Medium2026-07-10

Vulnerabilities classified as access:pre-auth represent 21465 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.