Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18854

18854 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-3912 WS Form LITE – Drag & Drop Contact Form Builder for WordPress <= 1.10.35 - Missing Authorization to Unauthenticated Sensitive Information Exposure — WS Form LITE – Drag & Drop Contact Form BuilderCWE-862 5.3 Medium2025-04-25
CVE-2025-1565 Mayosis Core <= 5.4.1 - Unauthenticated Arbitrary File Read — Mayosis CoreCWE-22 7.5 High2025-04-25
CVE-2025-3870 1 Decembrie 1918 <= 1.dec.2012 - Cross-Site Request Forgery to Stored Cross-Site Scripting — 1 Decembrie 1918CWE-79 6.1 Medium2025-04-25
CVE-2025-3743 Upsell Funnel Builder for WooCommerce <= 3.0.0 - Unauthenticated Order Manipulation — Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups.CWE-472 5.3 Medium2025-04-25
CVE-2025-3867 Ajax Comment Form CST <= 1.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Ajax Comment Form CSTCWE-79 6.1 Medium2025-04-25
CVE-2025-3868 Custom Admin-Bar Favorites <= 0.1 - Reflected Cross-Site Scripting — Custom Admin-Bar FavoritesCWE-79 6.1 Medium2025-04-25
CVE-2025-3866 Add Google +1 (Plus one) social share Button <= 1.0.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Add Google +1 (Plus one) social share ButtonCWE-79 6.1 Medium2025-04-25
CVE-2025-3923 Prevent Direct Access – Protect WordPress Files <= 2.8.8 - Unauthenticated Sensitive Information Exposure — Prevent Direct Access – Protect WordPress FilesCWE-200 5.3 Medium2025-04-25
CVE-2025-3511 Mitsubishi Electric多款产品 安全漏洞 — CC-Link IE TSN Remote I/O module NZ2GN2S1-32DCWE-1284 7.5 High2025-04-25
CVE-2025-3775 ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter — ShopLentor – All-in-One WooCommerce Growth & Store Enhancement PluginCWE-918 6.5 Medium2025-04-25
CVE-2025-46599 k3s 安全漏洞 — K3sCWE-1188 6.8 Medium2025-04-25
CVE-2025-46274 Planet Technology Network Products Use of Hard-coded Credentials — UNI-NMS-LiteCWE-798 9.8 Critical2025-04-24
CVE-2025-46273 Planet Technology Network Products Use of Hard-coded Credentials — UNI-NMS-LiteCWE-798 9.8 Critical2025-04-24
CVE-2025-46272 Planet Technology Network Products OS Command Injection — WGS-804HPT-V2CWE-78 9.1 Critical2025-04-24
CVE-2025-46271 Planet Technology Network Products OS Command Injection — UNI-NMS-LiteCWE-78 9.1 Critical2025-04-24
CVE-2025-1294 eForm <= 4.18.0 - Unauthenticated Stored Cross-Site Scripting — eForm - WordPress Form BuilderCWE-79 7.2 High2025-04-24
CVE-2025-31324 Missing Authorization check in SAP NetWeaver (Visual Composer development server) — SAP NetWeaver (Visual Composer development server)CWE-434 10.0 Critical2025-04-24
CVE-2025-43855 tRPC 11 WebSocket DoS Vulnerability — trpcCWE-248 7.5 -2025-04-24
CVE-2021-47664 Enumeration of valid user names — Franka Emika RobotCWE-203 5.3 Medium2025-04-24
CVE-2021-47663 Improper session handling — Franka Emika RobotCWE-613 8.1 High2025-04-24
CVE-2021-47662 Unauthenticated remote shutdown of the cobot — Franka Emika RobotCWE-862 7.5 High2025-04-24
CVE-2025-3603 Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Password Update — Flynax BridgeCWE-620 9.8 Critical2025-04-24
CVE-2025-3776 Verification SMS with TargetSMS <= 1.5 - Unauthenticated Limited Remote Code Execution — Verification SMS with TargetSMSCWE-94 8.3 High2025-04-24
CVE-2024-13307 Reales WP - Real Estate WordPress Theme <= 2.1.2 - Missing Authorization to Unauthenticated Attachment Deletion and Favorite Property Updates — Reales WP - Real Estate WordPress ThemeCWE-862 5.3 Medium2025-04-24
CVE-2025-3604 Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover — Flynax BridgeCWE-862 9.8 Critical2025-04-24
CVE-2025-3065 Database Toolset <= 1.8.4 - Unauthenticated Arbitrary File Deletion — Database ToolsetCWE-22 9.1 Critical2025-04-24
CVE-2025-2558 The Wound <= 0.0.1 - Unauthenticated LFI — the-wound 7.5 -2025-04-24
CVE-2025-32818 SonicWALL SonicOS SSLVPN 代码问题漏洞 — SonicOSCWE-476 7.5 -2025-04-23
CVE-2025-21605 Redis DoS Vulnerability due to unlimited growth of output buffers abused by unauthenticated client — redisCWE-770 7.5 High2025-04-23
CVE-2025-32969 org.xwiki.platform:xwiki-platform-rest-server allows SQL injection in query endpoint of REST API — xwiki-platformCWE-89 9.8 -2025-04-23

Vulnerabilities classified as access:pre-auth represent 18854 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.