Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18848

18848 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-51539 EzGED 安全漏洞 — n/a 9.1 -2025-08-19
CVE-2024-44373 Allsky Camera 安全漏洞 — n/a 9.8 -2025-08-19
CVE-2025-3639 Liferay Portal和Liferay DXP 安全漏洞 — PortalCWE-288 9.8AICriticalAI2025-08-18
CVE-2025-54118 NamelessMC allows sensitive information disclosure in member list component — NamelessCWE-200 5.3 Medium2025-08-18
CVE-2025-8105 Soledad <= 8.6.7 - Unauthenticated Arbitrary Shortcode Execution — SoledadCWE-94 7.3 High2025-08-16
CVE-2025-8878 Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.4 - Unauthenticated Arbitrary Shortcode Execution — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePressCWE-94 6.5 Medium2025-08-16
CVE-2025-7499 BetterDocs <= 4.1.1 - Missing Authorization to Private And Password-Protected Posts Information Disclosure — BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block EditorCWE-862 5.3 Medium2025-08-16
CVE-2025-8464 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.0 - Directory Traversal via `wpcf7_guest_user_id` Cookie — Drag and Drop Multiple File Upload for Contact Form 7CWE-23 5.3 Medium2025-08-16
CVE-2025-8898 Taxi Booking Manager for Woocommerce | E-cab <= 1.3.0 - Missing Authorization to Unauthenticated Privilege Escalation via Account Takeover — E-cab Taxi Booking Manager for WoocommerceCWE-862 9.8 Critical2025-08-16
CVE-2025-7686 weichuncai(WP伪春菜) <= 1.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting — weichuncai(WP伪春菜)CWE-352 6.1 Medium2025-08-16
CVE-2025-7683 LatestCheckins <= 1 - Cross-Site Request Forgery to Stored Cross-Site Scripting — LatestCheckinsCWE-352 6.1 Medium2025-08-16
CVE-2025-7441 StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload — StoryChiefCWE-434 9.8 Critical2025-08-16
CVE-2025-7664 Al Pack <= 1.1.1 - Missing Authorization to Unauthenticated Premium Feature Activation via check_activate_permission Function — AL PackCWE-862 7.5 High2025-08-16
CVE-2025-7668 Linux Promotional Plugin <= 1.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Linux Promotional PluginCWE-352 6.1 Medium2025-08-16
CVE-2025-7684 Last.fm Recent Album Artwork <= 1.0.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Last.fm Recent Album ArtworkCWE-352 6.1 Medium2025-08-16
CVE-2024-12612 School Management System for Wordpress <= 93.2.0 - Unauthenticated SQL Injection — School Management System for WordpressCWE-89 7.5 High2025-08-16
CVE-2024-12575 Poll Maker – Versus Polls, Anonymous Polls, Image Polls <= 5.8.9 - Unauthenticated Basic Information Exposure — Poll Maker – Versus Polls, Anonymous Polls, Image PollsCWE-200 5.3 Medium2025-08-16
CVE-2025-54466 Apache OFBiz: RCE Vulnerability in scrum plugin — Apache OFBizCWE-94 9.8AICriticalAI2025-08-15
CVE-2025-7688 Add User Meta <= 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Add User MetaCWE-352 6.1 Medium2025-08-15
CVE-2025-7778 Icons Factory <= 1.6.12 - Missing Authorization to Unauthenticated Arbitrary File Deletion via delete_files() Function — Icons FactoryCWE-285 9.8 Critical2025-08-15
CVE-2025-8091 EventON Lite <= 2.4.7 - Authenticated (Contributor+) Information Disclosure — EventON – Events CalendarCWE-200 4.3 Medium2025-08-15
CVE-2025-7641 Assistant for NextGEN Gallery <= 1.0.9 - Unauthenticated Arbitrary Directory Deletion — Assistant for NextGEN GalleryCWE-22 7.5 High2025-08-15
CVE-2025-6679 Contact Form by Bit Form - Bit Form <= 2.20.3 - Unauthenticated Arbitrary File Upload — Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builderCWE-434 9.8 Critical2025-08-15
CVE-2025-6025 Order Tip for WooCommerce <= 1.5.4 - Unauthenticated Tip Manipulation to Negative Value Leading to Unauthorized Discounts — Order Tip for WooCommerceCWE-602 7.5 High2025-08-15
CVE-2025-8342 WooCommerce OTP Login With Phone Number, OTP Verification <= 1.8.47 - Authentication Bypass — OTP Login With Phone Number, OTP VerificationCWE-862 8.1 High2025-08-15
CVE-2025-20268 Cisco Secure Firewall Threat Defense Software Geolocation Remote Access VPN Bypass Vulnerability — Cisco Firepower Threat Defense SoftwareCWE-229 5.8 Medium2025-08-14
CVE-2025-20265 Cisco Secure Firewall Management Center Software Radius Remote Code Execution Vulnerability — Cisco Firepower Management CenterCWE-74 10.0 Critical2025-08-14
CVE-2025-20254 Cisco Secure Firewall Adaptive Security Appliance和Cisco Secure Firewall Threat Defense 安全漏洞 — Cisco Adaptive Security Appliance (ASA) SoftwareCWE-401 5.8 Medium2025-08-14
CVE-2025-20263 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Buffer Overflow Denial of Service Vulnerability — Cisco Adaptive Security Appliance (ASA) SoftwareCWE-680 8.6 High2025-08-14
CVE-2025-20253 Cisco IOS, IOS XE, Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability — Cisco Adaptive Security Appliance (ASA) SoftwareCWE-835 8.6 High2025-08-14

Vulnerabilities classified as access:pre-auth represent 18848 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.