Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22856

22856 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2026-59834 SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content — siyuanCWE-89 7.5 High2026-07-09
CVE-2026-58143 Cotonti Siena 0.9.26 CSRF via admin.php Config Update Endpoint — CotontiCWE-352 8.8 High2026-07-09
CVE-2026-58122 Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoofing — hermes-webuiCWE-348 9.1 Critical2026-07-09
CVE-2026-57054 Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs — Junos OSCWE-706 5.8 Medium2026-07-09
CVE-2026-58123 Hermes WebUI < 0.51.788 Unauthenticated RCE via Terminal API — hermes-webuiCWE-306 9.8 Critical2026-07-09
CVE-2026-57030 Junos OS: SRX Series: Flow sessions are not getting cleared leading to a DoS — Junos OSCWE-362 5.9 Medium2026-07-09
CVE-2026-57029 Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-pfemand process can crash — Junos OS EvolvedCWE-820 5.3 Medium2026-07-09
CVE-2026-55605 @arikusi/deepseek-mcp-server Missing Authentication on Self-Hosted HTTP MCP Endpoint — deepseek-mcp-serverCWE-306 5.3 Medium2026-07-09
CVE-2026-57028 Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attacker — Junos OS EvolvedCWE-923 7.3 High2026-07-09
CVE-2026-57027 Junos OS: EX4100 Series, EX4400: With sFlow configured in a VC scenario multicast traffic leads to an FPC crash — Junos OSCWE-401 6.5 Medium2026-07-09
CVE-2026-57026 Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash — Junos OSCWE-1286 7.5 High2026-07-09
CVE-2026-57024 Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will eventually cause iked to crash continuously — Junos OSCWE-694 5.3 Medium2026-07-09
CVE-2026-57023 Junos OS: MX with SPC3, SRX Series: A specifically malformed TCP packet causes a flowd crash — Junos OSCWE-1284 7.5 High2026-07-09
CVE-2026-57022 Junos OS: MX Series with SPC3, SRX Series: Specific packet in response to a TCP connection establishment by the affected device can crash the PFE — Junos OSCWE-754 5.9 Medium2026-07-09
CVE-2026-57021 Junos OS: SRX Series: If VPN compliance-check is configured an attacker can cause http-gk process crash — Junos OSCWE-787 5.3 Medium2026-07-09
CVE-2026-57020 Junos OS: QFX10000 Series: IPv6 multicast traffic received on non-IRB interfaces causes a multicast flood — Junos OSCWE-754 6.5 Medium2026-07-09
CVE-2026-57019 Junos OS: MX Series: Specific traffic causes an FPC to reset — Junos OSCWE-1284 6.5 Medium2026-07-09
CVE-2026-33803 Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attacker — Junos OS EvolvedCWE-923 6.5 Medium2026-07-09
CVE-2026-33801 Junos OS and Junos OS Evolved: When a specifically malformed BGP route update is received RPD crashes — Junos OSCWE-754 6.5 Medium2026-07-09
CVE-2026-33800 Junos OS: MX Series: In a VC scenario a high rate of micro-BFD session flaps will cause an FPC crash — Junos OSCWE-606 6.5 Medium2026-07-09
CVE-2026-33794 Junos OS Evolved: PTX Series: Receipt of repeated ECMP routing updates results in PFE crash — Junos OS EvolvedCWE-754 5.9 Medium2026-07-09
CVE-2026-55207 Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass — pimcoreCWE-640 8.8 High2026-07-09
CVE-2026-60120 Bagisto < 2.4.4 Stored XSS via CSTI in create.blade.php — BagistoCWE-79 5.4 Medium2026-07-09
CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities — Cloud NGFWCWE-79--2026-07-09
CVE-2026-0280 PAN-OS: IPv6 Firewall Policy Bypass — Cloud NGFWCWE-131--2026-07-09
CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface — Cloud NGFWCWE-524--2026-07-09
CVE-2026-0282 PAN-OS: File Deletion Vulnerability in Management Web Interface — Cloud NGFWCWE-20--2026-07-09
CVE-2026-0284 PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN) — Cloud NGFWCWE-74--2026-07-09
CVE-2026-54695 Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID — pipecatCWE-862 7.5 High2026-07-09
CVE-2026-0287 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing — Cloud NGFWCWE-754--2026-07-09

Vulnerabilities classified as access:pre-auth represent 22856 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.