Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22880

22880 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2026-13765 LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-862 7.5 High2026-07-17
CVE-2026-14503 pCloud WP Backup <= 2.0.3 - Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read — pCloud WP BackupCWE-200 6.5 Medium2026-07-17
CVE-2026-15395 Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value — Kali Forms — Contact Form & Drag-and-Drop BuilderCWE-79 7.2 High2026-07-17
CVE-2026-11324 WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url' — WooCommerce Placetopay Gateway BeliceCWE-79 6.1 Medium2026-07-17
CVE-2026-8616 Fense Proxy & VPN Blocker <= 3.0.1 - Missing Authorization to Unauthenticated Plugin Option/Transient Deletion via fense_bpvt_save_settings AJAX Action — Fense Proxy & VPN BlockerCWE-862 5.3 Medium2026-07-17
CVE-2026-14956 Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter — BricksforgeCWE-269 9.8 Critical2026-07-17
CVE-2026-62241 clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery — clawvetCWE-306 9.1 Critical2026-07-17
CVE-2026-62230 Grav < 2.0.4 File Access Bypass via Case Variation — gravCWE-178 7.5 High2026-07-17
CVE-2026-36669 Feng Office 任意文件上传漏洞 — n/a--2026-07-17
CVE-2026-34150 Wazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsing — wazuhCWE-122 7.5 High2026-07-16
CVE-2026-33754 Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS) — wazuhCWE-400 6.5 Medium2026-07-16
CVE-2026-44177 Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup — kirbyCWE-22--2026-07-16
CVE-2026-53412 Zoom Workplace VDI Plugin for Windows - Improper Input Validation — Zoom Workplace for WindowsCWE-20 9.8 Critical2026-07-16
CVE-2026-33692 AVideo Has Unauthenticated .env File Exposure via Official Docker Compose Configuration — AVideoCWE-20 7.5 High2026-07-16
CVE-2026-44981 CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression — crowdsecCWE-409--2026-07-16
CVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record — corednsCWE-476 5.3 Medium2026-07-16
CVE-2026-62963 Centrifugo: Decompression bomb DoS via permessage-deflate in unidirectional WebSocket transport — centrifugoCWE-409--2026-07-16
CVE-2026-15422 SCTP needs to better-check INIT ACK chunk parameters — illumos-gateCWE-122--2026-07-16
CVE-2026-63089 WireGuard Easy Weak Token Generation Information Disclosure via OTL Route — wg-easyCWE-338 9.3 Critical2026-07-16
CVE-2026-45336 HireFlow: Use of Hard-coded Credentials — HireFlowCWE-798 10.0 Critical2026-07-16
CVE-2026-63088 stoatchat < 0.14.0 SSRF via DNS-based IP Blocklist Bypass — stoatchatCWE-918 8.6 High2026-07-16
CVE-2026-46562 Yamcs: Remote Code Execution via Mission Database algorithm override — yamcsCWE-94 9.8 Critical2026-07-16
CVE-2026-44596 Yamcs: No Rate Limiting on Authentication Endpoint — yamcsCWE-307 6.5 Medium2026-07-16
CVE-2026-63087 Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint — oncallCWE-306 9.8 Critical2026-07-16
CVE-2026-63086 text-generation-inference 3.3.7 SSRF via fetch_image in multimodal chat completions — text-generation-inferenceCWE-918 8.6 High2026-07-16
CVE-2026-55407 Buffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation — buffaCWE-400--2026-07-16
CVE-2026-45695 Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is used — kopiaCWE-78 9.8 Critical2026-07-16
CVE-2026-57206 SimpleChat plugin validation endpoints missing authentication and authorization — simplechatCWE-306 8.6 High2026-07-16
CVE-2026-54733 moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoint — o365-moodleCWE-347--2026-07-16
CVE-2026-14890 CVE-2026-14890 — SGLang--2026-07-16

Vulnerabilities classified as access:pre-auth represent 22880 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.