Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18853

18853 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-30018 Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit) — SAP Supplier Relationship Management (Live Auction Cockpit)CWE-611 8.6 High2025-05-13
CVE-2025-30012 Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit) — SAP Supplier Relationship Management (Live Auction Cockpit)CWE-502 10.0 Critical2025-05-13
CVE-2025-30011 Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit) — SAP Supplier Relationship Management (Live Auction Cockpit)CWE-497 5.3 Medium2025-05-13
CVE-2025-30010 Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit) — SAP Supplier Relationship Management (Live Auction Cockpit)CWE-601 6.1 Medium2025-05-13
CVE-2025-30009 Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit) — SAP Supplier Relationship Management (Live Auction Cockpit)CWE-79 6.1 Medium2025-05-13
CVE-2024-46506 NetAlertX 安全漏洞 — NetAlertXCWE-306 10.0 Critical2025-05-13
CVE-2024-48766 NetAlertX 安全漏洞 — NetAlertXCWE-698 8.6 High2025-05-13
CVE-2025-45746 ZKTeco ZKBio CVSecurity 安全漏洞 — ZKBio CVSecurityCWE-321 6.5 Medium2025-05-13
CVE-2023-49641 Billing Software v1.0 - Multiple Unauthenticated SQL Injections (SQLi) — Billing SoftwareCWE-89 9.8 Critical2025-05-12
CVE-2025-30448 Apple多款产品 安全漏洞 — iOS and iPadOS 7.5AIHighAI2025-05-12
CVE-2025-3659 Improper authentication handling for Digi PortServer TS; Digi One SP, SP IA, IA; Digi One IAP — Digi PortServer TSCWE-287 9.8AICriticalAI2025-05-12
CVE-2025-46739 Improper Restriction of Excessive Authentication Attempts — SEL Blueframe OSCWE-307 8.1 High2025-05-12
CVE-2025-3496 AUMA Riester: Buffer overflow in service telegram — AC1.2CWE-120 7.5 High2025-05-12
CVE-2025-4560 Netvision ISOinsight - Missing Authentication — ISOinsightCWE-306 6.5 Medium2025-05-12
CVE-2025-4559 Netvision ISOinsight - SQL Injection — ISOinsightCWE-89 9.8 Critical2025-05-12
CVE-2025-4558 WormHole Tech GPM - Unverified Password Change — GPMCWE-620 9.8 Critical2025-05-12
CVE-2025-4557 ZONG YU Parking Management System - Missing Authentication — Parking Management SystemCWE-306 9.1 Critical2025-05-12
CVE-2025-4556 ZONG YU Okcat Parking Management Platform - Arbitrary File Upload — Okcat Parking Management PlatformCWE-434 9.8 Critical2025-05-12
CVE-2025-4555 ZONG YU Okcat Parking Management Platform - Missing Authentication — Okcat Parking Management PlatformCWE-306 9.8 Critical2025-05-12
CVE-2025-3897 EUCookieLaw <= 2.7.2 - Unauthenticated Arbitrary File Read — EUCookieLawCWE-22 5.9 Medium2025-05-09
CVE-2025-4403 Drag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - Unauthenticated Arbitrary File Upload via upload Function — Drag and Drop Multiple File Upload for WooCommerceCWE-434 9.8 Critical2025-05-09
CVE-2024-11617 Envolve Plugin <= 1.0 - Unauthenticated Arbitrary File Upload via language_file and fonts_file — Envolve PluginCWE-434 9.8 Critical2025-05-09
CVE-2025-3605 Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover — Login, Registration and Lost Password BlocksCWE-639 9.8 Critical2025-05-09
CVE-2025-2253 IMITHEMES Listing <= 3.3 - Unauthenticated Privilege Escalation via Unverified Password Reset — IMITHEMES ListingCWE-620 9.8 Critical2025-05-09
CVE-2025-3714 ATEN LCD KVM over IP Switch CL5708IM - Stack-based Buffer Overflow — CL5708IMCWE-121 9.8 Critical2025-05-09
CVE-2025-3713 ATEN LCD KVM over IP Switch CL5708IM - Heap-based Buffer Overflow — CL5708IMCWE-122 7.5 High2025-05-09
CVE-2025-3712 ATEN LCD KVM over IP Switch CL5708IM - Heap-based Buffer Overflow — CL5708IMCWE-122 7.5 High2025-05-09
CVE-2025-3711 ATEN LCD KVM over IP Switch CL5708IM - Stack-based Buffer Overflow — CL5708IMCWE-121 9.8 Critical2025-05-09
CVE-2025-3710 ATEN LCD KVM over IP Switch CL5708IM - Stack-based Buffer Overflow — CL5708IMCWE-121 9.8 Critical2025-05-09
CVE-2025-3810 WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Account Takeover — WPBookitCWE-639 9.8 Critical2025-05-09

Vulnerabilities classified as access:pre-auth represent 18853 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.