Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18853

18853 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-2776 SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection — SysAid On-PremCWE-611 9.3 Critical2025-05-07
CVE-2025-2775 SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection — SysAid On-PremCWE-611 9.3 Critical2025-05-07
CVE-2025-4104 Frontend Dashboard 1.0 - 2.2.6 - Missing Authorization to Unauthenticated Privilege Escalation via fed_wp_ajax_fed_login_form_post Function — Frontend DashboardCWE-285 9.8 Critical2025-05-07
CVE-2025-4054 Relevanssi <= 4.24.3 (Free) and <= 2.27.4 (Premium) - Unauthenticated Stored Cross-Site Scripting via Search Highlights — Relevanssi PremiumCWE-79 6.1 Medium2025-05-07
CVE-2025-3921 PeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Missing Authorization to Limited Unauthenticated Arbitrary User Meta Update via handel_ajax_req Function — PeproDev Ultimate Profile SolutionsCWE-285 8.2 High2025-05-07
CVE-2025-3924 PeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Missing Authorization to Unauthenticated Email Enumeration — PeproDev Ultimate Profile SolutionsCWE-285 5.3 Medium2025-05-07
CVE-2025-3844 PeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Authentication Bypass to Account Takeover — PeproDev Ultimate Profile SolutionsCWE-288 9.8 Critical2025-05-07
CVE-2025-2821 Search Exclude <= 2.4.9 - Missing Authorization to Unauthenticated Plugin Settings Modification — Search ExcludeCWE-862 5.3 Medium2025-05-07
CVE-2025-29448 Easy!Appointments 安全漏洞 — n/a 7.5AIHighAI2025-05-07
CVE-2025-47423 Personal Weather Station Dashboard 安全漏洞 — Personal Weather Station DashboardCWE-24 5.8 Medium2025-05-07
CVE-2025-0856 PGS Core <= 5.8.0 - Missing Authorization via Multiple Functions — PGS CoreCWE-862 7.3 High2025-05-06
CVE-2025-0855 PGS Core <= 5.8.0 - Unauthenticated PHP Object Injection — PGS CoreCWE-502 9.8 Critical2025-05-06
CVE-2025-0853 PGS Core <= 5.8.0 - Unauthenticated SQL Injection — PGS CoreCWE-89 7.5 High2025-05-06
CVE-2025-22477 Dell Storage Manager 授权问题漏洞 — Dell Storage Center - Dell Storage ManagerCWE-287 8.3 High2025-05-06
CVE-2025-22478 Dell Storage Manager 代码问题漏洞 — Dell Storage Center - Dell Storage ManagerCWE-611 8.1 High2025-05-06
CVE-2025-22479 Dell Storage Manager 路径遍历漏洞 — Dell Storage Center - Dell Storage ManagerCWE-22 3.5 Low2025-05-06
CVE-2025-23379 Dell Storage Manager 跨站脚本漏洞 — Dell Storage Center - Dell Storage ManagerCWE-79 3.5 Low2025-05-06
CVE-2025-40625 Multiple vulnerabilities in TCMAN's GIM — GIMCWE-434 9.8AICriticalAI2025-05-06
CVE-2025-40624 Multiple vulnerabilities in TCMAN's GIM — GIMCWE-89 9.8AICriticalAI2025-05-06
CVE-2025-40623 Multiple vulnerabilities in TCMAN's GIM — GIMCWE-89 9.8AICriticalAI2025-05-06
CVE-2025-40622 Multiple vulnerabilities in TCMAN's GIM — GIMCWE-89 9.8AICriticalAI2025-05-06
CVE-2025-40621 Multiple vulnerabilities in TCMAN's GIM — GIMCWE-89 9.8AICriticalAI2025-05-06
CVE-2025-40620 Multiple vulnerabilities in TCMAN's GIM — GIMCWE-89 9.8AICriticalAI2025-05-06
CVE-2025-2011 Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter — Depicter — Popup & Slider BuilderCWE-89 7.5 High2025-05-06
CVE-2025-3281 User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.2.1 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion — User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login BuilderCWE-639 5.3 Medium2025-05-06
CVE-2025-2802 LayoutBoxx <= 0.3.1 - Unauthenticated Arbitrary Shortcode Execution — LayoutBoxxCWE-94 7.3 High2025-05-06
CVE-2025-4337 AHAthat Plugin <= 1.6 - Cross-Site Request Forgery to AHA Page Deletion — AHAthat PluginCWE-352 4.3 Medium2025-05-06
CVE-2025-3609 Reales WP STPT <= 2.1.2 - Unauthorized User Registration — Reales WP STPTCWE-863 5.3 Medium2025-05-06
CVE-2025-3610 Reales WP STPT <= 2.1.2 - Authenticated (Subscriber+) Privilege Escalation via Password Update — Reales WP STPTCWE-639 8.8 High2025-05-06
CVE-2025-46813 Private data leak on login-required Discourse sites — discourseCWE-200 5.8 Medium2025-05-05

Vulnerabilities classified as access:pre-auth represent 18853 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.