Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18842

18842 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-41251 Weak password recovery vulnerability — NSXCWE-640 8.1 High2025-09-29
CVE-2025-57872 BUG-000174150 - Unvalidated redirect in Portal for ArcGIS. — Portal for ArcGISCWE-601 6.1 Medium2025-09-29
CVE-2025-57878 BUG-000174149 - The Portal for ArcGIS has an unvalidated redirect. — Portal for ArcGISCWE-601 6.1 Medium2025-09-29
CVE-2025-57879 BUG-000171009 - URL manipulation vulnerability in Portal for ArcGIS. — Portal for ArcGISCWE-601 6.1 Medium2025-09-29
CVE-2025-57266 ThriveX-Blog 安全漏洞 — n/a 7.5AIHighAI2025-09-29
CVE-2025-8014 Allocation of Resources Without Limits or Throttling in GitLab — GitLabCWE-770 7.5 High2025-09-27
CVE-2025-9893 VM Menu Reorder plugin <= 1.0.0 - Cross-Site Request Forgery to Settings Update — VM Menu Reorder pluginCWE-352 4.3 Medium2025-09-27
CVE-2025-9944 Professional Contact Form <= 1.0.0 - Cross-Site Request Forgery to Test Email Sending — Professional Contact FormCWE-352 4.3 Medium2025-09-27
CVE-2025-9898 cForms – Light speed fast Form Builder <= 3.0.0 - Cross-Site Request Forgery — cForms – Light speed fast Form BuilderCWE-352 4.3 Medium2025-09-27
CVE-2025-9899 Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms <= 1.0 - Cross-Site Request Forgery — Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platformsCWE-352 6.1 Medium2025-09-27
CVE-2025-9894 Sync Feedly <= 1.0.1 - Cross-Site Request Forgery to Sync Trigger — Sync FeedlyCWE-352 4.3 Medium2025-09-27
CVE-2025-9896 HidePost <= 2.3.8 - Cross-Site Request Forgery — HidePostCWE-352 4.3 Medium2025-09-27
CVE-2025-9816 WP Statistics <= 14.5.4 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header — WP Statistics – Simple, privacy-friendly Google Analytics alternativeCWE-79 7.2 High2025-09-27
CVE-2025-10498 Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion — Ninja Forms – The Contact Form Builder That Grows With YouCWE-352 4.3 Medium2025-09-27
CVE-2025-10499 Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update — Ninja Forms – The Contact Form Builder That Grows With YouCWE-352 4.3 Medium2025-09-27
CVE-2025-36239 IBM Storage TS4500 Library cross-site scripting — Storage TS4500 LibraryCWE-79 6.1 Medium2025-09-27
CVE-2025-36274 IBM Aspera HTTP Gateway information disclosure — Aspera HTTP GatewayCWE-319 7.5 High2025-09-26
CVE-2025-10858 Allocation of Resources Without Limits or Throttling in GitLab — GitLabCWE-770 7.5 High2025-09-26
CVE-2025-10137 Snow Monkey <= 29.1.5 - Unauthenticated Blind Server-Side Request Forgery — Snow MonkeyCWE-918 5.4 Medium2025-09-26
CVE-2025-9984 Featured Image from URL (FIFU) <= 5.2.7 - Missing Authorization to Password Protected Post Disclosure — Featured Image from URL (FIFU)CWE-862 5.3 Medium2025-09-26
CVE-2025-9985 Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File — Featured Image from URL (FIFU)CWE-532 5.3 Medium2025-09-26
CVE-2025-10377 System Dashboard <= 2.8.20 - Cross-Site Request Forgery — System DashboardCWE-352 4.3 Medium2025-09-26
CVE-2025-10745 Banhammer – Monitor Site Traffic, Block Bad Users and Bots <= 3.4.8 - Unauthenticated Protection Mechanism Bypass — Banhammer – Monitor Site Traffic, Block Bad Users and BotsCWE-330 5.3 Medium2025-09-26
CVE-2025-10752 OAuth Single Sign On – SSO (OAuth Client) <= 6.26.12 - Cross-Site Request Forgery — OAuth Single Sign On – SSO (OAuth Client)CWE-352 4.3 Medium2025-09-26
CVE-2025-10880 Insufficiently Protected Credentials in Dingtian DT-R002 — DT-R002CWE-522 7.5AIHighAI2025-09-25
CVE-2025-10879 Insufficiently Protected Credentials in Dingtian DT-R002 — DT-R002CWE-522 5.3AIMediumAI2025-09-25
CVE-2025-20363 Cisco多款产品 安全漏洞 — IOSCWE-122 9.0 Critical2025-09-25
CVE-2025-20362 Cisco Secure Firewall Adaptive Security Appliance和Cisco Secure Firewall Threat Defense 安全漏洞 — Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-862 6.5 Medium2025-09-25
CVE-2024-48014 Dell BSAFE Micro Edition Suite 缓冲区错误漏洞 — BSAFE Micro Edition SuiteCWE-787 7.5 High2025-09-25
CVE-2025-36601 Dell PowerScale OneFS 信息泄露漏洞 — PowerScale OneFSCWE-200 4.0 Medium2025-09-25

Vulnerabilities classified as access:pre-auth represent 18842 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.