Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18855

18855 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-12537 Unauthenticated Denial of Service in open-webui/open-webui — open-webui/open-webuiCWE-770 7.5 -2025-03-20
CVE-2024-10553 Jdbc Deserialization in h2oai/h2o-3 — h2oai/h2o-3CWE-502 9.8 -2025-03-20
CVE-2024-9340 Denial of Service (DoS) via Multipart Boundary in zenml-io/zenml — zenml-io/zenmlCWE-835 7.5 -2025-03-20
CVE-2024-10713 Denial of Service (DoS) via Multipart Request in szad670401/hyperlpr — szad670401/hyperlprCWE-770 7.5 -2025-03-20
CVE-2025-2505 Age Gate <= 3.5.3 - Unauthenticated Local PHP File Inclusion via 'lang' — Age GateCWE-22 9.8 Critical2025-03-20
CVE-2025-1766 Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Missing Authorization to Unauthenticated Payment Status Update — Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)CWE-862 5.3 Medium2025-03-20
CVE-2025-1314 Custom Twitter Feeds <= 2.2.5 - Cross-Site Request Forgery to Cache Reset via ctf_clear_cache_admin Function — Custom Twitter Feeds – A Tweets Widget or X Feed WidgetCWE-352 4.3 Medium2025-03-20
CVE-2025-0431 Enterprise Protection Backslash URL Rewrite Bypass — Enterprise ProtectionCWE-790 5.8 Medium2025-03-19
CVE-2025-2512 File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated File Upload via upload Function — File AwayCWE-434 9.8 Critical2025-03-19
CVE-2024-13442 Service Finder Bookings <= 5.0 - Unauthenticated Privilege Escalation via Account Takeover — Service Finder BookingsCWE-288 9.8 Critical2025-03-19
CVE-2024-13933 FoodBakery | Delivery Restaurant Directory WordPress Theme <= 4.7 - Cross-Site Request Forgery in Multiple Functions — FoodBakery | Delivery Restaurant Directory WordPress ThemeCWE-352 8.8 High2025-03-19
CVE-2024-13790 MinimogWP – The High Converting eCommerce WordPress Theme <= 3.7.0 - Unauthenticated Local PHP File Inclusion — MinimogWP – The High Converting eCommerce WordPress ThemeCWE-98 9.8 Critical2025-03-19
CVE-2024-13412 CozyStay <= 1.7.0 - Missing Authorization to Arbitrary Action Execution in ajax_handler — CozyStay - Hotel Booking WordPress ThemeCWE-862 7.5 High2025-03-19
CVE-2024-13410 CozyStay <= 1.7.0 and TinySalt <= 3.9.0 - Unauthenticated PHP Object Injection in ajax_handler — CozyStay - Hotel Booking WordPress ThemeCWE-502 9.8 Critical2025-03-19
CVE-2025-1232 Site Reviews < 7.2.5 - Unauthenticated Stored XSS — Site Reviews 6.1 -2025-03-19
CVE-2024-12922 Altair <= 5.2.4 - Unauthenticated Arbitrary Options Update via pp_import_current — AltairCWE-862 9.8 Critical2025-03-19
CVE-2025-2290 LifterLMS <= 8.0.1 - Missing Authorization to Unauthenticated Post Trashing — LifterLMS – WP LMS for eLearning, Online Courses, & QuizzesCWE-862 5.3 Medium2025-03-19
CVE-2025-24799 GLPI allows unauthenticated SQL injection through the inventory endpoint — glpiCWE-89 7.5 High2025-03-18
CVE-2023-22514 Atlassian Sourcetree 安全漏洞 — Sourcetree for Mac--2025-03-18
CVE-2023-47539 Fortinet FortiMail 安全漏洞 — FortiMailCWE-284 9.0 Critical2025-03-18
CVE-2024-41975 CODESYS (Edge) Gateway for Windows insecure default — CODESYS Edge GatewayCWE-1188 5.3 Medium2025-03-18
CVE-2024-23943 MB connect line: Cloud API access due to a lack of authentication for a critical function — mbCONNECT24CWE-306 9.1 Critical2025-03-18
CVE-2025-1468 CODESYS Control V3 - OPC UA Server Authentication bypass — CODESYS Runtime ToolkitCWE-203 7.5 High2025-03-18
CVE-2025-2262 Logo Slider <= 3.7.3 - Unauthenticated Arbitrary Shortcode Execution — Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo PresentationCWE-862 7.3 High2025-03-18
CVE-2025-26137 Systemic RiskValue 安全漏洞 — n/a 7.5 -2025-03-18
CVE-2023-22512 Atlassian Confluence 安全漏洞 — Confluence Data Center--2025-03-17
CVE-2024-48831 Dell SmartFabric OS10 安全漏洞 — SmartFabric OS10 SoftwareCWE-259 8.4 High2025-03-17
CVE-2019-6697 Fortinet FortiGate 跨站脚本漏洞 — FortiOSCWE-79 5.2 Medium2025-03-17
CVE-2025-27102 Agate vulnerable to HTML injection in user signup - Administrator phishing risk — agateCWE-79 6.1 -2025-03-17
CVE-2019-17659 Fortinet FortiSIEM 安全漏洞 — FortiSIEMCWE-798 3.6 Low2025-03-17

Vulnerabilities classified as access:pre-auth represent 18855 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.