Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22836

22836 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2026-61502 Rejetto HFS < 3.2.1 Cross-Site Request Forgery via GET Requests — hfsCWE-352 4.3 Medium2026-07-13
CVE-2026-61501 Rejetto HFS < 3.2.1 Stored XSS in Admin Log Viewer — hfsCWE-79 6.1 Medium2026-07-13
CVE-2026-61500 Rejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key — hfsCWE-338 9.8 Critical2026-07-13
CVE-2026-6847 Unauthenticated Remote Code Execution in ThemisNETPanel — ThemisNETPanelCWE-306--2026-07-13
CVE-2026-61498 Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php — FlamingoCWE-78 9.8 Critical2026-07-13
CVE-2026-60121 Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php — FlamingoCWE-78 9.8 Critical2026-07-13
CVE-2026-13014 Remote Code Execution vulnerability in "Suspicious" application — SuspiciousCWE-22--2026-07-13
CVE-2026-57830 Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 — Helix Ultimate extension for JoomlaCWE-862 8.8 High2026-07-13
CVE-2026-57829 Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 — Helix Ultimate extension for JoomlaCWE-79 8.7 High2026-07-13
CVE-2026-4769 Unauthenticated Access to Internal Diagnostic Interface — 0765-110x/0100-0000CWE-912 9.8 Critical2026-07-13
CVE-2026-12582 Library Management System < 3.5.8 - Unauthenticated SQL Injection via book_id — Library Management System--2026-07-13
CVE-2026-11964 User Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signature Verification Bypass Leading to Membership Activation — User Registration & Membership--2026-07-13
CVE-2026-12081 Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticated PHP Object Injection via Entry File Field — Database for Contact Form 7, WPforms, Elementor forms--2026-07-13
CVE-2026-10551 Breeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library — Breeze Cache--2026-07-13
CVE-2026-15553 Ragic|Enterprise Cloud Database - Arbitrary File Upload — Enterprise Cloud DatabaseCWE-434 5.3 Medium2026-07-13
CVE-2026-15552 Ragic|Enterprise Cloud Database - Stored Cross-Site Scripting — Enterprise Cloud DatabaseCWE-79 6.1 Medium2026-07-13
CVE-2025-45869 LogicalDOC Enterprise 服务端请求伪造漏洞 — n/a--2026-07-13
CVE-2026-61875 luci-app-upnp Stored XSS via UPnP Port Mapping Description — luciCWE-79 8.8 High2026-07-12
CVE-2026-56336 Capgo - Information Disclosure via Unauthenticated SSO check-domain Endpoint — CapgoCWE-200 5.3 Medium2026-07-12
CVE-2026-56259 Crawl4AI - LLM Credential Exfiltration via base_url and Environment Variable Resolution — Crawl4AICWE-200 8.2 High2026-07-12
CVE-2026-56238 Capgo - Unauthenticated Information Disclosure via PostgREST global_stats Endpoint — CapgoCWE-200 7.5 High2026-07-12
CVE-2026-61454 Grav before 2.0.4 Information Disclosure via __GRAV_CONFIG__ — gravCWE-200 5.3 Medium2026-07-11
CVE-2026-61428 PraisonAI AgentMail before 4.6.78 Message Injection via Webhook — PraisonAICWE-290 7.3 High2026-07-11
CVE-2026-61426 PraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure Defaults — PraisonAICWE-200 8.6 High2026-07-11
CVE-2026-56303 Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC Function — CapgoCWE-200 7.5 High2026-07-11
CVE-2026-56296 Cap-go - App Existence Oracle via Unauthenticated transfer_app RPC — capgoCWE-203 5.3 Medium2026-07-11
CVE-2026-57827 Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 — rsjoomla.com RSFiles extension for JoomlaCWE-434 10.0 Critical2026-07-11
CVE-2026-9017 NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email AJAX Action — NEX-Forms – Ultimate Forms Plugin for WordPressCWE-862 5.3 Medium2026-07-11
CVE-2026-9282 W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter — W3 Total CacheCWE-22 7.5 High2026-07-11
CVE-2026-15010 bbp style pack <= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Topic Form Additional Fields — bbp style packCWE-79 6.4 Medium2026-07-11

Vulnerabilities classified as access:pre-auth represent 22836 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.