Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18854

18854 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-3363 HGiga iSherlock - OS Command Injection — iSherlock 4.5CWE-78 9.8 Critical2025-04-08
CVE-2025-3362 HGiga iSherlock - OS Command Injection — iSherlock 4.5CWE-78 9.8 Critical2025-04-08
CVE-2025-3361 HGiga iSherlock - OS Command Injection — iSherlock 4.5CWE-78 9.8 Critical2025-04-08
CVE-2025-2526 Streamit <= 4.0.2 - Authenticated (Subscriber+) Privilege Escalation via User Email Change/Account Takeover — StreamitCWE-639 8.8 High2025-04-08
CVE-2025-0942 Jalios JPlatform 10 SP6 < 10.0.6 Record Chooser SQL Injection — JPlatformCWE-89 8.6 High2025-04-07
CVE-2025-3248 Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code — langflowCWE-306 9.8 Critical2025-04-07
CVE-2025-31492 mod_auth_openidc allows OIDCProviderAuthRequestMethod POSTs to leak protected data — mod_auth_openidcCWE-200 7.5AIHighAI2025-04-06
CVE-2025-32370 Kentico Xperience 安全漏洞 — XperienceCWE-912 7.2 High2025-04-06
CVE-2025-2941 Drag and Drop Multiple File Upload for WooCommerce <= 1.1.4 - Unauthenticated Arbitrary File Move — Drag and Drop Multiple File Upload for WooCommerceCWE-22 9.8 Critical2025-04-05
CVE-2025-2789 MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.19 - Missing Authorization to Unauthenticated Table Rates Deletion — MultiVendorX – WooCommerce Multivendor Marketplace SolutionsCWE-862 5.3 Medium2025-04-05
CVE-2024-13604 KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin <= 1.7.4 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base PluginCWE-200 7.5 High2025-04-05
CVE-2025-0810 Read More & Accordion <= 3.4.7 - Cross-Site Request Forgery to Local File Inclusion — Read More & AccordionCWE-352 7.5 High2025-04-05
CVE-2021-47667 ZendTo 安全漏洞 — ZendToCWE-78 10.0 Critical2025-04-05
CVE-2025-27520 BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization — BentoMLCWE-502 9.8 Critical2025-04-04
CVE-2025-2798 Woffice <= 5.4.21 - Authentication Bypass via Registration Role — Woffice CRMCWE-269 9.8 Critical2025-04-04
CVE-2025-2797 Woffice Core <= 5.4.21 - Cross-Site Request Forgery to User Registration Approval — Woffice CoreCWE-352 5.4 Medium2025-04-04
CVE-2024-13708 Booster for WooCommerce 4.0.1 - 7.2.4 - Unauthenticated Stored Cross-Site Scripting — Booster for WooCommerceCWE-434 7.2 High2025-04-04
CVE-2025-2270 Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.8.9.1 - Unauthenticated Limited Local File Inclusion — Countdown, Coming Soon, Maintenance – Countdown & ClockCWE-22 8.1 High2025-04-04
CVE-2024-13645 TagDiv Composer <= 5.3 - Unauthenticated Arbitrary PHP Object Instantiation — tagDiv ComposerCWE-94 9.8 Critical2025-04-04
CVE-2025-2317 Product Filter by WBW <= 2.7.9 - Unauthenticated SQL Injection via filtersDataBackend Parameter — Product Filter for WooCommerce by WBWCWE-89 7.5 High2025-04-04
CVE-2024-13744 Booster for WooCommerce 4.0.1 - 7.2.4 - Unauthenticated Arbitrary File Upload — Booster for WooCommerceCWE-434 8.1 High2025-04-04
CVE-2025-2075 Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation — Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder PluginCWE-862 8.8 High2025-04-04
CVE-2025-25061 JTEKT ELECTRONICS HMI ViewJet C-more 安全漏洞 — HMI ViewJet C-more seriesCWE-441 8.2AIHighAI2025-04-04
CVE-2025-24317 JTEKT ELECTRONICS HMI ViewJet C-more 安全漏洞 — HMI ViewJet C-more seriesCWE-770 7.5AIHighAI2025-04-04
CVE-2025-24310 JTEKT ELECTRONICS HMI ViewJet C-more 安全漏洞 — HMI ViewJet C-more seriesCWE-1021 9.6AICriticalAI2025-04-04
CVE-2025-22457 Ivanti Connect Secure 安全漏洞 — Connect SecureCWE-121 9.0 Critical2025-04-03
CVE-2025-2299 LuckyWP Table of Contents <= 2.1.10 - Cross-Site Request Forgery to Reflected Cross-Site Scripting — LuckyWP Table of ContentsCWE-79 6.1 Medium2025-04-03
CVE-2025-22931 Open Solutions For Education OS4Ed OpenSIS 安全漏洞 — n/a 7.5AIHighAI2025-04-03
CVE-2025-31161 CrushFTP 安全漏洞 — CrushFTPCWE-305 9.8 Critical2025-04-03
CVE-2025-20120 Cisco Evolved Programmable Network Manager和Cisco Prime Infrastructure 跨站脚本漏洞 — Cisco Prime InfrastructureCWE-79 6.1 Medium2025-04-02

Vulnerabilities classified as access:pre-auth represent 18854 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.