Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22808

22808 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2026-45754 Symfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection — symfonyCWE-287--2026-07-14
CVE-2026-15712 Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumption — Red Hat Enterprise Linux 10CWE-125 5.9 Medium2026-07-14
CVE-2026-45077 Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener — symfonyCWE-502--2026-07-14
CVE-2026-56190 Remote Desktop Protocol Remote Code Execution Vulnerability — Windows 10 Version 1607CWE-908 9.8 Critical2026-07-14
CVE-2026-56159 DHCP Server Service Remote Code Execution Vulnerability — Windows 10 Version 1607CWE-122 9.8 Critical2026-07-14
CVE-2026-54126 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability — Windows 10 Version 1607CWE-125 6.5 Medium2026-07-14
CVE-2026-50647 Active Directory Federation Server Denial of Service Vulnerability — Microsoft .NET Framework 3.5 AND 4.7.2CWE-835 7.5 High2026-07-14
CVE-2026-50497 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability — Windows 10 Version 1607CWE-193 6.5 Medium2026-07-14
CVE-2026-50474 Remote Desktop Client Remote Code Execution Vulnerability — Windows 10 Version 1607CWE-416 8.8 High2026-07-14
CVE-2026-50439 Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability — Windows 10 Version 1607CWE-416 8.1 High2026-07-14
CVE-2026-50365 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability — Windows 10 Version 1607CWE-287 8.0 High2026-07-14
CVE-2026-50388 Windows NTFS Remote Code Execution Vulnerability — Windows 10 Version 1607CWE-125 7.8 High2026-07-14
CVE-2026-50380 Windows GDI+ Remote Code Execution Vulnerability — Windows 10 Version 1607CWE-122 9.6 Critical2026-07-14
CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability — Windows 10 Version 1607CWE-416 9.3 Critical2026-07-14
CVE-2026-49787 HTTP.sys Denial of Service Vulnerability — Windows 10 Version 1607CWE-770 7.5 High2026-07-14
CVE-2026-56193 Microsoft Office Information Disclosure Vulnerability — Microsoft 365 Apps for EnterpriseCWE-125 7.1 High2026-07-14
CVE-2026-50695 Windows Active Directory Federation Services Denial of Service Vulnerability — Windows 10 Version 1607CWE-121 7.5 High2026-07-14
CVE-2026-14645 Nexus Repository 3 - Server-Side Request Forgery (SSRF) via Webhook: Global Capability — Nexus Repository 3CWE-918--2026-07-14
CVE-2026-60119 Hi.Events < 1.11.0 XSS via Event Title JSON.stringify Injection — Hi.EventsCWE-862 5.4 Medium2026-07-14
CVE-2026-60118 Hi.Events < 1.11.0 Hidden Ticket Enumeration via Order Creation Endpoint — Hi.EventsCWE-862 5.3 Medium2026-07-14
CVE-2025-53379 Fortinet FortiAuthenticator 缓冲区错误漏洞 — FortiAuthenticatorCWE-125 7.0 High2026-07-14
CVE-2026-59835 Fortinet FortiSandbox 权限许可和访问控制问题漏洞 — FortiSandboxCWE-668 7.7 High2026-07-14
CVE-2026-52838 Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS — easyappointmentsCWE-79 2.6 Low2026-07-14
CVE-2026-52837 Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page — easyappointmentsCWE-200 6.9 Medium2026-07-14
CVE-2026-58479 Sustainable Irrigation Platform 5.2.16 RCE via cli_control Plugin Command Injection — SIPCWE-78 9.8 Critical2026-07-14
CVE-2026-58478 Sustainable Irrigation Platform 5.2.16 SSRF via Node-RED Callback URL — SIPCWE-918 6.5 Medium2026-07-14
CVE-2026-58477 Sustainable Irrigation Platform 5.2.16 Mass Assignment via HTTP Parameters — SIPCWE-915 8.2 High2026-07-14
CVE-2026-58476 Sustainable Irrigation Platform 5.2.16 CSRF via Administrative GET Requests — SIPCWE-352 8.1 High2026-07-14
CVE-2026-14902 Ivanti Xtraction 输入验证错误漏洞 — XtractionCWE-601 4.0 Medium2026-07-14
CVE-2026-58475 Sustainable Irrigation Platform 5.2.16 Stored XSS via Program Name — SIPCWE-79 6.1 Medium2026-07-14

Vulnerabilities classified as access:pre-auth represent 22808 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.