Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18854

18854 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-20139 Cisco Enterprise Chat and Email 安全漏洞 — Cisco Enterprise Chat and EmailCWE-185 7.5 High2025-04-02
CVE-2025-3097 wp Time Machine <= 3.4.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting — wp Time MachineCWE-79 6.1 Medium2025-04-02
CVE-2025-2483 Gift Certificate Creator <= 1.1.0 - Reflected Cross-Site Scripting via receip_address Parameter — Gift Certificate CreatorCWE-79 6.1 Medium2025-04-02
CVE-2025-3098 Video Url <= 1.0.0.3 - Reflected Cross-Site Scripting — Video UrlCWE-79 6.1 Medium2025-04-02
CVE-2024-12410 Front End Users <= 3.2.32 - Authenticated (Admin+) SQL injection — Front End UsersCWE-89 4.9 Medium2025-04-02
CVE-2025-2005 Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload — Front End UsersCWE-434 9.8 Critical2025-04-02
CVE-2025-3099 Advanced Search by My Solr Server <= 2.0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Advanced Search by My Solr ServerCWE-352 6.1 Medium2025-04-02
CVE-2025-27244 Hammock AssetView 安全漏洞 — AssetViewCWE-201 7.5 -2025-04-02
CVE-2025-25060 Hammock AssetView 访问控制错误漏洞 — AssetViewCWE-306 9.8 -2025-04-02
CVE-2025-27694 Dell Wyse Management Suite 安全漏洞 — Wyse Management SuiteCWE-410 5.3 Medium2025-04-02
CVE-2025-29981 Dell Wyse Management Suite 安全漏洞 — Wyse Management SuiteCWE-202 7.5 High2025-04-02
CVE-2025-2237 WP RealEstate <= 1.6.26 - Unauthenticated Privilege Escalation via 'process_register' — WP RealEstateCWE-269 9.8 Critical2025-04-01
CVE-2024-13553 SMS Alert Order Notifications – WooCommerce <= 3.7.9 - Unauthenticated Account Takeover/Privilege Escalation — SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart RecoveryCWE-288 9.8 Critical2025-04-01
CVE-2025-27130 Welcart e-Commerce 代码问题漏洞 — Welcart e-CommerceCWE-502 9.8 -2025-04-01
CVE-2024-12278 Booster for WooCommerce <= 7.2.4 - Unauthenticated Stored Cross-Site Scripting — Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ ToolsCWE-79 7.2 High2025-04-01
CVE-2024-13567 Awesome Support – WordPress HelpDesk & Support Plugin <= 6.3.1 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — Awesome Support – WordPress HelpDesk & Support PluginCWE-200 7.5 High2025-04-01
CVE-2025-31194 Apple macOS 安全漏洞 — macOS 9.8 -2025-03-31
CVE-2025-30428 Apple iOS和Apple iPadOS 安全漏洞 — iOS and iPadOS 5.3 -2025-03-31
CVE-2025-2794 Kentico Xperience <= 13.0.180 Unsafe Reflection — XperienceCWE-470 7.5 -2025-03-31
CVE-2025-2586 Ols: unauthenticated metrics flooding in openshift lightspeed service leading to resource exhaustion CWE-400 7.5 High2025-03-31
CVE-2025-2402 Hard-coded password for object store of KNIME Business Hub — KNIME Business HubCWE-259 9.8 -2025-03-31
CVE-2025-0613 Photo Gallery < 1.8.34 - Unauthenticated Stored XSS — Photo Gallery by 10Web 6.1 -2025-03-31
CVE-2025-24517 Inaba Denki Sangyo CHOCO TEI WATCHER mini 安全漏洞 — CHOCO TEI WATCHER mini (IB-MCT001)CWE-603 7.5 High2025-03-31
CVE-2025-3011 PiExtract SOOP-CLM - SQL Injection — SOOP-CLMCWE-89 9.8 Critical2025-03-31
CVE-2025-29266 Unraid 安全漏洞 — UnraidCWE-289 9.6 Critical2025-03-31
CVE-2024-13804 Hewlett Packard Enterprise Insight Cluster Management Utility 安全漏洞 — HPE Insight Cluster Management Utility (CMU) 8.8 -2025-03-30
CVE-2024-13557 Shortcodes by United Themes <= 5.1.6 - Unauthenticated Arbitrary Shortcode Execution — Shortcodes by United ThemesCWE-94 6.5 Medium2025-03-29
CVE-2025-2006 Inline Image Upload for BBPress <= 1.1.19 - Authenticated (Subscriber+) Arbitrary File Upload — Inline Image Upload for BBPressCWE-434 8.8 High2025-03-29
CVE-2025-2266 Checkout Mestres do WP for WooCommerce 8.6.5 - 8.7.5 - Unauthenticated Arbitrary Options Update — Checkout Mestres do WP for WooCommerceCWE-862 9.8 Critical2025-03-29
CVE-2025-2803 So-Called Air Quotes <= 0.1 - Unauthenticated Arbitrary Shortcode Execution — So-Called Air QuotesCWE-94 7.3 High2025-03-29

Vulnerabilities classified as access:pre-auth represent 18854 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.