Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18843

18843 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-59345 Dragonfly did not enable authentication for some Manager’s endpoints — dragonflyCWE-306 9.1AICriticalAI2025-09-17
CVE-2025-35436 CISA Thorium account verification email error handling — ThoriumCWE-248 5.3 Medium2025-09-17
CVE-2025-35434 CISA Thorium does not validate TLS connections to Elasticsearch — ThoriumCWE-295 4.2 Medium2025-09-17
CVE-2025-35432 CISA Thorium does not rate limit account verification email messages — ThoriumCWE-400 5.3 Medium2025-09-17
CVE-2025-9242 WatchGuard Firebox iked Out of Bounds Write Vulnerability — Fireware OSCWE-787 9.8AICriticalAI2025-09-17
CVE-2025-9972 Planet Technology|Industrial Cellular Gateway - OS Command Injection — ICG-2510WG-LTE (EU/US)CWE-78 9.8 Critical2025-09-17
CVE-2025-9971 Planet Technology|Industrial Cellular Gateway - Missing Authentication — ICG-2510WG-LTE (EU/US)CWE-306 9.8 Critical2025-09-17
CVE-2025-10042 Quiz Maker <= 6.7.0.56 - Unauthenticated SQL Injection — Quiz MakerCWE-89 5.9 Medium2025-09-17
CVE-2025-10188 The Hack Repair Guy's Plugin Archiver <= 2.0.4 - Cross-Site Request Forgery to Arbitrary Directory Deletion in /wp-content — The Hack Repair Guy's Plugin ArchiverCWE-352 5.4 Medium2025-09-17
CVE-2025-9891 User Sync – Remote User Sync <= 1.0.2 - Cross-Site Request Forgery to Plugin Deactivation — User SyncCWE-352 4.3 Medium2025-09-17
CVE-2025-9629 USS Upyun <= 1.5.0 - Cross-Site Request Forgery — USS UpyunCWE-352 4.3 Medium2025-09-17
CVE-2025-37124 Unauthenticated Access Vulnerability allows Transit Traffic Misrouting in SD-WAN Edge Interface — HPE Aruba Networking EdgeConnect SD-WAN Gateway 8.6 High2025-09-16
CVE-2025-34184 Ilevia EVE X1 Server 4.7.18.0.eden Neuro-Core Unauthenticated Code Injection — EVE X1 ServerCWE-78 9.8AICriticalAI2025-09-16
CVE-2025-34183 Ilevia EVE X1 Server 4.7.18.0.eden Credentials Leak Through Log Disclosure — EVE X1 ServerCWE-532 9.8AICriticalAI2025-09-16
CVE-2025-59270 psPAS does not enforce TLS 1.2 within Get-PASSAMLResponse — psPASCWE-757 3.1 Low2025-09-16
CVE-2009-20006 osCommerce <= 2.2 Admin File Manager Arbitrary PHP Code Execution — osCommerceCWE-434 9.8AICriticalAI2025-09-16
CVE-2025-9808 The Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information Disclosure — The Events CalendarCWE-200 5.3 Medium2025-09-16
CVE-2025-30468 Apple iOS和Apple iPadOS 安全漏洞 — iOS and iPadOS 4.6AIMediumAI2025-09-15
CVE-2025-59361 OS command injection in Chaos Mesh via the cleanIptables mutation CWE-78 9.8 Critical2025-09-15
CVE-2025-59360 OS command injection in Chaos Mesh via the killProcesses mutation CWE-78 9.8 Critical2025-09-15
CVE-2025-59359 OS command injection in Chaos Mesh via the cleanTcs mutation CWE-78 9.8 Critical2025-09-15
CVE-2025-59358 Denial of Service via Unauthorized Access to Chaos Mesh debugging server CWE-306 7.5 High2025-09-15
CVE-2025-41713 WAGO: Vulnerability in hardware switch circuit — CC100 0751-9301CWE-1188 6.5 Medium2025-09-15
CVE-2025-10453 PilotGaea Technologies|O'View MapServer - Server-Side Request Forgery — O'View MapServerCWE-918 5.3 Medium2025-09-15
CVE-2025-10452 Gotac|Statistical Database System - Missing Authentication — Statistical Database SystemCWE-306 9.8 Critical2025-09-15
CVE-2025-52053 TOTOLINK X6000R 安全漏洞 — n/a 9.8AICriticalAI2025-09-15
CVE-2025-57174 Ceragon EtherHaul series 安全漏洞 — n/a 9.8AICriticalAI2025-09-15
CVE-2025-57176 Ceragon EtherHaul series 安全漏洞 — EtherHaul and MultiHaul Series microwave antennasCWE-434 6.5 Medium2025-09-15
CVE-2025-10397 Magicblack MacCMS API server-side request forgery — MacCMSCWE-918 4.7 Medium2025-09-14
CVE-2025-58434 Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover — FlowiseCWE-306 9.8 Critical2025-09-12

Vulnerabilities classified as access:pre-auth represent 18843 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.