Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18853

18853 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-20242 Cisco Unified Contact Center Enterprise 访问控制错误漏洞 — Cisco Unified Contact Center EnterpriseCWE-284 6.5 Medium2025-05-21
CVE-2025-20152 ISE restart — Cisco Identity Services Engine SoftwareCWE-125 8.6 High2025-05-21
CVE-2025-4008 Arbitrary Command Injection in Smartbedded MeteoBridge — MeteoBridgeCWE-77 9.8AICriticalAI2025-05-21
CVE-2024-12561 Affiliate Sales in Google Analytics and other tools <= 2.0.0 - Open Redirect — Affiliate Sales in Google Analytics and other toolsCWE-601 6.1 Medium2025-05-21
CVE-2025-4524 Madara – Responsive and modern WordPress theme for manga sites <= 2.2.2 - Unauthenticated Local File Inclusion — Madara – Responsive and modern WordPress theme for manga sitesCWE-22 9.8 Critical2025-05-21
CVE-2025-4364 Exposure of Sensitive System Information to an Unauthorized Control Sphere — Fleet Management SystemCWE-497 9.1AICriticalAI2025-05-20
CVE-2025-4322 Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover — Motors - Car Dealer, Rental & Listing WordPress themeCWE-620 9.8 Critical2025-05-20
CVE-2025-26086 RSI Queue Management System 安全漏洞 — n/a 7.5AIHighAI2025-05-20
CVE-2025-31185 Apple iOS和Apple iPadOS 安全漏洞 — iOS and iPadOS 2.4AILowAI2025-05-19
CVE-2025-36560 appleple a-blog cms 代码问题漏洞 — a-blog cmsCWE-918 8.6 High2025-05-19
CVE-2025-41429 appleple a-blog cms 安全漏洞 — a-blog cmsCWE-117 4.8 Medium2025-05-19
CVE-2024-13613 Wise Chat <= 3.3.3 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — Wise ChatCWE-200 7.5 High2025-05-17
CVE-2025-4391 Echo RSS Feed Post Generator <= 5.4.8.1 - Unauthenticated Arbitrary File Upload — Echo RSS Feed Post GeneratorCWE-434 9.8 Critical2025-05-17
CVE-2025-4389 Crawlomatic Multipage Scraper Post Generator <= 2.6.8.1 - Unauthenticated Arbitrary File Upload — Crawlomatic Multipage Scraper Post GeneratorCWE-434 9.8 Critical2025-05-17
CVE-2025-4194 AlT Monitoring <= 1.0.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting — AlT MonitoringCWE-352 6.1 Medium2025-05-17
CVE-2025-4189 Audio Comments Plugin <= 1.0.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Audio Comments PluginCWE-352 6.1 Medium2025-05-17
CVE-2025-4476 Libsoup: null pointer dereference in libsoup may lead to denial of service CWE-476 4.3 Medium2025-05-16
CVE-2025-32962 Flask-AppBuilder open redirect vulnerability using HTTP host injection — Flask-AppBuilderCWE-601 4.3 Medium2025-05-16
CVE-2025-2306 Improper Access Control vulnerability in LIVE CONTRACT — LIVE CONTRACTCWE-284 5.9 Medium2025-05-16
CVE-2025-2305 Local file inclusion vulnerability in LIVE CONTRACT — LIVE CONTRACTCWE-20 8.6 High2025-05-16
CVE-2025-47916 Invision Community 安全漏洞 — Invision Power BoardCWE-1336 10.0 Critical2025-05-16
CVE-2024-0852 coreActivity < 1.8.1 - Unauthenticated Stored XSS — coreActivity: Activity Logging for WordPress 6.1AIMediumAI2025-05-15
CVE-2023-7231 illi Link Party! <= 1.0 - Unauthenticated Arbitrary Link Deletion — illi Link Party! 5.3AIMediumAI2025-05-15
CVE-2023-7228 illi Link Party! <= 1.0 - Unauthenticated Stored XSS — illi Link Party! 6.1AIMediumAI2025-05-15
CVE-2023-6030 LogDash Activity Log < 1.1.4 - Unauthenticated SQLi — LogDash Activity Log 9.8AICriticalAI2025-05-15
CVE-2025-1303 Plugin Oficial – Getnet para WooCommerce <= 1.7.3 - Unauthenticated Reflected XSS — Plugin Oficial 6.1AIMediumAI2025-05-15
CVE-2025-0688 Spiritual Gifts Survey <= 0.9.10 - Unauthenticated CSRF to XSS — Spiritual Gifts Survey (and optional S.H.A.P.E survey) 6.1AIMediumAI2025-05-15
CVE-2025-1288 wooexim <= 5.0.0 - CSRF to Reflected XSS — WOOEXIM 6.1AIMediumAI2025-05-15
CVE-2025-0687 Spiritual Gifts Survey <= 0.9.10 - Unauthenticated CSRF to XSS — Spiritual Gifts Survey (and optional S.H.A.P.E survey) 6.1AIMediumAI2025-05-15
CVE-2024-8703 Z-Downloads < 1.11.6 - Unauthenticated Stored XSS — Z-Downloads 6.1AIMediumAI2025-05-15

Vulnerabilities classified as access:pre-auth represent 18853 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.