Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18854

18854 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-42599 QUALITIA Active! mail 安全漏洞 — Active! mail 6CWE-121 9.8 -2025-04-18
CVE-2025-28232 JMBroadcast JMB0150 Firmware 安全漏洞 — n/a 9.8 -2025-04-18
CVE-2024-42178 HCL MyXalytics is affected by a failure to restrict URL access vulnerability — HCL MyXalyticsCWE-288 2.5 Low2025-04-17
CVE-2025-26478 Dell ECS 信任管理问题漏洞 — ECSCWE-295 3.1 Low2025-04-17
CVE-2025-3479 Forminator <= 1.42.0 - Order Replay Vulnerability — Forminator Forms – Contact Form, Payment Form & Custom Form BuilderCWE-354 5.3 Medium2025-04-17
CVE-2025-3453 Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products <= 2.7.7 - Unauthenticated Sensitive Information Exposure — Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial ContentCWE-863 5.3 Medium2025-04-17
CVE-2025-29931 Siemens TeleControl Server Basic 安全漏洞 — TeleControl Server BasicCWE-130 3.7 Low2025-04-17
CVE-2024-13925 Klarna Checkout for WooCommerce < 2.13.5 - DoS via Excessive Logging — Klarna Checkout for WooCommerce 7.5AIHighAI2025-04-17
CVE-2025-29662 LandChat 安全漏洞 — n/a 9.8AICriticalAI2025-04-17
CVE-2025-32433 Erlang/OTP SSH Vulnerable to Pre-Authentication RCE — otpCWE-306 10.0 Critical2025-04-16
CVE-2025-27540 Siemens TeleControl Server Basic SQL注入漏洞 — TeleControl Server BasicCWE-89 9.8 Critical2025-04-16
CVE-2025-27539 Siemens TeleControl Server Basic SQL注入漏洞 — TeleControl Server BasicCWE-89 9.8 Critical2025-04-16
CVE-2025-27495 Siemens TeleControl Server Basic SQL注入漏洞 — TeleControl Server BasicCWE-89 9.8 Critical2025-04-16
CVE-2025-20236 Cisco Webex App Client-Side Remote Code Execution Vulnerability — Cisco Webex TeamsCWE-829 8.8 High2025-04-16
CVE-2025-20150 Cisco Nexus Dashboard Username Enumeration Vulnerability — Cisco Nexus DashboardCWE-209 5.3 Medium2025-04-16
CVE-2025-3104 WP Staging Pro <= 6.1.2 - Unauthenticated Information Exposure via getOutdatedPluginsRequest Function — WP STAGING Pro WordPress Backup PluginCWE-200 5.3 Medium2025-04-16
CVE-2025-3247 Contact Form 7 <= 6.0.5 - Order Replay Vulnerability — Contact Form 7CWE-354 5.3 Medium2025-04-16
CVE-2024-13452 Contact Form by Supsystic <= 1.7.29 - Cross-Site Request Forgery to Stored Cross-Site Scripting via saveAsCopy AJAX Action — Contact Form by SupsysticCWE-79 6.1 Medium2025-04-16
CVE-2024-53304 LRQA Nettitude PoshC2 安全漏洞 — n/a 9.8AICriticalAI2025-04-16
CVE-2024-55372 Wallos 安全漏洞 — n/a 9.8AICriticalAI2025-04-16
CVE-2025-27929 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portalCWE-639 5.3 Medium2025-04-15
CVE-2025-24315 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portalCWE-639 5.3 Medium2025-04-15
CVE-2025-27561 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portalCWE-639 5.3 Medium2025-04-15
CVE-2025-30257 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portalCWE-639 5.3 Medium2025-04-15
CVE-2025-31147 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portalCWE-639 5.3 Medium2025-04-15
CVE-2025-31360 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portalCWE-639 6.5 Medium2025-04-15
CVE-2025-30512 Growatt Cloud portal External Control of System or Configuration Setting — Cloud portalCWE-15 6.5 Medium2025-04-15
CVE-2025-27927 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portalCWE-639 5.3 Medium2025-04-15
CVE-2025-25276 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portalCWE-639 5.3 Medium2025-04-15
CVE-2025-27565 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portalCWE-639 5.3 Medium2025-04-15

Vulnerabilities classified as access:pre-auth represent 18854 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.