Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18851

18851 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-8097 WoodMart - Multipurpose WooCommerce Theme <= 8.2.6 - Improper Input Validation Leading to Unauthenticated Cart Manipulation — WoodmartCWE-20 5.3 Medium2025-07-26
CVE-2025-8198 MinimogWP – The High Converting eCommerce WordPress Theme <= 3.9.0 - Unauthenticated Price Manipulation — MinimogWP – The High Converting eCommerce WordPress ThemeCWE-472 7.5 High2025-07-26
CVE-2025-6895 MelaPress Login Security 2.1.0 - 2.1.1 - Authentication Bypass to Privilege Escalation via get_valid_user_based_on_token Function — Melapress Login SecurityCWE-288 9.8 Critical2025-07-26
CVE-2025-8103 WPeMatico RSS Feed Fetcher <= 2.8.7 - Cross-Site Request Forgery to Plugin Deactivation via handle_feedback_submission Function — WPeMatico RSS Feed FetcherCWE-352 4.3 Medium2025-07-26
CVE-2024-13507 GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 - Unauthenticated SQL Injection — GeoDirectory – WP Business Directory Plugin and Classified Listings DirectoryCWE-89 7.5 High2025-07-26
CVE-2025-3508 Certain HP DesignJet products – Information disclosure — Certain HP DesignJet productsCWE-200 5.3 -2025-07-25
CVE-2025-34139 Sitecore XM/XP/XC and Managed Cloud 8.0 - 10.4 Arbitrary File Read — Experience Manager (XM)CWE-522 7.5 -2025-07-25
CVE-2014-125115 Pandora FMS ≤ 5.0 SP2 Default Credential SQL Injection RCE — Pandora FMSCWE-798 9.8 -2025-07-25
CVE-2014-125116 HybridAuth 2.0.9 - 2.2.2 Unauthenticated RCE via install.php Configuration Injection — HybridAuthCWE-434 9.8 -2025-07-25
CVE-2014-125117 D-Link info.cgi POST Request Stack-Based Buffer Overflow RCE — DSP-W215CWE-121 9.8 -2025-07-25
CVE-2025-34136 Commvault CommServe Web Server Unauthenticated SQL Injection — CommvaultCWE-89 9.8 -2025-07-25
CVE-2023-7306 Frontend File Manager <= 21.5 - Missing Authorization to Unauthenticated Arbitrary Post Deletion — Frontend File Manager PluginCWE-862 7.5 High2025-07-25
CVE-2019-25224 WP Database Backup < 5.2 - Unauthenticated OS Command Injection — WP Database Backup – Unlimited Database & Files Backup by Backup for WPCWE-78 9.8 Critical2025-07-25
CVE-2015-10143 Platform < 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Options Update — PlatformCWE-862 9.8 Critical2025-07-25
CVE-2025-51411 Institute-of-Current-Students 安全漏洞 — n/a 6.1 -2025-07-25
CVE-2025-30135 IROAD Dashcam FX2 安全漏洞 — n/a 7.5 -2025-07-25
CVE-2025-54379 eKuiper API endpoints handling SQL queries with user-controlled table names. — ekuiperCWE-89 9.8 -2025-07-24
CVE-2025-6260 Network Thermostat X-Series WiFi Thermostats Missing Authentication for Critical Function — X-Series WiFi thermostatsCWE-306 9.8 Critical2025-07-24
CVE-2025-6998 Calibre Web 0.6.24 & Autocaliweb 0.7.0 - ReDoS — Calibre WebCWE-1333 7.5 -2025-07-24
CVE-2025-6588 FunnelCockpit <= 1.4.3 - Reflected Cross-Site Scripting via `error` Parameter — FunnelCockpitCWE-79 6.1 Medium2025-07-24
CVE-2025-7690 Affiliate Plus <= 1.3.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Affiliate PlusCWE-352 6.1 Medium2025-07-24
CVE-2025-7835 iThoughts Advanced Code Editor <= 1.2.10 - Cross-Site Request Forgery to Settings Update — iThoughts Advanced Code EditorCWE-352 4.3 Medium2025-07-24
CVE-2025-6380 ONLYOFFICE Docs 1.1.0 - 2.2.0 - Missing Authorization to Unauthenticated Privilege Escalation via callback Function — ONLYOFFICE DocsCWE-862 9.8 Critical2025-07-24
CVE-2025-6441 Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition <= 4.03.32 - Unauthenticated Login Token Generation to Authentication Bypass — WebinarIgnition – Live, Automated & Evergreen Webinars for WooCommerceCWE-862 9.8 Critical2025-07-24
CVE-2025-7640 hiWeb Export Posts <= 0.9.0.0 - Cross-Site Request Forgery to Arbitrary File Deletion — hiWeb Export PostsCWE-22 8.1 High2025-07-24
CVE-2025-5084 Post Grid Master <= 3.4.13 - Reflected Cross-Site Scripting via argsArray['read_more_text'] — Post Grid Master — Post Grids & AJAX FiltersCWE-79 6.1 Medium2025-07-24
CVE-2025-41240 Mounted Kubernetes Secrets under a predictable path located within the web server document root — bitnamicharts/appsmith 10.0 Critical2025-07-24
CVE-2025-7437 Ebook Store <= 5.8012 - Unauthenticated Arbitrary File Upload — Ebook StoreCWE-434 9.8 Critical2025-07-24
CVE-2025-7852 WPBookit <= 1.0.6 - Unauthenticated Arbitrary File Upload via image_upload_handle Function — WPBookitCWE-434 9.8 Critical2025-07-24
CVE-2016-15044 Kaltura < 11.1.0-2 PHP Object Injection RCE — Video PlatformCWE-502 9.8 -2025-07-23

Vulnerabilities classified as access:pre-auth represent 18851 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.