Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18848

18848 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-7710 Brave Conversion Engine (PRO) <= 0.7.7 - Authentication Bypass to Administrator — Brave Conversion Engine (PRO)CWE-288 9.8 Critical2025-08-02
CVE-2025-6722 BitFire <= 4.5 - Unauthenticated Information Exposure — BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login SecurityCWE-200 5.3 Medium2025-08-02
CVE-2025-8400 Image Gallery <= 1.0.0 - Reflected Cross-Site Scripting — Image GalleryCWE-79 6.1 Medium2025-08-02
CVE-2025-6832 All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier <= 2.0 - Reflected Cross-Site Scripting — All in One Time Clock Lite – Tracking Employee Time Has Never Been EasierCWE-79 6.1 Medium2025-08-02
CVE-2025-8152 WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons <= 1.7.0 - Missing Authorization to Unauthenticated Sticky Status Update — WP CTA – Call Now Button, Sticky Button & Call to Action BuilderCWE-862 5.3 Medium2025-08-02
CVE-2025-54955 OpenNebula 竞争条件问题漏洞 — OpenNebulaCWE-362 8.1 High2025-08-02
CVE-2025-54792 LocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interception — localsendCWE-300 6.8 -2025-08-01
CVE-2013-10049 Raidsonic NAS Devices Unauthenticated Remote Command Execution — IB-NAS5220CWE-78 9.8 -2025-08-01
CVE-2013-10047 MiniWeb <= Build 300 Arbitrary File Upload — MiniWebCWE-434 9.8 -2025-08-01
CVE-2012-10022 Kloxo <= 6.1.12 Local Privilege Escalation — KloxoCWE-269 8.4 -2025-08-01
CVE-2013-10055 Havalite CMS Arbitary File Upload RCE — Havalite CMSCWE-434 9.8 -2025-08-01
CVE-2013-10048 D-Link Devices command.php Unauthenticated RCE — DIR-600CWE-78 9.8 -2025-08-01
CVE-2013-10046 Agnitum Outpost Internet Security Local Privilege Escalation — Outpost Internet SecurityCWE-22 8.4 -2025-08-01
CVE-2025-54595 Pearcleaner's unauthenticated access to privileged XPC helper allows root command execution — PearcleanerCWE-78 7.3 High2025-08-01
CVE-2025-5921 SureForms < 1.7.2 - Reflected XSS — SureForms 6.1 -2025-08-01
CVE-2025-7443 BerqWP <= 2.2.42 - Unauthenticated Arbitrary File Upload — BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScriptCWE-434 8.1 High2025-08-01
CVE-2025-7725 Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting — Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & StripeCWE-79 7.2 High2025-08-01
CVE-2025-5947 Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie — Service Finder BookingsCWE-639 9.8 Critical2025-08-01
CVE-2025-5954 Service Finder SMS System <= 2.0.0 - Unauthenticated Privilege Escalation — Service Finder SMS SystemCWE-269 9.8 Critical2025-08-01
CVE-2025-50870 Institute-of-Current-Students 安全漏洞 — n/a 6.5 -2025-08-01
CVE-2025-8286 Güralp Systems FMUS Series and MIN Series Devices — Güralp FMUS SeriesCWE-306 9.8AICriticalAI2025-07-31
CVE-2025-54833 OPEXUS FOIAXpress Public Access Link (PAL) account-lockout and CAPTCHA protection bypass — FOIAXpress Public Access Link (PAL)CWE-307 5.3 Medium2025-07-31
CVE-2025-54834 OPEXUS FOIAXpress Public Access Link (PAL) unauthenticated username enumeration — FOIAXpress Public Access Link (PAL)CWE-204 5.3 Medium2025-07-31
CVE-2013-10037 WebTester 5.x install2.php Unauthenticated Command Execution — WebTesterCWE-78 9.8AICriticalAI2025-07-31
CVE-2014-125126 Simple E-Document Arbitrary File Upload RCE — Simple E-DocumentCWE-434 9.8AICriticalAI2025-07-31
CVE-2014-125124 Pandora FMS <= 5.0RC1 Anyterm Unauthenticated Command Injection — Pandora FMSCWE-78 9.8AICriticalAI2025-07-31
CVE-2014-125122 Linksys WRT120N tmUnblock.cgi Stack-Based Buffer Overflow Admin Password Reset — WRT120NCWE-121 9.8AICriticalAI2025-07-31
CVE-2014-125123 Kloxo < 6.1.12 Unauthenticated SQL Injection RCE — KloxoCWE-89 9.8AICriticalAI2025-07-31
CVE-2013-10033 Kimai 0.9.2 db_restore.php SQL Injection — KimaiCWE-89 9.8AICriticalAI2025-07-31
CVE-2013-10034 Kaseya < 6.3.0.2 uploadImage.asp Arbitrary File Upload RCE — KServerCWE-434 9.8AICriticalAI2025-07-31

Vulnerabilities classified as access:pre-auth represent 18848 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.