Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18853

18853 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-34047 Leadsec VPN Path Traversal Arbitrary File Read — Leadsec SSL VPNCWE-22 7.5AIHighAI2025-06-26
CVE-2025-34048 D-Link DSL-2730U/2750U/2750E Path Traversal Arbitrary File Read — DSL-2730UCWE-22 7.5AIHighAI2025-06-26
CVE-2025-34046 Fanwei E-Office Unauthenticated File Upload — E-OfficeCWE-434 9.8AICriticalAI2025-06-26
CVE-2025-34045 WeiPHP Path Traversal Arbitrary File Read — WeiPHPCWE-22 7.5AIHighAI2025-06-26
CVE-2025-34044 WIFISKY 7-Layer Flow Control Router Remote Command Execution — WIFISKY 7-layer flow control routerCWE-78 9.8AICriticalAI2025-06-26
CVE-2025-34043 Vacron NVR Remote Command Execution — Network Video Recorder (NVR)CWE-78 9.8AICriticalAI2025-06-26
CVE-2025-6561 Hunt Electronic Hybrid DVR - Exposure of Sensitive System Information — HBF-09KDCWE-497 9.8 Critical2025-06-26
CVE-2025-6212 Ultra Addons for Contact Form 7 3.5.11 - 3.5.19 - Unauthenticated Stored Cross-Site Scripting via Database module — Ultra Addons for Contact Form 7CWE-79 7.2 High2025-06-26
CVE-2025-1754 Missing Authentication for Critical Function in GitLab — GitLabCWE-306 5.3 Medium2025-06-26
CVE-2025-5813 Amazon Products to WooCommerce <= 1.2.7 - Missing Authorization to Unauthenticated Arbitrary Product Creation — Amazon Products to WooCommerceCWE-862 5.3 Medium2025-06-26
CVE-2025-5932 Homerunner <= 1.0.30 - Cross-Site Request Forgery to Settings Update — HomerunnerCWE-352 4.3 Medium2025-06-26
CVE-2025-4334 Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation — Simple User RegistrationCWE-269 9.8 Critical2025-06-26
CVE-2025-30131 IROAD Dashcam FX2 安全漏洞 — n/a 9.8AICriticalAI2025-06-26
CVE-2025-52894 OpenBao Vulnerable to Unauthenticated Rekey Operation Cancellation — openbaoCWE-20 7.5AIHighAI2025-06-25
CVE-2025-49153 Path Traversal in MICROSENS NMP Web+ — NMP Web+CWE-22 9.8AICriticalAI2025-06-25
CVE-2025-49151 Use of Hard-coded, Security-relevant Constants in MICROSENS NMP Web+ — NMP Web+CWE-547 9.1AICriticalAI2025-06-25
CVE-2025-20282 Cisco ISE API Unauthenticated Remote Code Execution Vulnerability — Cisco Identity Services Engine SoftwareCWE-269 10.0 Critical2025-06-25
CVE-2025-5015 Parsons AccuWeather Widget Cross-site Scripting — Parsons Utility Enterprise Data ManagementCWE-79 8.8 High2025-06-25
CVE-2025-20281 Cisco ISE API Unauthenticated Remote Code Execution Vulnerability — Cisco Identity Services Engine SoftwareCWE-74 10.0 Critical2025-06-25
CVE-2021-4457 ZoomSounds < 6.05 - Unauthenticated Arbitrary File Upload — ZoomSounds 9.8AICriticalAI2025-06-25
CVE-2025-5927 Everest Forms (Pro) <= 1.9.4 - Unauthenticated Path Traversal to Arbitrary File Deletion — Everest Forms ProCWE-36 7.5 High2025-06-25
CVE-2024-51983 Unauthenticated Denial of Service (DoS) via malformed WS-Scan request affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc. — HL-L8260CDNCWE-1286 7.5 High2025-06-25
CVE-2024-51982 Unauthenticated Denial of Service (DoS) via malformed PJL request affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, and Ricoh. — HL-L8260CDNCWE-1286 7.5 High2025-06-25
CVE-2024-51981 Unauthenticated Server Side Request Forgery (SSRF) via WS-Eventing affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, Ricoh, and Toshiba Tec, and Konica Minolta, Inc. — HL-L8260CDNCWE-918 5.3 Medium2025-06-25
CVE-2024-51980 Unauthenticated Server Side Request Forgery (SSRF) via WS-Addressing affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc. — HL-L8260CDNCWE-918 5.3 Medium2025-06-25
CVE-2024-51978 Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc. — DCP-J928N-W/BCWE-1391 9.8 Critical2025-06-25
CVE-2024-51977 Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc. — HL-L8260CDNCWE-538 5.3 Medium2025-06-25
CVE-2025-52571 Hikka vulnerable to RCE through edits in a channel — HikkaCWE-287 9.7 Critical2025-06-24
CVE-2025-49852 Server-Side Request Forgery (SSRF) in ControlID iDSecure On-premises — iDSecure On-premisesCWE-918 7.5 High2025-06-24
CVE-2025-2566 Deserialization of Untrusted Data in Kaleris Navis N4 — Navis N4CWE-502 9.8AICriticalAI2025-06-24

Vulnerabilities classified as access:pre-auth represent 18853 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.