Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18851

18851 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-40598 SonicWall SMA 100 Series 跨站脚本漏洞 — SMA 100 SeriesCWE-79 6.1 -2025-07-23
CVE-2025-40597 SonicWall SMA 100 Series 安全漏洞 — SMA 100 SeriesCWE-122 9.8 -2025-07-23
CVE-2025-40596 SonicWall SMA 100 Series 安全漏洞 — SMA 100 SeriesCWE-121 9.8 -2025-07-23
CVE-2025-36116 IBM Db2 Mirror for i cross-site websocket hijacking — Db2 Mirror for iCWE-1385 6.3 Medium2025-07-23
CVE-2010-10012 httpdASM 0.92 Path Traversal — httpdasmCWE-22 7.5 -2025-07-23
CVE-2015-10141 Xdebug Remote Debugger Unauthenticated OS Command Execution — XdebugCWE-78 9.8 -2025-07-23
CVE-2017-20198 DC/OS Marathon UI < 1.9.0 Unauthenticated RCE via Docker Mount Abuse — DC/OS MarathonCWE-732 9.8 -2025-07-23
CVE-2018-25113 Dicoogle PACS Web Server 2.5.0 Unauthenticated Path Traversal — PACS Web ServerCWE-22 7.5 -2025-07-23
CVE-2018-25114 osCommerce 2.3.4.1 Installer Unauthenticated Configuration File Injection PHP Code Execution — Online MerchantCWE-434 9.8 -2025-07-23
CVE-2022-4978 Steppschuh Remote Control Server 3.1.1.12 Unauthenticated RCE — Remote Control Collection ServerCWE-306 8.8 -2025-07-23
CVE-2025-41687 Weidmueller: Unauthenticated Stack-Based Buffer Overflow in u-link Management API — IE-SR-2TX-WLCWE-121 9.8 Critical2025-07-23
CVE-2025-6214 Omnishop <= 1.0.9 - Cross-Site Request Forgery to Arbitrary User Deletion via /users/delete REST Endpoint — Omnishop – Mobile shop apps complementing your WooCommerce webshopCWE-352 6.5 Medium2025-07-23
CVE-2025-6054 YANewsflash <= 1.0.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting — YANewsflashCWE-352 6.1 Medium2025-07-23
CVE-2025-6215 Omnishop <= 1.0.9 - Missing Registration Restriction to Unauthenticated Account Creation via /users/register REST Endpoint — Omnishop – Mobile shop apps complementing your WooCommerce webshopCWE-862 5.3 Medium2025-07-23
CVE-2025-47187 Mitel 6800 Series、Mitel 6900 Series和Mitel 6900w Series 安全漏洞 — n/a 7.5 -2025-07-23
CVE-2025-54139 HAX CMS' application pages are vulnerable to clickjacking — issuesCWE-1021 4.3 Medium2025-07-22
CVE-2025-7766 Lantronix Provisioning Manager Improper Restriction of XML External Entity Reference — Provisioning ManagerCWE-611 8.0 High2025-07-22
CVE-2025-54137 NodeJS version of the HAX CMS application is distributed with Default Secrets — issuesCWE-1392 7.3 High2025-07-22
CVE-2025-7724 Unauthenticated command injection on VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2 — VIGI NVR1104H-4P V1CWE-78 9.8 -2025-07-22
CVE-2025-6523 Devolutions Server 安全漏洞 — ServerCWE-1391 9.1 -2025-07-22
CVE-2025-34140 ETQ Reliance CG/NXG API Authorization Bypass via ;localized-text URI Suffix — Reliance CG (legacy)CWE-639 5.3 -2025-07-22
CVE-2025-6187 bSecure 1.3.7 - 1.7.9 - Missing Authorization to Unauthenticated Privilege Escalation via order_info REST Endpoint — bSecure – Your Universal CheckoutCWE-862 9.8 Critical2025-07-22
CVE-2025-7685 Like & Share My Site <= 0.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Like & Share My SiteCWE-352 6.1 Medium2025-07-22
CVE-2025-6082 Birth Chart Compatibility <= 2.0 - Unauthenticated Full Path Exposure — Birth Chart CompatibilityCWE-200 5.3 Medium2025-07-22
CVE-2025-7692 Orion Login with SMS <= 1.0.5 - Authentication Bypass via Weak OTP — Orion Login with SMSCWE-288 8.1 High2025-07-22
CVE-2025-7687 Latest Post Accordian Slider <= 1.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Latest Post Accordian SliderCWE-352 6.1 Medium2025-07-22
CVE-2025-7645 Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) <= 3.2.8 - Unauthenticated Arbitrary File Deletion Triggered via Admin Form Submission Deletion — Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection)CWE-22 8.1 High2025-07-22
CVE-2012-10020 FoxyPress <= 0.4.2.1 - Arbitrary File Upload — FoxyPressCWE-434 9.8 Critical2025-07-22
CVE-2015-10137 Website Contact Form With File Upload <= 1.3.4 - Arbitrary File Upload — Website Contact Form With File UploadCWE-434 9.8 Critical2025-07-22
CVE-2025-54122 Manager-io/Manager allows unauthenticated full read server-side request forgery in "proxy" endpoint — ManagerCWE-918 10.0 Critical2025-07-21

Vulnerabilities classified as access:pre-auth represent 18851 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.