Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18853

18853 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-46634 Tenda RX2 Pro 安全漏洞 — n/a 5.9AIMediumAI2025-05-01
CVE-2025-2170 SonicWALL SMA1000 安全漏洞 — SMA1000CWE-918 9.8AICriticalAI2025-04-30
CVE-2025-46554 XWiki missing authorization when accessing the wiki level attachments list and metadata via REST API — xwiki-platformCWE-862 5.3 Medium2025-04-30
CVE-2025-24344 Bosch Rexroth ctrlX OS 安全漏洞 — ctrlX OS - SolutionsCWE-81 6.3 Medium2025-04-30
CVE-2025-24342 Bosch Rexroth ctrlX OS 安全漏洞 — ctrlX OS - Device AdminCWE-204 5.3 Medium2025-04-30
CVE-2025-24339 Bosch Rexroth ctrlX OS 安全漏洞 — ctrlX OS - Device AdminCWE-644 5.0 Medium2025-04-30
CVE-2025-29906 Finit bundled getty can bypass /bin/login — finitCWE-287 8.6 High2025-04-29
CVE-2025-46348 YesWiki Vulnerable to Unauthenticated Site Backup Creation and Download — yeswikiCWE-287 10.0 Critical2025-04-29
CVE-2025-46349 YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting — yeswikiCWE-79 7.6 High2025-04-29
CVE-2025-40619 Improper access control vulnerability in Bookgy — BookgyCWE-863 9.1AICriticalAI2025-04-29
CVE-2025-1551 IBM Operational Decision Manager cross-site scripting — Operational Decision ManagerCWE-79 6.1 Medium2025-04-29
CVE-2025-3891 Mod_auth_openidc: dos via empty post in mod_auth_openidc with oidcpreservepost enabled CWE-248 7.5 High2025-04-29
CVE-2025-24271 Apple iOS和Apple iPadOS 安全漏洞 — iOS and iPadOS 4.3 -2025-04-29
CVE-2024-57698 ModernWMS 安全漏洞 — n/a 7.5AIHighAI2025-04-29
CVE-2024-10635 Enterprise Protection S/MIME Opaque Signature Attachment Scanning Bypass — Enterprise ProtectionCWE-754 6.1 Medium2025-04-28
CVE-2025-3200 Com-Server Exposed via Weak TLS — Com-Server++CWE-327 9.1 Critical2025-04-28
CVE-2025-32470 Unauthenticated change of IP adress — SICK FLX0-GPNT100CWE-284 7.5 High2025-04-28
CVE-2025-3706 104 Corporation eHRMS - Reflected Cross-Site Scripting — eHRMSCWE-79 6.1 Medium2025-04-28
CVE-2025-46661 IPW Systems Metazo 安全漏洞 — MetazoCWE-1336 10.0 Critical2025-04-28
CVE-2025-31144 SIOS Technology Quick Agent 安全漏洞 — Quick Agent V3CWE-923 9.8 -2025-04-27
CVE-2025-26692 SIOS Technology Quick Agent 路径遍历漏洞 — Quick Agent V3CWE-22 9.8 -2025-04-27
CVE-2025-2101 Edumall <= 4.2.4 - Unauthenticated Local File Inclusion — EduMall - Professional LMS Education Center WordPress ThemeCWE-98 8.1 High2025-04-26
CVE-2024-13812 Anps Theme plugin <= 1.1.1 - Unauthenticated Arbitrary Shortcode Execution — Anps Theme pluginCWE-94 6.5 Medium2025-04-26
CVE-2025-2105 Jupiter X Core <= 4.8.11 - Unauthenticated PHP Object Injection via PHAR — Jupiter X CoreCWE-502 8.1 High2025-04-26
CVE-2025-2801 Create custom forms for WordPress with a smart form plugin for smart businesses <= 1.2.4 - Unauthenticated Arbitrary Shortcode Execution — Create custom forms for WordPress with a smart form plugin for smart businesses – Form builder for WordPressCWE-94 7.3 High2025-04-26
CVE-2025-32044 Moodle: unauthenticated rest api user data exposure CWE-200 7.5 High2025-04-25
CVE-2024-6199 Unauthenticated Remote Code Execution — RM5110CWE-120 7.5 -2025-04-25
CVE-2025-2470 Service Finder Bookings <= 5.1 - Unauthenticated Privilege Escalation via 'nsl_registration_store_extra_input' — Service Finder BookingsCWE-266 9.8 Critical2025-04-25
CVE-2024-11917 JobSearch WP Job Board <= 2.9.2 - Authentication Bypass via Social Logins — JobSearch WP Job BoardCWE-287 8.1 High2025-04-25
CVE-2025-3912 WS Form LITE – Drag & Drop Contact Form Builder for WordPress <= 1.10.35 - Missing Authorization to Unauthenticated Sensitive Information Exposure — WS Form LITE – Drag & Drop Contact Form BuilderCWE-862 5.3 Medium2025-04-25

Vulnerabilities classified as access:pre-auth represent 18853 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.