Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-60898 Halo CMS 安全漏洞 — n/a 7.5AIHighAI2025-10-29
CVE-2025-61234 Dataphone A920 安全漏洞 — n/a 4.3AIMediumAI2025-10-29
CVE-2025-4665 WordPress plugin Contact Form CFDB7 安全漏洞 — CFDB7CWE-89 9.6 Critical2025-10-28
CVE-2025-64095 DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite — Dnn.PlatformCWE-434 10.0 Critical2025-10-28
CVE-2025-62802 DNN CKEditor Provider allows unauthenticated upload out-of-the-box — Dnn.PlatformCWE-1188 4.3 Medium2025-10-28
CVE-2025-62727 Starlette vulnerable to O(n^2) DoS via Range header merging in starlette.responses.FileResponse — starletteCWE-407 7.5 High2025-10-28
CVE-2025-9313 Unauthorized database access in Asseco mMedica — mMedicaCWE-288 9.8AICriticalAI2025-10-28
CVE-2025-11735 HUSKY – Products Filter Professional for WooCommerce <= 1.3.7.1 - Unauthenticated SQL Injection via `phrase` Parameter — HUSKY – Products Filter Professional for WooCommerceCWE-89 7.5 High2025-10-28
CVE-2025-59461 API does not require authentication — TLOC100-100 all Firmware versionsCWE-862 7.6 High2025-10-27
CVE-2025-12055 Unauthenticated Local File Disclosure in MPDV Mikrolab MIP 2 / FEDRA 2 / HYDRA X Manufacturing Execution System — MIP 2CWE-22 7.5AIHighAI2025-10-27
CVE-2025-11154 IDonate < 2.1.13 - Unauthenticated User Deletion — IDonate 6.5AIMediumAI2025-10-27
CVE-2025-10497 Allocation of Resources Without Limits or Throttling in GitLab — GitLabCWE-770 7.5 High2025-10-27
CVE-2025-11974 Allocation of Resources Without Limits or Throttling in GitLab — GitLabCWE-770 6.5 Medium2025-10-27
CVE-2025-11447 Allocation of Resources Without Limits or Throttling in GitLab — GitLabCWE-770 7.5 High2025-10-27
CVE-2025-27225 Rocket TRUfusion Enterprise 安全漏洞 — n/a 7.5AIHighAI2025-10-27
CVE-2023-37749 HubSpot 安全漏洞 — n/a 5.3AIMediumAI2025-10-27
CVE-2025-55757 Extension - virtuemart.net - XSS in VirtueMart component 1.0.0 - 4.4.10 for Joomla — Virtuemart component for JoomlaCWE-79 6.1 -2025-10-25
CVE-2025-4203 wpForo Forum <= 2.4.8 - Unauthenticated SQL Injection via get_members Function — wpForo ForumCWE-89 7.5 High2025-10-25
CVE-2025-8416 Product Filter by WBW <= 2.9.7 - Unauthenticated SQL Injection — Product Filter for WooCommerce by WBWCWE-89 7.5 High2025-10-25
CVE-2025-11976 FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) <= 1.1.23.0 - Cross-Site Request Forgery to Sync Rule Creation — FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)CWE-352 4.3 Medium2025-10-25
CVE-2025-10637 Social Feed Gallery <= 4.9.2 - Missing Authorization to Unauthenticated Information Exposure — Social Feed GalleryCWE-862 5.3 Medium2025-10-25
CVE-2025-9322 Stripe Payment Forms <= 8.3.1 - Unauthenticated SQL Injection — Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & SubscriptionsCWE-89 7.5 High2025-10-25
CVE-2025-11497 Advanced Database Cleaner <= 3.1.6 - Cross-Site Request Forgery to Settings Manipulation — Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site PerformanceCWE-20 4.3 Medium2025-10-25
CVE-2025-10488 Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.4.8 - Authenticated (Subscriber+) Arbitrary File Move — Directorist: AI-Powered Business Directory, Listings & Classified AdsCWE-22 8.1 High2025-10-25
CVE-2025-10694 User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.8.0 - Missing Authorization to Information Disclosure — UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in SecondsCWE-862 5.3 Medium2025-10-25
CVE-2025-12095 Simple Registration for WooCommerce <= 1.5.8 - Cross-Site Request Forgery to Privilege Escalation via Role Request Approval — Simple Registration for WooCommerceCWE-352 8.8 High2025-10-25
CVE-2025-11564 Tutor LMS – eLearning and online course solution <= 3.8.3 - Missing Authorization to Unauthenticated Payment Status Update — Tutor LMS – eLearning and online course solutionCWE-862 5.3 Medium2025-10-25
CVE-2025-11238 Watu Quiz <= 3.4.4 - Unauthenticated Stored Cross-Site Scripting via HTTP Referer — Watu QuizCWE-79 7.2 High2025-10-25
CVE-2025-11269 Product Filter by WBW <= 3.0.0 - Missing Authorization to Unauthenticated Settings Update — Product Filter for WooCommerce by WBWCWE-862 5.3 Medium2025-10-25
CVE-2025-11760 eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams <= 1.5.6 - Unauthenticated Sensitive Information Exposure — eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft TeamsCWE-200 5.3 Medium2025-10-25

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.