Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18842

18842 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-11198 Security Director Policy Enforcer: An unrestricted API allows a network-based unauthenticated attacker to deploy malicious vSRX images to VMWare NSX Server — Security Director Policy EnforcerCWE-306 7.4 High2025-10-09
CVE-2025-10862 Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers <= 2.1.3 - Unauthenticated SQL Injection via 'id' — Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce TriggersCWE-89 7.5 High2025-10-09
CVE-2025-11522 Search & Go - Directory WordPress Theme <= 2.7 - Authentication Bypass to Privilege Escalation via Account Takeover — Search & Go - Directory WordPress ThemeCWE-288 9.8 Critical2025-10-09
CVE-2025-7634 WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Unauthenticated Local File Inclusion — WP Travel Engine – Tour Booking Plugin – Tour Operator SoftwareCWE-98 9.8 Critical2025-10-09
CVE-2025-7526 WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Authenticated (Subscriber+) Arbitrary File Deletion via File Renaming — WP Travel Engine – Tour Booking Plugin – Tour Operator SoftwareCWE-22 9.8 Critical2025-10-09
CVE-2025-10496 Cookie Notice & Consent <= 1.6.5 - Unauthenticated Stored Cross-Site Scripting — Cookie Notice & ConsentCWE-80 7.2 High2025-10-09
CVE-2025-11166 WP Go Maps (formerly WP Google Maps) <= 9.0.46 - Cross-Site Request Forgery to Plugin Settings Update — WP Go Maps (formerly WP Google Maps)CWE-352 5.4 Medium2025-10-09
CVE-2025-61788 Opencast Paella Player 7 vulnerable to Cross-Site-Scripting — opencastCWE-79 5.4AIMediumAI2025-10-08
CVE-2025-9868 Nexus Repository 2 - SSRF Vulnerability in Remote Browser Plugin — Nexus RepositoryCWE-918 7.5AIHighAI2025-10-08
CVE-2025-10352 Missing Authorization vulnerability in Melis Platform — Melis PlatformCWE-862 9.8AICriticalAI2025-10-08
CVE-2025-48464 Exposure of Sensitive Information — DuckDuckGo BrowserCWE-200 4.7 Medium2025-10-08
CVE-2025-11171 Chartify – WordPress Chart Plugin <= 3.5.9 - Missing Authentication for Administrative Function — Chartify – WordPress Chart PluginCWE-306 5.3 Medium2025-10-08
CVE-2025-11204 RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.2 - Authenticated (Administrator+) SQL Injection — RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User LoginCWE-89 7.2 High2025-10-08
CVE-2025-53967 Framelink Figma MCP Server 安全漏洞 — Figma MCP ServerCWE-420 8.0 High2025-10-08
CVE-2025-43727 Dell PowerProtect Data Domain 安全漏洞 — PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature ReleaseCWE-303 7.5 High2025-10-07
CVE-2025-43909 Dell PowerProtect Data Domain 加密问题漏洞 — PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature ReleaseCWE-327 3.7 Low2025-10-07
CVE-2025-43913 Dell PowerProtect Data Domain 加密问题漏洞 — PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature ReleaseCWE-327 5.3 Medium2025-10-07
CVE-2025-43912 Dell PowerProtect Data Domain 安全漏洞 — PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature ReleaseCWE-122 5.3 Medium2025-10-07
CVE-2025-43891 Dell PowerProtect Data Domain 加密问题漏洞 — PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature ReleaseCWE-327 5.3 Medium2025-10-07
CVE-2025-43889 Dell PowerProtect Data Domain 路径遍历漏洞 — PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature ReleaseCWE-22 5.3 Medium2025-10-07
CVE-2025-3449 Weak Session Token used in Automation Runtime SDM — Automation RuntimeCWE-340 4.2 Medium2025-10-07
CVE-2025-3450 Automation Runtime SDM requests may impact system — Automation RuntimeCWE-413 10.0 Critical2025-10-07
CVE-2025-10645 WP Reset <= 2.05 - Unauthenticated Sensitive Information Exposure via wf-licensing.log — WP ResetCWE-532 5.3 Medium2025-10-07
CVE-2025-10162 OrderConvo < 14 - Unauthenticated Arbitrary File Read — Admin and Customer Messages After Order for WooCommerce: OrderConvo 7.5AIHighAI2025-10-07
CVE-2025-57564 CubeAPM 安全漏洞 — n/a 6.5AIMediumAI2025-10-07
CVE-2025-36354 IBM Security Verify Access command execution — Security Verify Access ApplianceCWE-78 7.3 High2025-10-06
CVE-2025-61777 FlagForge Allows Unauthenticated Badge Template API Access — flagForgeCWE-200 9.4 Critical2025-10-06
CVE-2025-58579 Username Disclosure Through Missing Authentication — Baggage AnalyticsCWE-497 5.3 Medium2025-10-06
CVE-2025-9710 Responsive Lightbox & Gallery < 2.5.3 - Unauthenticated Stored-XSS via Comments — Responsive Lightbox & Gallery 6.1AIMediumAI2025-10-06
CVE-2025-11311 Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 findTenantPage.do findTenantPage sql injection — Data Leakage Prevention System 天锐数据泄露防护系统CWE-89 7.3 High2025-10-06

Vulnerabilities classified as access:pre-auth represent 18842 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.