Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18842

18842 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-9213 TextBuilder 1.0.0 - 1.1.1 - Cross-Site Request Forgery to Privilege Escalation via Account Takeover — TextBuilderCWE-352 8.8 High2025-10-03
CVE-2025-6388 Spirit Framework <= 1.2.14 - Authentication Bypass to Account Takeover and Privilege Escalation — Spirit FrameworkCWE-288 9.8 Critical2025-10-03
CVE-2025-55971 TCL 65C655 Smart TV 安全漏洞 — n/a 9.8AICriticalAI2025-10-03
CVE-2025-55972 TCL 65C655 Smart TV 安全漏洞 — n/a 7.5AIHighAI2025-10-03
CVE-2025-57423 MyClub 安全漏洞 — n/a 9.1AICriticalAI2025-10-03
CVE-2025-61666 Traccar Unauthenticated Local File Inclusion on Windows - Leakage of Traccar Config File — traccarCWE-22 9.1AICriticalAI2025-10-02
CVE-2025-61665 WeGIA: Broken Access Control in `get_relatorios_socios.php` Endpoint — WeGIACWE-287 7.5 -2025-10-02
CVE-2025-10653 Raise3D Pro2 Series 3D Printers Authentication Bypass Using an Alternate Path or Channel — Pro2 SeriesCWE-288 8.6 High2025-10-02
CVE-2025-11240 Open redirect vulnerability in KNIME Business Hub — KNIME Business HubCWE-601 6.1 -2025-10-02
CVE-2025-40645 Exposure of sensitive information in Viday — ViDayCWE-200 7.5AIHighAI2025-10-02
CVE-2025-54291 Project existence disclosure in LXD images API — LXDCWE-209 5.3AIMediumAI2025-10-02
CVE-2025-54290 Project Existence Disclosure via Error Handling in LXD Image Export — LXDCWE-200 5.3AIMediumAI2025-10-02
CVE-2025-9697 Ajax WooSearch <= 1.0.0 - Unauthenticated SQL Injection — Ajax WooSearch 9.8AICriticalAI2025-10-02
CVE-2025-9587 CTL Behance Importer Lite <= 1.0 - Unauthenticated SQL Injection — CTL Behance Importer Lite 9.8AICriticalAI2025-10-02
CVE-2025-56019 Agasta Easytouch Plus 安全漏洞 — n/a 6.5AIMediumAI2025-10-02
CVE-2025-56161 Yoshop 安全漏洞 — n/a 7.5AIHighAI2025-10-02
CVE-2025-56162 Yoshop 安全漏洞 — n/a 9.8AICriticalAI2025-10-02
CVE-2025-59403 Flock Safety Android Collins 安全漏洞 — n/a 9.8AICriticalAI2025-10-02
CVE-2023-28760 TP-Link AX1800 安全漏洞 — n/a 8.8AIHighAI2025-10-02
CVE-2025-61582 Ts3 Manager: Unauthenticated Denial of Service possible through specially crafted Unicode input — ts3-managerCWE-20 7.5 High2025-10-01
CVE-2025-54811 OpenPLC_V3 — OpenPLC_V3CWE-758 7.1 High2025-10-01
CVE-2025-59538 Argo CD is Vulnerable to Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook — argo-cdCWE-248 7.5 High2025-10-01
CVE-2025-59531 Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload — argo-cdCWE-703 7.5 High2025-10-01
CVE-2025-8679 ExtremeGuest Essentials Captive Portal Unauthenticated Brute Force — ExtremeGuest EssentialsCWE-307 8.2AIHighAI2025-10-01
CVE-2025-20371 Unauthenticated Blind Server Side Request Forgery (SSRF) in Splunk Enterprise — Splunk EnterpriseCWE-918 7.5 High2025-10-01
CVE-2020-36852 Custom Searchable Data Entry System <= 1.7.1 - Unauthenticated Database Wiping — Custom Searchable Data Entry SystemCWE-862 9.1 Critical2025-10-01
CVE-2025-9512 Schema & Structured Data for WP & AMP < 1.50 - Unauthenticated Stored-XSS — Schema & Structured Data for WP & AMP 6.1AIMediumAI2025-10-01
CVE-2025-10735 Block For Mailchimp – Easy Mailchimp Form Integration <= 1.1.12 - Unauthenticated Blind Server-Side Request Forgery — Block for Mailchimp – Add Email Subscription Forms and Collect LeadsCWE-918 4.0 Medium2025-10-01
CVE-2025-10744 File Manager, Code editor, backup by Managefy <= 1.6.1 - Unauthenticated Information Exposure — File Manager, Code Editor, and Backup by ManagefyCWE-200 5.9 Medium2025-10-01
CVE-2025-10659 MegaSys Enterprises Telenium Online Web Application OS Command Injection — Telenium Online Web Application:CWE-78 9.8 Critical2025-09-30

Vulnerabilities classified as access:pre-auth represent 18842 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.