Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18840

18840 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-11518 WPC Smart Wishlist for WooCommerce <= 5.0.3 - Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation — WPC Smart Wishlist for WooCommerceCWE-639 5.3 Medium2025-10-11
CVE-2025-11254 Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injection — Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & StripeCWE-1236 4.3 Medium2025-10-11
CVE-2025-6553 Ovatheme Events Manager <= 1.8.5 - Unauthenticated Arbitrary File Upload — Ovatheme Events ManagerCWE-434 9.8 Critical2025-10-11
CVE-2025-9196 Trinity Audio <= 5.21.0 - Unauthenticated Information Exposure — Trinity Audio – Text to Speech AI audio player to convert content into audioCWE-200 5.3 Medium2025-10-11
CVE-2025-11533 WP Freeio <= 1.2.21 - Unauthenticated Privilege Escalation — WP FreeioCWE-269 9.8 Critical2025-10-11
CVE-2025-11380 Everest Backup <= 2.3.5 - Missing Authorization to Unauthenticated Information Exposure — Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning PluginCWE-862 5.9 Medium2025-10-11
CVE-2025-62158 Frappe had attachments made by students to their assignments of type Text set to public — lmsCWE-200 7.5AIHighAI2025-10-10
CVE-2025-61928 Better Auth: Unauthenticated API key creation through api-key plugin — better-authCWE-285 7.5AIHighAI2025-10-09
CVE-2025-35061 Newforma Info Exchange (NIX) forced NTLMv2 authentication via /NPCSRemoteWeb/LegacyIntegrationServices.asmx — Project CenterCWE-294 5.9 Medium2025-10-09
CVE-2025-35062 Newforma Info Exchange (NIX) default anonymous access — Project CenterCWE-276 5.3 Medium2025-10-09
CVE-2025-35059 Newforma Info Exchange (NIX) open URL redirect via /DownloadWeb/hyperlinkredirect.aspx — Project CenterCWE-601 4.3 Medium2025-10-09
CVE-2025-35058 Newforma Info Exchange (NIX) forced NTLMv2 authentication via /UserWeb/Common/MarkupServices.ashx — Project CenterCWE-294 5.9 Medium2025-10-09
CVE-2025-35057 Newforma Info Exchange (NIX) forced NTLMv2 authentication via /RemoteWeb/IntegrationServices.ashx — Project CenterCWE-294 5.3 Medium2025-10-09
CVE-2025-35055 Newforma Info Exchange (NIX) insecure file upload — Project CenterCWE-22 8.8 High2025-10-09
CVE-2025-35053 Newforma Info Exchange (NIX) arbitrary file read and delete — Project CenterCWE-22 6.4 Medium2025-10-09
CVE-2025-35051 Newforma Project Center Server (NPCS) .NET unauthenticated deserialization — Project CenterCWE-502 9.8 Critical2025-10-09
CVE-2025-35050 Newforma Info Exchange (NIX) .NET unauthenticated deserialization — Project CenterCWE-502 9.8 Critical2025-10-09
CVE-2025-11371 Gladinet CentreStack and TrioFox Local File Inclusion Flaw — CentreStack and TrioFox 7.5AIHighAI2025-10-09
CVE-2025-60004 Junos OS and Junos OS Evolved: Specific BGP EVPN update message causes rpd crash — Junos OSCWE-754 7.5 High2025-10-09
CVE-2025-59980 Junos OS: When a user with the name ftp or anonymous is configured unauthenticated filesystem access is allowed — Junos OSCWE-305 6.5 Medium2025-10-09
CVE-2025-59975 Junos Space: Flooding device with inbound API calls leads to WebUI and CLI management access DoS — Junos SpaceCWE-400 7.5 High2025-10-09
CVE-2025-59968 Junos Space Security Director: Insufficient authorization for sensitive resources in web interface — Junos Space Security Director 8.6 High2025-10-09
CVE-2025-59967 Junos OS Evolved: ACX7024, ACX7024X, ACX7100-32C, ACX7100-48L, ACX7348, ACX7509: When specific valid multicast traffic is received on the L3 interface on a vulnerable device evo-pfemand crashes and restarts — Junos OS EvolvedCWE-476 6.5 Medium2025-10-09
CVE-2025-59964 Junos OS: SRX4700: When forwarding-options sampling is enabled any traffic destined to the RE will cause the forwarding line card to crash and restart — Junos OSCWE-908 7.5 High2025-10-09
CVE-2025-59958 Junos OS Evolved: PTX Series: When a firewall filter rejects traffic these packets are erroneously sent to the RE — Junos OS EvolvedCWE-754 6.5 Medium2025-10-09
CVE-2025-59957 Junos OS: EX4600 Series and QFX5000 Series: An attacker with physical access can open a persistent backdoor — Junos OSCWE-346 6.8 Medium2025-10-09
CVE-2025-52961 Junos OS Evolved: PTX Series except PTX10003: An unauthenticated adjacent attacker sending specific valid traffic can cause a memory leak in cfmman leading to FPC crash and restart — Junos OS EvolvedCWE-400 6.5 Medium2025-10-09
CVE-2025-52960 Junos OS: SRX Series and MX Series: Receipt of specific SIP packets in a high utilization situation causes a flowd/mspmand crash — Junos OSCWE-120 5.9 Medium2025-10-09
CVE-2025-11198 Security Director Policy Enforcer: An unrestricted API allows a network-based unauthenticated attacker to deploy malicious vSRX images to VMWare NSX Server — Security Director Policy EnforcerCWE-306 7.4 High2025-10-09
CVE-2025-10862 Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers <= 2.1.3 - Unauthenticated SQL Injection via 'id' — Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce TriggersCWE-89 7.5 High2025-10-09

Vulnerabilities classified as access:pre-auth represent 18840 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.