Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18851

18851 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-52575 EspoCRM vulnerable to LDAP Injection through Improper Neutralization of Special Elements — espocrmCWE-90 6.5 Medium2025-07-21
CVE-2025-54082 nova-tiptap has an Unauthenticated Arbitrary File Upload Vulnerability — nova-tiptapCWE-434 8.6 -2025-07-21
CVE-2025-7382 Sophos Firewall 安全漏洞 — Sophos FirewallCWE-78 8.8 High2025-07-21
CVE-2025-6704 Sophos Firewall 安全漏洞 — Sophos FirewallCWE-78 9.8 Critical2025-07-21
CVE-2025-41679 Unauthenticated Buffer Overflow in Conftool Service Leading to Denial of Service — mbNET.miniCWE-787 5.3 Medium2025-07-21
CVE-2025-7369 Shortcodes Ultimate <= 7.4.2 - Cross-Site Request Forgery to Arbitrary Shortcode Execution — WP Shortcodes Plugin — Shortcodes UltimateCWE-352 6.1 Medium2025-07-21
CVE-2025-7920 Simopro Technology|WinMatrix3 Web package - Reflected Cross-Site Scripting — WinMatrix3 Web packageCWE-79 6.1 Medium2025-07-21
CVE-2025-7343 Digiwin|SFT - SQL Injection — SFTCWE-89 9.8 Critical2025-07-21
CVE-2025-7921 ASKEY|modem - Stack-based Buffer Overflow — RTF8207wCWE-121 9.8 Critical2025-07-21
CVE-2025-7919 Simopro Technology|WinMatrix3 Web package - SQL Injection — WinMatrix3 Web packageCWE-200 6.5 Medium2025-07-21
CVE-2025-7918 Simopro Technology|WinMatrix3 Web package - SQL Injection — WinMatrix3 Web packageCWE-89 9.8 Critical2025-07-21
CVE-2025-7916 Simopro Technology|WinMatrix3 - Insecure Deserialization — WinMatrix3CWE-502 9.8 Critical2025-07-21
CVE-2025-36846 Eveo URVE Web Manager 安全漏洞 — n/a 9.8 -2025-07-21
CVE-2025-46120 CommScope Ruckus Unleashed和CommScope Ruckus ZoneDirector 安全漏洞 — n/a 9.8 -2025-07-21
CVE-2025-46121 CommScope Ruckus Unleashed 安全漏洞 — n/a 7.4 -2025-07-21
CVE-2025-52362 phproxy 安全漏洞 — n/a 9.1 -2025-07-21
CVE-2020-26799 LuxSoft Luxcal 安全漏洞 — n/a 6.1 -2025-07-21
CVE-2025-7858 PHPGurukul Apartment Visitors Management System HTTP POST Request admin-profile.php cross site scripting — Apartment Visitors Management SystemCWE-79 3.5 Low2025-07-19
CVE-2015-10138 Work The Flow File Upload <= 2.5.2 - Arbitrary File Upload — Work The Flow File UploadCWE-434 9.8 Critical2025-07-19
CVE-2012-10019 Front-end Editor < 2.3 - Arbitrary File Upload — Front-end EditorCWE-434 9.8 Critical2025-07-19
CVE-2015-10135 WPshop 2 – E-Commerce < 1.3.9.6 - Arbitrary File Upload — WPshop 2 – E-CommerceCWE-434 9.8 Critical2025-07-19
CVE-2015-10136 GI-Media Library < 3.0 - Directory Traversal — GI-Media LibraryCWE-22 7.5 High2025-07-19
CVE-2016-15043 WP Mobile Detector <= 3.5 - Arbitrary File Upload — WP Mobile DetectorCWE-434 9.8 Critical2025-07-19
CVE-2025-6720 Vchasno Kasa <= 1.0.3 - Unauthenticated Log File Clearing — MORKVA Vchasno Kasa IntegrationCWE-862 5.3 Medium2025-07-19
CVE-2025-6721 Vchasno Kasa <= 1.0.3 - Missing Authorization to Unauthenticated Invoice Generation — MORKVA Vchasno Kasa IntegrationCWE-862 5.3 Medium2025-07-19
CVE-2025-7697 Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 - Unauthenticated PHP Object Injection via verify_field_val Function — Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja FormsCWE-502 9.8 Critical2025-07-19
CVE-2025-7696 Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.2.3 - Unauthenticated PHP Object Injection via verify_field_val Function — Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja FormsCWE-502 9.8 Critical2025-07-19
CVE-2025-7669 Avishi WP PayPal Payment Button <= 2.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Avishi WP PayPal Payment ButtonCWE-352 6.1 Medium2025-07-19
CVE-2025-50057 Extension - rsjoomla.com - DOS vulnerability RSFiles! component 1.16.3-1.17.7 for Joomla — RSFiles! component for JoomlaCWE-400 7.5 -2025-07-18
CVE-2025-7444 LoginPress Pro <= 5.0.1 - Authentication Bypass via WordPress.com OAuth provider — LoginPress ProCWE-288 9.8 Critical2025-07-18

Vulnerabilities classified as access:pre-auth represent 18851 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.