Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18853

18853 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-8700 Event Calendar <= 1.0.4 - Unauthenticated Arbitrary Calendar Deletion — Event Calendar 7.5AIHighAI2025-05-15
CVE-2024-7762 Simple Job Board < 2.12.6 - Unauthenticated Resumes Download — Simple Job Board 5.3AIMediumAI2025-05-15
CVE-2024-6809 Simple Video Directory < 1.4.3 - Unauthenticated SQLi — Simple Video Directory 9.8AICriticalAI2025-05-15
CVE-2024-6159 Push Notification for Post and BuddyPress <=1.93 - Multiple Unauthenticated SQLi — Push Notification for Post and BuddyPress 9.8AICriticalAI2025-05-15
CVE-2024-13823 360 Product Rotation <= 1.5.8 - Reflected XSS — 360 Product Rotation 6.1AIMediumAI2025-05-15
CVE-2024-13865 drm-protected-video-streaming <= 4.2.1 - Reflected XSS — S3Player 6.1AIMediumAI2025-05-15
CVE-2024-13727 MemberSpace – Membership Plugin and Paid Subscriptions < 2.1.14 - Reflected XSS — MemberSpace 6.1AIMediumAI2025-05-15
CVE-2024-10504 ARForms Builder < 1.7.1 - Unauthenticated Stored XSS — Contact Form, Survey, Quiz & Popup Form Builder 6.1AIMediumAI2025-05-15
CVE-2024-10098 ApplyOnline – Application Form Builder and Manager < 2.6.3 - Unauthenticated Application File Access — ApplyOnline 7.5AIHighAI2025-05-15
CVE-2024-10075 Jetpack < 13.8 - Unauthenticated Arbitrary Block & Shortcode Execution — Jetpack 5.3AIMediumAI2025-05-15
CVE-2025-30476 Dell PowerScale InsightIQ 资源管理错误漏洞 — PowerScale InsightIQCWE-400 5.3 Medium2025-05-15
CVE-2025-30475 Dell PowerScale InsightIQ 安全漏洞 — PowerScale InsightIQCWE-269 8.1 High2025-05-15
CVE-2025-4762 Insecure Direct Object Reference (IDOR) vulnerability in eSignaViewer — eSignaCWE-20 7.5AIHighAI2025-05-15
CVE-2025-4564 TicketBAI Facturas para WooCommerce <= 3.18 - Unauthenticated Arbitrary File Deletion — TicketBAI Facturas para WooCommerceCWE-22 9.8 Critical2025-05-15
CVE-2025-32738 I-O Data HDL-T 访问控制错误漏洞 — HDL-TC1CWE-306 5.3 Medium2025-05-15
CVE-2025-32002 I-O Data HDL-T 操作系统命令注入漏洞 — HDL-TC1CWE-78 9.8 Critical2025-05-15
CVE-2025-3917 百度站长SEO合集(支持百度/神马/Bing/头条推送) <= 2.0.6 - Unauthenticated Arbitrary File Upload — SEO合集(支持百度/Google/Bing/头条推送)CWE-434 9.8 Critical2025-05-15
CVE-2025-4579 WP Content Security Plugin <= 2.3 - Unauthenticated Stored Cross-Site Scripting via CSP-Report Fields — WP Content Security PluginCWE-79 7.2 High2025-05-15
CVE-2025-47889 Jenkins plugin WSO2 Oauth 安全漏洞 — Jenkins WSO2 Oauth Plugin 9.8AICriticalAI2025-05-14
CVE-2025-0132 Cortex XDR Broker VM: Unauthenticated User Can Disable Internal Services — Cortex XDR Broker VMCWE-306 5.3AIMediumAI2025-05-14
CVE-2025-0130 PAN-OS: Firewall Denial-of-Service (DoS) in the Web-Proxy Feature via a Burst of Maliciously Crafted Packets — Cloud NGFWCWE-754 7.5AIHighAI2025-05-14
CVE-2025-40595 SonicWALL SMA1000 安全漏洞 — SMA1000CWE-918 9.1AICriticalAI2025-05-14
CVE-2025-47781 Rallly Insufficient Password Login Token Entropy Leads to Account Takeover — ralllyCWE-331 9.8 Critical2025-05-14
CVE-2025-3769 Latepoint <= 5.1.92 - Unauthenticated Insecure Direct Object Reference — LatePoint – Calendar Booking Plugin for Appointments and EventsCWE-639 5.3 Medium2025-05-14
CVE-2025-47292 Cap Collectif vulnerable to insecure deserialization leading to remote code execution — cap-collectifCWE-502 9.8AICriticalAI2025-05-14
CVE-2025-2875 Schneider Electric多款产品 安全漏洞 — Modicon Controllers M241 / M251CWE-610 7.5 High2025-05-14
CVE-2024-8988 PeepSo Core: File Uploads <= 6.4.6.0 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via file_download — PeepSo Core: File UploadsCWE-639 5.3 Medium2025-05-14
CVE-2025-3623 Uncanny Automator <= 6.4.0.1 - Unauthenticated PHP Object Injection in automator_api_decode_message Function — Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder PluginCWE-502 9.1 Critical2025-05-14
CVE-2025-22892 Intel OpenVINO model server 资源管理错误漏洞 — OpenVINO™ model server software maintained by Intel(R) 6.5 Medium2025-05-13
CVE-2025-22844 Intel Tiber Edge Platform Edge Orchestrator 访问控制错误漏洞 — Edge Orchestrator software for Intel(R) Tiber™ Edge Platform 4.3 Medium2025-05-13

Vulnerabilities classified as access:pre-auth represent 18853 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.