Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-62716 Plane Vulnerable to Cross-Site Scripting via Open Redirect in ?next_path Parameter — planeCWE-79 8.1 High2025-10-24
CVE-2025-62714 Karmada Dashboard API Unauthorized Access Vulnerability — dashboardCWE-862 7.5 -2025-10-24
CVE-2025-43994 Dell Storage Manager 访问控制错误漏洞 — Dell Storage ManagerCWE-306 8.6 High2025-10-24
CVE-2025-43995 Dell Storage Manager 授权问题漏洞 — Dell Storage ManagerCWE-287 9.8 Critical2025-10-24
CVE-2025-11576 AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant <= 1.6.5 - Unauthenticated CSV Injection — AI Chatbot Free Models – Customer Support, Live Chat, Virtual AssistantCWE-1236 4.3 Medium2025-10-24
CVE-2025-10861 Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers <= 2.1.4 - Unauthenticated Server-Side Request Forgery — Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce TriggersCWE-918 7.5 High2025-10-24
CVE-2025-12134 ZoloBlocks <= 2.3.11 - Missing Authorization to Unauthenticated Popup Enable/Disable — ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & PatternsCWE-862 5.3 Medium2025-10-24
CVE-2025-12017 VNPAY for Woocommerce <= 1.0.0 - Reflected Cross-Site Scripting — VNPAY Payment gatewayCWE-79 6.1 Medium2025-10-24
CVE-2025-11504 Quickcreator – AI Blog Writer 0.0.9 - 0.1.17 - Unauthenticated API Key Exposure — Quickcreator – AI Blog WriterCWE-532 7.5 High2025-10-24
CVE-2025-12028 IndieAuth <= 4.5.4 - Cross-Site Request Forgery to Account Takeover via Stolen OAuth Tokens — IndieAuthCWE-352 8.8 High2025-10-24
CVE-2025-11992 Multi Item Responsive Slider <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Multi Item Responsive SliderCWE-80 6.1 Medium2025-10-24
CVE-2025-12072 Disable Content Editor For Specific Template <= 2.0 - Cross-Site Request Forgery to Template Configuration Update — Disable Content Editor For Specific TemplateCWE-352 4.3 Medium2025-10-24
CVE-2025-6440 WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload — WooCommerce Designer ProCWE-434 9.8 Critical2025-10-24
CVE-2025-56438 Nous W3 安全漏洞 — n/a 6.8 -2025-10-24
CVE-2025-60801 jshERP 安全漏洞 — n/a 9.8 -2025-10-24
CVE-2025-60803 White-Jotter 安全漏洞 — n/a 9.8 -2025-10-24
CVE-2025-60023 AutomationDirect Productivity Suite Relative Path Traversal — Productivity SuiteCWE-23 4.0 Medium2025-10-23
CVE-2025-59776 AutomationDirect Productivity Suite Relative Path Traversal — Productivity SuiteCWE-23 4.0 Medium2025-10-23
CVE-2025-58429 AutomationDirect Productivity Suite Relative Path Traversal — Productivity SuiteCWE-23 7.5 High2025-10-23
CVE-2025-58078 AutomationDirect Productivity Suite Relative Path Traversal — Productivity SuiteCWE-23 7.5 High2025-10-23
CVE-2025-58456 AutomationDirect Productivity Suite Relative Path Traversal — Productivity SuiteCWE-23 6.8 Medium2025-10-23
CVE-2025-61934 AutomationDirect Productivity Suite Binding to an Unrestricted IP Address CWE-1327 — Productivity SuiteCWE-1327 10.0 Critical2025-10-23
CVE-2025-62236 Frontier Airlines publicly available email address validation — flyfrontier.comCWE-204 5.3 Medium2025-10-23
CVE-2025-12044 Vault Vulnerable to Denial of Service Due to Rate Limit Regression — VaultCWE-770 7.5 High2025-10-23
CVE-2025-34156 Tibbo AggreGate Network Manager < 6.40.05 System Information Exposure — AggreGate Network ManagerCWE-497 5.3AIMediumAI2025-10-23
CVE-2025-34155 Tibbo AggreGate Network Manager < 6.40.05 Login Functionality User Enumeration — AggreGate Network ManagerCWE-204 8.2AIHighAI2025-10-23
CVE-2025-53702 DoS vulnerability in Vilar VS-IPC1002 IP cameras — VS-IPC1002CWE-755 5.7AIMediumAI2025-10-23
CVE-2025-10705 MxChat – AI Chatbot for WordPress <= 2.4.6 - Unauthenticated Blind Server-Side Request Forgery — MxChat – AI Chatbot & Content Generation for WordPressCWE-918 5.3 Medium2025-10-23
CVE-2025-62614 BookLore Media API Authentication Bypass — bookloreCWE-862 7.5AIHighAI2025-10-22
CVE-2025-62607 Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL — nautobot-app-ssotCWE-306 5.3 Medium2025-10-22

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.