Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18843

18843 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-10364 Unauthenticated Arbitrary Command Injection in Evertz SDVN — 3080ipx-10GCWE-77 9.8 -2025-09-12
CVE-2025-10365 Authentication Bypass in Evertz SDVN — 3080ipx-10GCWE-287 9.8 -2025-09-12
CVE-2025-10267 NewType Infortech|NUP Portal - Missing Authentication — NUP PortalCWE-306 5.3 Medium2025-09-12
CVE-2025-10266 NewType Infortech|NUP Portal - SQL Injection — NUP PortalCWE-89 9.8 Critical2025-09-12
CVE-2025-10264 Digiever|NVR - Exposure of Sensitive Information — DS-1200CWE-497 10.0 Critical2025-09-12
CVE-2025-9881 Ultimate Blogroll <= 2.5.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Ultimate BlogrollCWE-352 6.1 Medium2025-09-12
CVE-2025-9880 Side Slide Responsive Menu <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Side Slide Responsive MenuCWE-352 6.1 Medium2025-09-12
CVE-2025-9807 The Events Calendar <= 6.15.1 - Unauthenticated SQL Injection — The Events CalendarCWE-89 7.5 High2025-09-12
CVE-2025-45584 Audi UTR 2.0 安全漏洞 — n/a 5.3 -2025-09-12
CVE-2025-56467 AXIS BANK Axis Mobile App 安全漏洞 — n/a 2.4 -2025-09-12
CVE-2025-9633 LH Signing <= 2.83 - Cross-Site Request Forgery — LH SigningCWE-352 4.3 Medium2025-09-11
CVE-2025-9617 Publish approval <= 1.1 - Cross-Site Request Forgery — Publish approvalCWE-352 5.3 Medium2025-09-11
CVE-2025-9632 PhpList Subber <= 1.1 - Cross-Site Request Forgery — PhpList SubberCWE-352 4.3 Medium2025-09-11
CVE-2025-9620 Seo Monster <= 3.3.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Seo MonsterCWE-352 6.1 Medium2025-09-11
CVE-2025-8570 BeyondCart Connector <= 3.0.1 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation via determine_current_user Filter — BeyondCart ConnectorCWE-798 9.8 Critical2025-09-11
CVE-2025-8481 Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid <= 1.1.7 - Cross-Site Request Forgery — Blog Designer For Elementor – Post Slider, Post Carousel, Post GridCWE-352 4.3 Medium2025-09-11
CVE-2025-9623 Admin in English with Switch <= 1.1 - Cross-Site Request Forgery — Admin in English with SwitchCWE-352 4.3 Medium2025-09-11
CVE-2025-8492 Salon Booking System <= 10.22 - Missing Authorization to Unauthenticated AJAX Actions Execution — Salon Booking System – Free VersionCWE-862 5.3 Medium2025-09-11
CVE-2025-9627 Run Log <= 1.7.10 - Cross-Site Request Forgery to Settings Update — Run LogCWE-352 4.3 Medium2025-09-11
CVE-2025-9634 Plugin updates blocker <= 0.2 - Cross-Site Request Forgery — Plugin updates blockerCWE-352 4.3 Medium2025-09-11
CVE-2025-9635 Analytics Reduce Bounce Rate <= 2.3 - Cross-Site Request Forgery — Analytics Reduce Bounce RateCWE-352 4.3 Medium2025-09-11
CVE-2025-9073 All in one Minifier <= 3.2 - Unauthenticated SQL Injection — All in one MinifierCWE-89 7.5 High2025-09-11
CVE-2025-8417 Catalog Importer, Scraper & Crawler <= 5.1.4 - Unauthenticated PHP Code Injection — Catalog Importer, Scraper & CrawlerCWE-94 8.1 High2025-09-11
CVE-2025-8422 Propovoice <= 1.7.6.7 - Unauthenticated Arbitrary File Read — Propovoice: All-in-One Client Management SystemCWE-73 7.5 High2025-09-11
CVE-2025-9628 The integration of the AMO.CRM <= 1.0.1 - Cross-Site Request Forgery — The integration of the AMO.CRMCWE-352 4.3 Medium2025-09-11
CVE-2025-9631 AutoCatSet <= 2.1.4 - Cross-Site Request Forgery — AutoCatSetCWE-352 4.3 Medium2025-09-11
CVE-2025-8479 Zoho Flow <= 2.14.1 - Cross-Site Request Forgery — Zoho Flow – Integrate 100+ plugins with 1000+ business apps, no-code workflow automationCWE-352 4.3 Medium2025-09-11
CVE-2025-54376 Hoverfly's WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled. — hoverflyCWE-200 7.5AIHighAI2025-09-10
CVE-2025-8696 DoS attack against the Stork UI from an unauthenticated user — StorkCWE-789 7.5 High2025-09-10
CVE-2025-20340 Cisco IOS XR Address Resolution Protocol Broadcast Storm Vulnerability — Cisco IOS XR SoftwareCWE-400 7.4 High2025-09-10

Vulnerabilities classified as access:pre-auth represent 18843 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.