Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18844

18844 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-5514 Denial-of-Service(DoS) Vulnerability in Web server function on MELSEC iQ-F Series CPU module — MELSEC iQ-F Series FX5U-32MT/ESCWE-130 5.3 Medium2025-08-25
CVE-2025-43960 Adminer 安全漏洞 — n/a 7.5 -2025-08-25
CVE-2025-50900 Rebuild 安全漏洞 — n/a 9.8AICriticalAI2025-08-25
CVE-2025-36157 IBM Engineering Lifecycle Management incorrect authorization — Engineering Lifecycle ManagementCWE-863 9.8 Critical2025-08-24
CVE-2025-5060 Bravis User <= 1.0.1 - Authentication Bypass to Account Takeover — Bravis UserCWE-288 8.1 High2025-08-23
CVE-2025-5821 Case Theme User <= 1.0.3 - Authentication Bypass via Social Login — Case Theme UserCWE-288 9.8 Critical2025-08-23
CVE-2025-7813 Event Manager, Events Calendar, Booking, Registrations and Tickets – Eventin <= 4.0.37 - Unauthenticated Server-Side Request Forgery — Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)CWE-918 7.2 High2025-08-23
CVE-2025-7821 WC Plus <= 1.2.0 - Missing Authorization to Unauthenticated Settings Manipulation — WC PlusCWE-862 5.3 Medium2025-08-23
CVE-2025-7841 Sertifier Certificate & Badge Maker for WordPress – Tutor LMS <= 1.19 - Cross-Site Request Forgery to Settings Update — Sertifier Certificate & Badge Maker for WordPress – Tutor LMSCWE-352 4.3 Medium2025-08-23
CVE-2025-7839 Restore Permanently delete Post or Page Data <= 1.0 - Cross-Site Request Forgery — Restore Permanently delete Post or Page DataCWE-352 4.3 Medium2025-08-23
CVE-2025-7842 Silencesoft RSS Reader <= 0.6 - Cross-Site Request Forgery to RSS Feed Deletion — Silencesoft RSS ReaderCWE-352 4.3 Medium2025-08-23
CVE-2025-7642 Simpler Checkout 0.7.0 - 1.1.9 - Authentication Bypass — Simpler CheckoutCWE-288 9.8 Critical2025-08-23
CVE-2025-43758 Liferay Portal和Liferay DXP 安全漏洞 — PortalCWE-552 7.5AIHighAI2025-08-22
CVE-2025-57770 ZITADEL user enumeration vulnerability in login UI — zitadelCWE-203 5.3 Medium2025-08-22
CVE-2025-9255 Uniong|WebITR - SQL Injection — WebITRCWE-89 7.5 High2025-08-22
CVE-2025-9254 Uniong|WebITR - Missing Authentication — WebITRCWE-306 9.8 Critical2025-08-22
CVE-2025-8281 WP Talroo <= 2.4 - Reflected XSS — WP Talroo 6.1 -2025-08-22
CVE-2024-52786 AJ-Report 安全漏洞 — n/a 9.8 -2025-08-22
CVE-2024-53494 Kyrie Blog 安全漏洞 — n/a 7.5AIHighAI2025-08-22
CVE-2024-53496 my-site 安全漏洞 — n/a 7.5 -2025-08-22
CVE-2022-31491 Voltronic Power多款产品 安全漏洞 — n/a 9.8 -2025-08-22
CVE-2022-43110 Voltronic Power ViewPower和PowerShield NetGuard 安全漏洞 — n/a 10.0 -2025-08-22
CVE-2010-20121 EasyFTP Server <= 1.7.0.11 CWD Command Stack Buffer Overflow — EasyFTP ServerCWE-121 9.8AICriticalAI2025-08-21
CVE-2010-20109 Barracuda Spam & Virus Firewall "locale" Path Traversal — Spam & Virus FirewallCWE-22 9.1AICriticalAI2025-08-21
CVE-2025-3128 Mitsubishi Electric Europe smartRTU OS Command Injection — smartRTUCWE-78 9.8 Critical2025-08-21
CVE-2025-8895 WP Webhooks <= 3.3.5 - Unauthenticated Arbitrary File Copy — WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPressCWE-22 9.8 Critical2025-08-21
CVE-2025-8592 Inspiro <= 2.1.2 - Cross-Site Request Forgery to Arbitrary Plugin Installation — InspiroCWE-352 8.1 High2025-08-21
CVE-2025-52352 Aikaan IoT management platform 安全漏洞 — n/a 9.8 -2025-08-21
CVE-2024-45438 TitanHQ SpamTitan Email Security Gateway 安全漏洞 — n/a 7.5 -2025-08-21
CVE-2025-55746 Directus allows unauthenticated file upload and file modification due to lacking input sanitization — directusCWE-73 9.3 Critical2025-08-20

Vulnerabilities classified as access:pre-auth represent 18844 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.