Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18853

18853 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-6851 Broken Link Notifier <= 1.3.0 - Unauthenticated Server-Side Request Forgery — Broken Link NotifierCWE-918 7.2 High2025-07-11
CVE-2025-7442 WPGYM - Wordpress Gym Management System < 67.8.0 - Unauthenticated SQL Injection — WPGYM - Wordpress Gym Management SystemCWE-89 7.5 High2025-07-11
CVE-2025-6745 WoodMart <= 8.2.5 - Unauthenticated Post Disclosure — WoodmartCWE-200 5.3 Medium2025-07-11
CVE-2025-5392 GB Forms DB <= 1.0.2 - Unauthenticated Remote Code Execution — GB Forms DBCWE-94 9.8 Critical2025-07-11
CVE-2025-2942 Order Delivery Date Pro for WooCommerce < 12.6.0 - Unauthenticated Arbitrary Post Title Disclosure — Order Delivery Date 5.3AIMediumAI2025-07-11
CVE-2025-7401 Premium Age Verification / Restriction for WordPress <= 3.0.2 - Unauthenticated Arbitrary File Read and Write via remote_tunnel.php — Premium Age Verification / Restriction for WordPressCWE-798 9.8 Critical2025-07-11
CVE-2025-5241 Denial-of-Service Vulnerability in MELSEC iQ-F Series — MELSEC iQ-F Series FX5U-32MT/ESCWE-645 5.3 Medium2025-07-11
CVE-2023-38327 EGroupware 安全漏洞 — n/a 5.3AIMediumAI2025-07-11
CVE-2023-38329 EGroupware 安全漏洞 — n/a 6.1AIMediumAI2025-07-11
CVE-2025-34100 BuilderEngine 3.5.0 RCE via Unauthenticated Arbitrary File Upload — CMSCWE-434 9.8AICriticalAI2025-07-10
CVE-2025-34102 CryptoLog Unauthenticated RCE via SQL Injection and Command Injection — CryptoLogCWE-89 9.8AICriticalAI2025-07-10
CVE-2025-34096 Easy File Sharing HTTP Server 7.2 Buffer Overflow via POST to /sendemail.ghp — Easy File Sharing HTTP ServerCWE-119 9.8AICriticalAI2025-07-10
CVE-2025-34095 Mako Server v2.5 and v2.6 OS Command Injection via examples/save.lsp — Mako ServerCWE-78 9.8AICriticalAI2025-07-10
CVE-2025-34093 Polycom HDX Series Telnet Command Injection via lan traceroute — HDX SeriesCWE-78 8.8AIHighAI2025-07-10
CVE-2025-34101 Serviio Media Server Unauthenticated Command Injection via checkStreamUrl VIDEO Parameter — Media ServerCWE-78 9.8AICriticalAI2025-07-10
CVE-2025-34099 VICIdial vicidial_sales_viewer.php Unauthenticated Command Injection via Basic Auth Password — VICIdialCWE-78 9.8AICriticalAI2025-07-10
CVE-2025-53378 Trend Micro Worry-Free Business Security Services 访问控制错误漏洞 — Trend Micro Worry-Free Business Security ServicesCWE-306 7.6 High2025-07-10
CVE-2025-53709 Access control issues impacting secure-upload service — com.palantir.secupload:secure-uploadCWE-285 5.4 Medium2025-07-10
CVE-2025-49463 Zoom Clients for iOS - Insufficient Control Flow Management — Zoom Clients for iOSCWE-691 6.5 Medium2025-07-10
CVE-2025-5807 Gwolle Guestbook <= 4.9.2 - Unauthenticated Stored Cross-Site Scripting via `gwolle_gb_content` Parameter — Gwolle GuestbookCWE-79 6.1 Medium2025-07-10
CVE-2025-6970 Events Manager <= 7.0.3 - Unauthenticated SQL Injection via `orderby` Parameter — Events Manager – Calendar, Bookings, Tickets, and more!CWE-89 7.5 High2025-07-09
CVE-2025-6975 Event Manager <= 7.0.3 - Reflected Cross-Site Scripting via `calendar_header` Parameter — Events Manager – Calendar, Bookings, Tickets, and more!CWE-79 6.1 Medium2025-07-09
CVE-2025-3499 Unauthenticated execution of arbitrary commands in Radiflow iSAP Smart Collector — iSAP Smart CollectorCWE-78 10.0 Critical2025-07-09
CVE-2025-3498 Unauthenticated modification of Radiflow iSAP Smart Collector configuration — iSAP Smart CollectorCWE-306 9.9 Critical2025-07-09
CVE-2025-6691 SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission Deletion — SureForms – Drag and Drop Form Builder for WordPressCWE-73 8.1 High2025-07-09
CVE-2025-6742 SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission Deletion — SureForms – Drag and Drop Form Builder for WordPressCWE-502 7.5 High2025-07-09
CVE-2025-4606 Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover — Sala - Startup & SaaS WordPress ThemeCWE-620 9.8 Critical2025-07-09
CVE-2025-34077 WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE — WordPress Pie Register PluginCWE-434 9.8AICriticalAI2025-07-09
CVE-2025-44177 White Star Software Protop 安全漏洞 — n/a 7.5AIHighAI2025-07-09
CVE-2025-52364 Tenda CP3 Pro 安全漏洞 — n/a 9.1AICriticalAI2025-07-09

Vulnerabilities classified as access:pre-auth represent 18853 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.