Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18842

18842 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2020-36851 Rob--W / cors-anywhere Misconfigured CORS Proxy Allows SSRF — Rob--W / cors-anywhereCWE-942 9.1AICriticalAI2025-09-25
CVE-2025-10540 Unencrypted and Unauthenticated Communication Allows Data Exposure and Manipulation in iMonitor EAM — iMonitor EAMCWE-319 9.8AICriticalAI2025-09-25
CVE-2025-20314 Cisco IOS XE 安全漏洞 — Cisco IOS XE SoftwareCWE-232 6.7 Medium2025-09-24
CVE-2025-48867 Horilla Stored Cross-Site Scripting (XSS) Vulnerability in Project and Task Modules — horillaCWE-79 4.8 Medium2025-09-24
CVE-2025-48869 Horilla Unauthorized Access to Candidate Resume Files Due to Broken Access Control — horillaCWE-284 7.5 High2025-09-24
CVE-2025-20316 Cisco IOS XE 访问控制错误漏洞 — Cisco IOS XE SoftwareCWE-284 5.3 Medium2025-09-24
CVE-2025-20293 Cisco IOS XE Software 安全漏洞 — Cisco IOS XE SoftwareCWE-459 5.3 Medium2025-09-24
CVE-2025-20240 Cisco IOS XE Software 安全漏洞 — Cisco IOS XE SoftwareCWE-692 6.1 Medium2025-09-24
CVE-2025-20313 Cisco IOS XE 安全漏洞 — Cisco IOS XE SoftwareCWE-35 6.7 Medium2025-09-24
CVE-2025-20311 Cisco IOS XE Software 代码问题漏洞 — Cisco IOS XE SoftwareCWE-19 7.4 High2025-09-24
CVE-2025-20160 Cisco IOS和Cisco IOS XE Software 授权问题漏洞 — IOSCWE-287 8.1 High2025-09-24
CVE-2025-20315 Cisco IOS XE 安全漏洞 — Cisco IOS XE SoftwareCWE-805 8.6 High2025-09-24
CVE-2025-20334 Cisco IOS XE 命令注入漏洞 — Cisco IOS XE SoftwareCWE-77 8.8 High2025-09-24
CVE-2025-20339 Cisco SD-WAN vEdge Software Access Control List Bypass Vulnerability — Cisco SD-WAN vEdge CloudCWE-284 5.8 Medium2025-09-24
CVE-2025-20365 Cisco Access Point Software 安全漏洞 — Cisco Aironet Access Point Software (IOS XE Controller)CWE-940 4.3 Medium2025-09-24
CVE-2025-20364 Cisco Wireless LAN Controller 安全漏洞 — Cisco Aironet Access Point Software (IOS XE Controller)CWE-346 4.3 Medium2025-09-24
CVE-2025-9054 MultiLoca - WooCommerce Multi Locations Inventory Management <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Options Update via 'wcmlim_settings_ajax_handler' — MultiLoca - WooCommerce Multi Locations Inventory ManagementCWE-862 9.8 Critical2025-09-24
CVE-2025-41716 Unauthenticated User Enumeration via Missing Authentication — Solution BuilderCWE-306 5.3 Medium2025-09-24
CVE-2025-41715 Missing Authentication for Database Access in Web Application — Device SphereCWE-306 9.8 Critical2025-09-24
CVE-2025-56241 Aztech DSL5005EN 安全漏洞 — n/a 9.8AICriticalAI2025-09-24
CVE-2025-57882 AutomationDirect CLICK PLUS Improper Resource Shutdown or Release — CLICK PLUS C0-0x CPU firmwareCWE-404 5.9 Medium2025-09-23
CVE-2025-58473 AutomationDirect CLICK PLUS Improper Resource Shutdown or Release — CLICK PLUS C0-0x CPU firmwareCWE-404 5.9 Medium2025-09-23
CVE-2025-9965 UDP Service Weak Authentication — P series (P07, P10, P12, P15)CWE-287 9.1AICriticalAI2025-09-23
CVE-2025-10412 Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) <= 4.9.55 - Unauthenticated Arbitrary File Upload via 'uni_cpo_upload_file' — Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium)CWE-434 9.8 Critical2025-09-23
CVE-2025-10147 Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload — Podlove Podcast PublisherCWE-434 9.8 Critical2025-09-23
CVE-2025-26399 SolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnerability — Web Help DeskCWE-502 9.8 Critical2025-09-23
CVE-2025-9321 WPCasa <= 1.4.1 - Unauthenticated Code Injection — WPCasaCWE-94 9.8 Critical2025-09-23
CVE-2025-59559 WordPress Payrexx Payment Gateway for WooCommerce Plugin <= 3.1.5 - Broken Access Control Vulnerability — Payrexx Payment Gateway for WooCommerceCWE-862 4.3 Medium2025-09-22
CVE-2025-58668 WordPress WPLMS theme <= 4.970 - Broken Access Control vulnerability — WPLMSCWE-862 4.3 Medium2025-09-22
CVE-2025-10793 code-projects E-Commerce Website admin_account_delete.php sql injection — E-Commerce WebsiteCWE-89 7.3 High2025-09-22

Vulnerabilities classified as access:pre-auth represent 18842 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.