Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18853

18853 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-47227 Scriptcase 安全漏洞 — ScriptCaseCWE-684 7.5 High2025-07-05
CVE-2025-53485 SecurePoll: Unauthorized access to SetTranslationHandler allows arbitrary text changes — Mediawiki - SecurePoll extensionCWE-862 5.3 -2025-07-04
CVE-2025-6056 Ergon Informatik AG Airlock IAM 安全漏洞 — Airlock IAMCWE-203 5.3 -2025-07-04
CVE-2025-6740 Contact Form 7 Database Addon <= 1.3.1 - Unauthenticated Stored Cross-Site Scripting via tmpD Parameter — Database Addon for Contact Form 7 – CFDB7CWE-79 6.1 Medium2025-07-04
CVE-2025-6782 GoZen Forms <= 1.1.5 - Unauthenticated SQL Injection via dirGZActiveForm() — GoZen FormsCWE-89 7.5 High2025-07-04
CVE-2025-5924 WP Firebase Push Notification <= 1.2.0 - Cross-Site Request Forgery to Broadcast Notification — WP Firebase Push NotificationCWE-352 4.3 Medium2025-07-04
CVE-2025-6783 GoZen Forms <= 1.1.5 - Unauthenticated SQL Injection via emdedSc() — GoZen FormsCWE-89 7.5 High2025-07-04
CVE-2025-6814 Booking X 1.0 - 1.1.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via export_now() Function — Booking X – Appointment and Reservation Availability CalendarCWE-862 7.5 High2025-07-04
CVE-2025-6041 yContributors <= 0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting — yContributorsCWE-352 6.1 Medium2025-07-04
CVE-2025-6238 AI Engine 2.8.4 - Insecure OAuth Implementation — AI EngineCWE-601 8.0 High2025-07-04
CVE-2025-5933 RD Contacto <= 1.4 - Cross-Site Request Forgery to Settings Update — RD ContactoCWE-352 4.3 Medium2025-07-04
CVE-2025-6786 DocCheck Login <= 1.1.5 - Unauthorized Post Access — DocCheck LoginCWE-284 5.3 Medium2025-07-04
CVE-2025-34089 Remote for Mac Unauthenticated Remote Code Execution via AppleScript Injection — Remote for MacCWE-306 8.8AIHighAI2025-07-03
CVE-2025-34082 IGEL OS Secure Terminal and Secure Shadow Remote Code Execution — OSCWE-78 9.8AICriticalAI2025-07-03
CVE-2025-34061 PHPStudy 2016-2018 Backdoor Remote Code Execution Vulnerability — PHPStudyCWE-94 9.8AICriticalAI2025-07-03
CVE-2025-49618 Plesk Obsidian 安全漏洞 — ObsidianCWE-402 5.8 Medium2025-07-03
CVE-2025-20309 Cisco Unified Communications Manager Static SSH Credentials Vulnerability — Cisco Unified Communications ManagerCWE-798 10.0 Critical2025-07-02
CVE-2025-20310 Cisco Enterprise Chat and Email Stored Cross-Site Scripting Vulnerability — Cisco Enterprise Chat and EmailCWE-79 6.1 Medium2025-07-02
CVE-2025-34073 stamparm/maltrail <=0.54 Remote Command Execution — MaltrailCWE-78 9.8AICriticalAI2025-07-02
CVE-2025-34070 GFI Kerio Control GFIAgent Missing Authentication on Administrative Interfaces — Kerio ControlCWE-306 9.8AICriticalAI2025-07-02
CVE-2025-34069 GFI Kerio Control GFIAgent Authentication Bypass via Proxy Forwarding — Kerio ControlCWE-306 9.8AICriticalAI2025-07-02
CVE-2025-34067 Hikvision Integrated Security Management Platform Remote Command Execution via applyCT Fastjson — Integrated Security Management PlatformCWE-502 9.8AICriticalAI2025-07-02
CVE-2025-34057 Ruijie NBR Router Administrative Credential Disclosure — NBR RouterCWE-306 7.5AIHighAI2025-07-02
CVE-2024-13786 Education Center | LMS & Online Courses WordPress Theme <= 3.6.10 - PHP Object Injection — Education Center | LMS & Online Courses WordPress ThemeCWE-502 9.8 Critical2025-07-02
CVE-2024-13451 Contact Form by Bit Form <= 2.17.5 - Unauthenticated Sensitive Information Exposure — Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builderCWE-200 5.3 Medium2025-07-02
CVE-2025-6464 Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion — Forminator Forms – Contact Form, Payment Form & Custom Form BuilderCWE-502 7.5 High2025-07-02
CVE-2025-6463 Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion — Forminator Forms – Contact Form, Payment Form & Custom Form BuilderCWE-73 8.8 High2025-07-02
CVE-2025-5339 Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Time-Based SQL Injection via ‘bsa_pro_id' — Ads Pro Plugin - Multi-Purpose WordPress Advertising ManagerCWE-89 7.5 High2025-07-02
CVE-2024-11405 WP Front-end login and register <= 2.1.0 - Reflected Cross-Site Scripting — WP Front-end login and registerCWE-79 6.1 Medium2025-07-02
CVE-2025-5817 Amazon Products to WooCommerce <= 1.2.7 - Unauthenticated Server-Side Request Forgery — Amazon Products to WooCommerceCWE-918 7.2 High2025-07-02

Vulnerabilities classified as access:pre-auth represent 18853 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.