Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-53047 Oracle Database Server 安全漏洞 — Oracle Database Server 5.8 Medium2025-10-21
CVE-2025-53041 Oracle E-Business Suite 安全漏洞 — Oracle iStore 6.1 Medium2025-10-21
CVE-2025-53036 Oracle Financial Services Applications 安全漏洞 — Oracle Financial Services Analytical Applications Infrastructure 8.6 High2025-10-21
CVE-2025-53037 Oracle Financial Services Applications 安全漏洞 — Oracle Financial Services Analytical Applications Infrastructure 9.8 Critical2025-10-21
CVE-2025-53034 Oracle Financial Services Applications 安全漏洞 — Oracle Financial Services Analytical Applications Infrastructure 5.4 Medium2025-10-21
CVE-2025-62250 Liferay Portal和Liferay DXP 访问控制错误漏洞 — PortalCWE-346 9.8AICriticalAI2025-10-21
CVE-2025-10640 Missing Server-Side Authentication Checks in EfficientLab WorkExaminer Professional — WorkExaminer ProfessionalCWE-602 9.1AICriticalAI2025-10-21
CVE-2025-11949 Digiwin|EasyFlow .NET and EasyFlow AiNet - Missing Authentication — EasyFlow .NETCWE-306 7.5 High2025-10-21
CVE-2025-10916 FormGent < 1.0.4 - Unauthenticated Arbitrary File Deletion — FormGent 9.1AICriticalAI2025-10-21
CVE-2025-6542 OS command injection in multiple parameters — Omada gatewaysCWE-78 9.8AICriticalAI2025-10-21
CVE-2025-56450 Spacecom Log2Space Subscriber Management Software 安全漏洞 — n/a 9.8AICriticalAI2025-10-21
CVE-2025-60344 D-Link DSR-150 安全漏洞 — DSR-150CWE-24 8.6 High2025-10-21
CVE-2025-60772 NETLINK HG322G 安全漏洞 — n/a 9.8AICriticalAI2025-10-21
CVE-2025-11948 Excellent Infotek|Document Management System - Arbitrary File Upload — Document Management SystemCWE-434 9.8 Critical2025-10-20
CVE-2025-61455 E-commerce 安全漏洞 — n/a 9.8AICriticalAI2025-10-20
CVE-2025-9890 Theme Editor <= 3.0 - Cross-Site Request Forgery to Remote Code Execution — Theme EditorCWE-352 8.8 High2025-10-18
CVE-2025-10750 PowerBI Embed Reports <= 1.2.0 - Unauthenticated Sensitive Information Disclosure — PowerBI Embed ReportsCWE-200 5.3 Medium2025-10-18
CVE-2025-11256 Kognetiks Chatbot <= 2.3.5 - Missing Authorization to Unauthenticated Limited File Uploads and Conversation Erasing — Kognetiks Chatbot for WordPressCWE-285 5.3 Medium2025-10-18
CVE-2025-11372 LearnPress – WordPress LMS Plugin <= 4.2.9.3 - Missing Authorization to Unauthenticated Database Table Manipulation — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-862 6.5 Medium2025-10-18
CVE-2025-11691 PPOM – Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated SQL Injection — PPOM – Product Addons & Custom Fields for WooCommerceCWE-89 7.5 High2025-10-18
CVE-2025-11391 PPOM – Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated Arbitrary File Upload — PPOM – Product Addons & Custom Fields for WooCommerceCWE-434 9.8 Critical2025-10-18
CVE-2025-11703 WP Go Maps (formerly WP Google Maps) <= 9.0.48 - Unauthenticated Cache Poisoning — WP Go Maps (formerly WP Google Maps)CWE-349 5.3 Medium2025-10-18
CVE-2025-11741 WPC Smart Quick View for WooCommerce <= 4.2.5 - Insecure Direct Object Reference to Unauthenticated Private Product Exposure — WPC Smart Quick View for WooCommerceCWE-639 5.3 Medium2025-10-18
CVE-2025-11517 Event Tickets and Registration <= 5.26.5 - Unauthenticated Ticket Payment Bypass — Event Tickets and RegistrationCWE-639 7.5 High2025-10-18
CVE-2025-11738 Media Library Assistant <= 3.29 - Unauthenticated Limited File Read — Media Library AssistantCWE-73 5.3 Medium2025-10-18
CVE-2017-20207 Flickr Gallery <= 1.5.2 - Unauthenticated PHP Object Injection — Flickr GalleryCWE-502 9.8 Critical2025-10-18
CVE-2017-20208 RegistrationMagic - Custom Registration Forms <= 3.7.9.2 - PHP Object Injection — RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User LoginCWE-502 9.8 Critical2025-10-18
CVE-2017-20206 Appointments <= 2.2.1 - Unauthenticated PHP Object Injection — AppointmentsCWE-502 9.8 Critical2025-10-18
CVE-2020-36853 10WebMapBuilder <= 1.0.63 - Unauthenticated Stored Cross-Site Scripting via Plugin Settings Change — 10Web Map Builder for Google MapsCWE-79 7.2 High2025-10-18
CVE-2025-62430 ClipBucket v5 stored XSS via video/photo fields — clipbucket-v5CWE-79 5.4 Medium2025-10-17

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.