Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18853

18853 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-1909 BuddyBoss Platform Pro <= 2.7.01 - Authentication Bypass via Apple OAuth provider — BuddyBoss Platform ProCWE-288 9.8 Critical2025-05-05
CVE-2024-11615 Envolve Plugin <= 1.0 - Unauthenticated Language File Deletion — Envolve PluginCWE-22 5.3 Medium2025-05-05
CVE-2025-2905 An XML External Entity (XXE) vulnerability in Multiple WSO2 Products — WSO2 API ManagerCWE-611 9.1 Critical2025-05-05
CVE-2025-25504 Gefen WebFWC 安全漏洞 — n/a 9.8AICriticalAI2025-05-05
CVE-2024-41753 IBM Cloud Pak for Business Automation cross-site scripting — Cloud Pak for Business AutomationCWE-79 6.1 Medium2025-05-03
CVE-2024-13738 Motors - Car Dealer, Rental & Listing WordPress theme <= 5.6.65 - Unauthenticated Arbitrary Shortcode Execution — Motors - Car Dealer, Rental & Listing WordPress themeCWE-94 7.3 High2025-05-03
CVE-2025-4222 Database Toolset <= 1.8.4 - Unauthenticated Sensitive Information Exposure via Backup Files — Database ToolsetCWE-200 5.9 Medium2025-05-03
CVE-2025-3918 Job Listings 0.1 - 0.1.1 - Unauthenticated Privilege Escalation via register_action Function — Job ListingsCWE-285 9.8 Critical2025-05-03
CVE-2025-4198 Alink Tap <= 1.3.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Alink TapCWE-352 6.1 Medium2025-05-03
CVE-2025-4199 Abundatrade Plugin <= 1.8.02 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Abundatrade PluginCWE-352 6.1 Medium2025-05-03
CVE-2025-4188 Advanced Reorder Image Text Slider <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Advanced Reorder Image Text SliderCWE-352 6.1 Medium2025-05-03
CVE-2025-4204 Ultimate Auction Pro <= 1.5.2 - Unauthenticated SQL Injection via 'auction_id' — Ultimate Auction ProCWE-89 7.5 High2025-05-02
CVE-2025-3438 MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege Escalation — MStore API – Create Native Android & iOS Apps On The CloudCWE-269 6.5 Medium2025-05-02
CVE-2024-13322 Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.88 - Unauthenticated SQL Injection — Ads Pro Plugin - Multi-Purpose WordPress Advertising ManagerCWE-89 7.5 High2025-05-02
CVE-2024-13344 Advance Seat Reservation Management for WooCommerce <= 3.3 - Unauthenticated SQL Injection — Advance Seat Reservation Management for WooCommerceCWE-89 7.5 High2025-05-02
CVE-2025-3709 Flowring Technology Agentflow - Account Lockout Bypass — AgentflowCWE-307 9.8 Critical2025-05-02
CVE-2025-3708 Le-show Medical Practice Management System - SQL Injection — Le-showCWE-89 9.8 Critical2025-05-02
CVE-2025-4177 Flynax Bridge <= 2.2.0 - Unauthenticated Arbitrary User Deletion — Flynax BridgeCWE-862 5.3 Medium2025-05-02
CVE-2025-4179 Flynax Bridge <= 2.2.0 - Unauthenticated Limited Privilege Escalation — Flynax BridgeCWE-862 7.3 High2025-05-02
CVE-2025-2880 Yame | Link In Bio <= 0.9.0 - Unauthenticated Information Exposure — Yame | Link In BioCWE-200 5.3 Medium2025-05-02
CVE-2025-3746 OTP-less one tap Sign in 2.0.14 - 2.0.59 - Unauthenticated Arbitrary Email Update to Account Takeover/Privilege Escalation — OTP-less one tap Sign inCWE-862 9.8 Critical2025-05-02
CVE-2025-24522 KUNBUS Revolution Pi Authentication Bypass by Primary Weakness — Revolution Pi OS BookwormCWE-305 10.0 Critical2025-05-01
CVE-2025-3874 WordPress Simple PayPal Shopping Cart <= 5.1.3 - Insecure Direct Object Reference — Simple Shopping CartCWE-639 6.5 Medium2025-05-01
CVE-2025-3889 WordPress Simple PayPal Shopping Cart <= 5.1.3 - Insecure Direct Object Reference via 'quantity' — Simple Shopping CartCWE-639 5.3 Medium2025-05-01
CVE-2025-2168 Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 2.4.1 - Cross-Site Request Forgery to Limited User Meta Update — Ultimate Store Kit – Addon For WooCommerce, EDD and ElementorCWE-352 4.3 Medium2025-05-01
CVE-2025-1305 NewsBlogger <= 0.2.5.4 - Cross-Site Request Forgery to Arbitrary Plugin Installation — NewsBloggerCWE-352 8.8 High2025-05-01
CVE-2025-46627 Tenda RX2 Pro 安全漏洞 — n/a 9.8AICriticalAI2025-05-01
CVE-2025-46629 Tenda RX2 Pro 安全漏洞 — n/a 9.1AICriticalAI2025-05-01
CVE-2025-46630 Tenda RX2 Pro 安全漏洞 — n/a 9.1AICriticalAI2025-05-01
CVE-2025-46631 Tenda RX2 Pro 安全漏洞 — n/a 7.5AIHighAI2025-05-01

Vulnerabilities classified as access:pre-auth represent 18853 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.