Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-11268 Strong Testimonials <= 3.2.16 - Unauthenticated Arbitrary Shortcode Execution — Strong TestimonialsCWE-79 4.3 Medium2025-11-06
CVE-2025-10259 Denial-of-Service(DoS) Vulnerability in TCP Communication Function on MELSEC iQ-F Series CPU module — MELSEC iQ-F Series FX5U-32MT/ESCWE-1284 5.3 Medium2025-11-06
CVE-2025-12471 Hubbub Lite <= 1.36.0 - Reflected Cross-Site Scripting — Hubbub Lite – Fast, free social sharing and follow buttonsCWE-79 6.1 Medium2025-11-06
CVE-2025-11271 Easy Digital Download <= 3.5.2 - Insufficient Verification to Order Manipulation — Easy Digital Downloads – eCommerce Payments and Subscriptions made easyCWE-807 5.3 Medium2025-11-06
CVE-2025-10691 Easy Email Subscription <= 1.3 - Cross-Site Request Forgery to Arbitrary Subscriber Deletion — Easy Email SubscriptionCWE-352 4.3 Medium2025-11-06
CVE-2025-63588 CMSimple_XH 安全漏洞 — n/a 6.1 -2025-11-06
CVE-2025-10713 XML External Entity (XXE) Vulnerability in Multiple WSO2 Products Due to Improper XML Parser Configuration — WSO2 Enterprise IntegratorCWE-611 6.5 Medium2025-11-05
CVE-2025-20358 Cisco Unified Contact Center Express Editor Authentication Bypass Vulnerability — Cisco Unified Contact Center ExpressCWE-306 9.4 Critical2025-11-05
CVE-2025-20354 Cisco Unified Contact Center Express Remote Code Execution Vulnerability — Cisco Unified Contact Center ExpressCWE-434 9.8 Critical2025-11-05
CVE-2025-20343 Cisco Identity Services Engine Radius Suppression Denial of Service Vulnerability — Cisco Identity Services Engine SoftwareCWE-697 8.6 High2025-11-05
CVE-2025-12497 Premium Portfolio Features for Phlox theme <= 2.3.10 - Unauthenticated Local File Inclusion via args[extra_template_path] — Premium Portfolio Features for Phlox themeCWE-98 8.1 High2025-11-05
CVE-2025-12192 The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure — The Events CalendarCWE-697 5.3 Medium2025-11-05
CVE-2025-12469 FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending — FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerceCWE-862 4.3 Medium2025-11-05
CVE-2025-12468 FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information Exposure — FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerceCWE-200 5.3 Medium2025-11-05
CVE-2025-55108 BMC Control-M/Agent default configuration does not enforce SSL/TLS allowing unauthorized actions and remote code execution — Control-M/AgentCWE-306 10.0 Critical2025-11-05
CVE-2025-12674 KiotViet Sync <= 1.8.5 - Unauthenticated Arbitrary File Upload — KiotViet SyncCWE-434 9.8 Critical2025-11-05
CVE-2025-12676 KiotViet Sync <= 1.8.5 - Use of Hard-coded Password to Authorization Bypass — KiotViet SyncCWE-259 5.3 Medium2025-11-05
CVE-2025-12677 KiotViet Sync <= 1.8.5 - Unauthenticated Webhook Key Exposure — KiotViet SyncCWE-200 5.3 Medium2025-11-05
CVE-2025-12384 Document Embedder – Embed PDFs, Word, Excel, and Other Files <= 2.0.0 - Missing Authorization to Unauthenticated Document Manipulation — Document Embedder – Embed PDFs, Word, Excel, and Other FilesCWE-862 8.6 High2025-11-05
CVE-2025-12139 File Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information Exposure — File Manager for Google Drive – Integrate Google DriveCWE-200 7.5 High2025-11-05
CVE-2025-10873 Elementinvader Addons for Elementor < 1.4.1 – Unauthenticated Arbitrary Email Sending — ElementInvader Addons for Elementor 5.3 -2025-11-05
CVE-2025-11072 Download Counter Button <= 1.8.6.7 - Unauthenticated Arbitrary File Download — MelAbu WP Download Counter Button 7.5 -2025-11-05
CVE-2025-11749 AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation — AI Engine – The Chatbot, AI Framework & MCP for WordPressCWE-200 9.8 Critical2025-11-05
CVE-2025-12197 The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s — The Events CalendarCWE-89 7.5 High2025-11-05
CVE-2025-11835 Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.16.4 - Missing Authorization to Unauthenticated Arbitrary Member Subscription Auto Renewal — Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content RestrictionCWE-862 5.3 Medium2025-11-05
CVE-2025-12580 SMS for WordPress <= 1.1.8 - Reflected Cross-Site Scripting — SMS for WordPressCWE-79 6.1 Medium2025-11-05
CVE-2025-8871 Everest Forms (Pro) <= 1.9.7 - Unauthenticated PHP Object Injection via PHAR Deserialization in Form Signature — Everest Forms ProCWE-502 5.6 Medium2025-11-05
CVE-2025-59716 guests 安全漏洞 — n/a 5.3 -2025-11-05
CVE-2025-63334 PocketVJ CP 安全漏洞 — n/a 9.8 -2025-11-05
CVE-2025-61956 Missing Authentication for Critical Function in Radiometrics VizAir — VizAirCWE-306 10.0 Critical2025-11-04

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.