Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18853

18853 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-52376 Nexxt Solutions NCM-X1800 安全漏洞 — n/a 9.8 -2025-07-15
CVE-2025-53890 pyLoad vulnerable to remote code execution through js2py onCaptchaResult — pyloadCWE-94 9.8 Critical2025-07-14
CVE-2025-53889 Directus missing permission checks for manual trigger Flows — directusCWE-287 6.5 Medium2025-07-14
CVE-2025-53887 Directus's exact version number is exposed by the OpenAPI Spec — directusCWE-200 5.3 Medium2025-07-14
CVE-2025-53825 Dokploy's Preview Deployments are vulnerable to Remote Code Execution — dokployCWE-862 9.4 Critical2025-07-14
CVE-2024-26293 Unauthenticated Path Traversal affecting Avid NEXIS — Avid NEXIS E-seriesCWE-1395 9.8AICriticalAI2025-07-14
CVE-2024-26291 Authenticated Arbitrary File Read affecting Avid NEXIS — Avid NEXIS E-seriesCWE-285 6.2AIMediumAI2025-07-14
CVE-2025-7451 Hgiga|iSherlock - OS Command Injection — iSherlock-maillog-4.5CWE-78 9.8 Critical2025-07-14
CVE-2024-41169 Apache Zeppelin: raft directory listing and file read — Apache ZeppelinCWE-664 7.5AIHighAI2025-07-12
CVE-2020-36848 Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download — Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGridCWE-200 7.5 High2025-07-12
CVE-2021-4458 Modern Events Calendar Lite <= 6.3.0 - Unauthenticated SQL Injection — Modern Events Calendar LiteCWE-89 5.9 Medium2025-07-12
CVE-2020-36847 Simple File List < 4.2.3 - Remote Code Execution — Simple File ListCWE-434 9.8 Critical2025-07-12
CVE-2025-6058 WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload — WPBookitCWE-434 9.8 Critical2025-07-12
CVE-2023-38036 Ivanti Avalanche Manager 安全漏洞 — Avalanche 9.8AICriticalAI2025-07-12
CVE-2025-6549 Junos OS: SRX Series: J-Web can be exposed on additional interfaces — Junos OSCWE-863 6.5 Medium2025-07-11
CVE-2025-52985 Junos OS Evolved: When a control-plane firewall filter refers to a prefix-list with more than 10 entries it's not matching — Junos OS EvolvedCWE-480 5.3 Medium2025-07-11
CVE-2025-52984 Junos OS and Junos OS Evolved: When a static route points to a reject next-hop and a gNMI query for this route is processed, RPD crashes — Junos OSCWE-476 5.9 Medium2025-07-11
CVE-2025-52983 Junos OS: After removing ssh public key authentication root can still log in — Junos OSCWE-446 7.2 High2025-07-11
CVE-2025-52982 Junos OS: MX Series: When specific SIP packets are processed the MS-MPC will crash — Junos OSCWE-404 5.9 Medium2025-07-11
CVE-2025-52981 Junos OS: SRX Series: Sequence of specific PIM packets causes a flowd crash — Junos OSCWE-754 7.5 High2025-07-11
CVE-2025-52980 Junos OS: SRX300 Series: rpd will crash upon receiving a specific, valid BGP UPDATE message — Junos OSCWE-198 7.5 High2025-07-11
CVE-2025-52964 Junos OS and Junos OS Evolved: Receipt of a specific BGP UPDATE causes an rpd crash on devices with BGP multipath configured — Junos OSCWE-617 6.5 Medium2025-07-11
CVE-2025-52953 Junos OS and Junos OS Evolved: An unauthenticated adjacent attacker sending a valid BGP UPDATE packet forces a BGP session reset — Junos OSCWE-440 6.5 Medium2025-07-11
CVE-2025-52952 Junos OS: MX Series with MPC-BUILTIN, MPC 1 through MPC 9: Receipt and processing of a malformed packet causes one or more FPCs to crash — Junos OSCWE-787 6.5 Medium2025-07-11
CVE-2025-52958 Junos OS and Junos OS Evolved: When route validation is enabled, BGP connection establishment failure causes RPD crash — Junos OSCWE-617 5.3 Medium2025-07-11
CVE-2025-52955 Junos OS and Junos OS Evolved: When jflow/sflow is configured continuous logical interface flaps causes rpd crash and restart — Junos OSCWE-131 6.5 Medium2025-07-11
CVE-2025-52950 Juniper Security Director: Insufficient authorization for multiple endpoints in web interface — Juniper Security DirectorCWE-862 9.6 Critical2025-07-11
CVE-2025-53862 Aap: aap-gateway: automation-hub: sensitive information disclosure — Red Hat Ansible Automation Platform 2CWE-497 3.5 Low2025-07-11
CVE-2025-50125 Schneider Electric EcoStruxure IT Data Center Expert 代码问题漏洞 — EcoStruxure™ IT Data Center ExpertCWE-918 9.8AICriticalAI2025-07-11
CVE-2025-50121 Schneider Electric EcoStruxure IT Data Center Expert 操作系统命令注入漏洞 — EcoStruxure™ IT Data Center ExpertCWE-78 9.8AICriticalAI2025-07-11

Vulnerabilities classified as access:pre-auth represent 18853 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.