Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18854

18854 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-2840 DAP to Autoresponders Email Syncing <= 1.0 - Unauthenticated Information Exposure — DAP to Autoresponders Email SyncingCWE-200 5.3 Medium2025-03-29
CVE-2025-2863 Cross-site request forgery (CSRF) vulnerability in saTECH BCU — saTECH BCUCWE-352 8.8 -2025-03-28
CVE-2021-24008 Fortinet多款产品 信息泄露漏洞 — FortiDDoSCWE-200 5.0 Medium2025-03-28
CVE-2025-1705 tagDiv Composer <= 5.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting — tagDiv ComposerCWE-79 6.1 Medium2025-03-28
CVE-2025-2578 Booking for Appointments and Events Calendar – Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure — Booking for Appointments and Events Calendar – AmeliaCWE-200 5.3 Medium2025-03-28
CVE-2025-2485 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletion — Drag and Drop Multiple File Upload for Contact Form 7CWE-502 7.5 High2025-03-28
CVE-2025-2328 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated Arbitrary File Deletion — Drag and Drop Multiple File Upload for Contact Form 7CWE-22 8.8 High2025-03-28
CVE-2025-2804 tagDiv Composer <= 5.3 - Reflected Cross-Site Scripting via 'account_id' and 'account_username' — tagDiv ComposerCWE-79 6.1 Medium2025-03-28
CVE-2025-2294 Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion — Kubio AI Page BuilderCWE-22 9.8 Critical2025-03-28
CVE-2025-24381 Dell Unity 输入验证错误漏洞 — UnityCWE-601 8.8 High2025-03-28
CVE-2024-49601 Dell Unity 操作系统命令注入漏洞 — UnityCWE-78 7.3 High2025-03-28
CVE-2025-24382 Dell Unity 操作系统命令注入漏洞 — UnityCWE-78 7.3 High2025-03-28
CVE-2025-22398 Dell Unity 操作系统命令注入漏洞 — UnityCWE-78 9.8 Critical2025-03-28
CVE-2025-24383 Dell Unity 安全漏洞 — UnityCWE-78 9.1 Critical2025-03-28
CVE-2025-2332 Export All Posts, Products, Orders, Refunds & Users <= 2.13 - Unauthenticated PHP Object Injection — Export All Posts, Products, Orders, Refunds & UsersCWE-502 9.8 Critical2025-03-27
CVE-2025-2481 MediaView <= 1.1.2 - Reflected Cross-Site Scripting via id Parameter — MediaViewCWE-79 6.1 Medium2025-03-27
CVE-2025-28138 TOTOLINK A810R 安全漏洞 — n/a 9.8AICriticalAI2025-03-27
CVE-2025-1440 Advanced iFrame <= 2024.5 - Unauthenticated Settings Update — Advanced iFrameCWE-20 5.3 Medium2025-03-26
CVE-2025-1514 Active Products Tables for WooCommerce <= 1.0.6.7 - Unauthenticated Arbitrary Filter Call — Active Products Tables for WooCommerce. Use constructor to create tablesCWE-20 7.3 High2025-03-26
CVE-2025-2009 Newsletters <= 4.9.9.7 - Unauthenticated Stored Cross-Site Scripting — NewslettersCWE-79 7.2 High2025-03-26
CVE-2025-1490 Smart Maintenance Mode <= 1.5.2 - Reflected Cross-Site Scripting via setstatus Parameter — Smart Maintenance ModeCWE-79 6.1 Medium2025-03-26
CVE-2025-2165 SH Email Alert <= 1.0 - Reflected Cross-Site Scripting — SH Email AlertCWE-79 6.1 Medium2025-03-26
CVE-2025-2109 WP Compress <= 6.30.15 - Unauthenticated Server-Side Request Forgery via init Function — WP Compress – Instant Performance & Speed OptimizationCWE-918 5.8 Medium2025-03-25
CVE-2025-2635 Digital License Manager <= 1.7.3 - Reflected Cross-Site Scripting via remove_query_arg Function — Digital License ManagerCWE-79 6.1 Medium2025-03-25
CVE-2025-2319 EZ SQL Reports Shortcode Widget and DB Backup 4.11.13 - 5.25.08 - Cross-Site Request Forgery to Remote Code Execution — EZ SQL Reports Shortcode Widget and DB BackupCWE-352 8.8 High2025-03-25
CVE-2024-13690 WP Church Donation <= 1.7 - Unauthenticated Stored Cross-Site Scripting — WP Church DonationCWE-79 7.2 High2025-03-25
CVE-2024-13710 Estatebud – Properties & Listings <= 5.5.0 - Cross-Site Request Forgery to Settings Update — Estatebud – Properties & ListingsCWE-352 4.3 Medium2025-03-25
CVE-2025-1320 teachPress <= 9.0.9 - Cross-Site Request Forgery to Import Delete — teachPressCWE-352 4.3 Medium2025-03-25
CVE-2025-2252 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title Disclosure — Easy Digital Downloads – eCommerce Payments and Subscriptions made easyCWE-200 5.3 Medium2025-03-25
CVE-2025-1798 Design Comuni Italia < 1.1.2 - Unauthenticated Stored XSS — design-comuni-wordpress-theme 6.1 -2025-03-25

Vulnerabilities classified as access:pre-auth represent 18854 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.