Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18865

18865 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-26340 Q-Free MAXTIME Suite 安全漏洞 — MaxTimeCWE-321 8.8 High2025-02-12
CVE-2025-26339 Q-Free MAXTIME Suite 访问控制错误漏洞 — MaxTimeCWE-306 9.8 Critical2025-02-12
CVE-2025-1102 Q-Free MAXTIME Suite 访问控制错误漏洞 — MaxTimeCWE-346 5.5 Medium2025-02-12
CVE-2025-1101 Q-Free MAXTIME Suite 安全漏洞 — MaxTimeCWE-204 5.3 Medium2025-02-12
CVE-2025-1100 Q-Free MAXTIME Suite 安全漏洞 — MaxTimeCWE-259 9.8 Critical2025-02-12
CVE-2024-12386 WP Abstracts <= 2.7.3 - Cross-Site Request Forgery to Arbitrary Account Deletion — WP AbstractsCWE-352 8.1 High2025-02-12
CVE-2024-13480 LTL Freight Quotes – For Customers of FedEx Freight <= 3.4.1 - Unauthenticated SQL Injection — LTL Freight Quotes – For Customers of FedEx FreightCWE-89 7.5 High2025-02-12
CVE-2024-13477 LTL Freight Quotes – Unishippers Edition <= 2.5.8 - Unauthenticated SQL Injection — LTL Freight Quotes – Unishippers EditionCWE-89 7.5 High2025-02-12
CVE-2024-13532 Small Package Quotes – Purolator Edition <= 3.6.4 - Unauthenticated SQL Injection — Small Package Quotes – Purolator EditionCWE-89 7.5 High2025-02-12
CVE-2025-0511 Welcart e-Commerce <= 2.11.9 - Unauthenticated Stored Cross-Site Scripting via name Parameter — Welcart e-CommerceCWE-79 7.2 High2025-02-12
CVE-2024-13475 Small Package Quotes – UPS Edition <= 4.5.16 - Unauthenticated SQL Injection — Small Package Quotes – UPS EditionCWE-89 7.5 High2025-02-12
CVE-2024-13531 ShipEngine Shipping Quotes <= 1.0.7 - Unauthenticated SQL Injection — ShipEngine Shipping QuotesCWE-89 7.5 High2025-02-12
CVE-2024-13365 Security & Malware scan by CleanTalk <= 2.149 - Unauthenticated Arbitrary File Upload — Login Security, FireWall, Malware removal by CleanTalkCWE-434 9.8 Critical2025-02-12
CVE-2024-13437 Book a Room <= 2.9 - Cross-Site Request Forgery to Settings Update — Book a RoomCWE-352 4.3 Medium2025-02-12
CVE-2024-12213 WP Job Board Pro < 1.2.85 - Unauthenticated Privilege Escalation via process_register — WP Job Board ProCWE-266 9.8 Critical2025-02-12
CVE-2024-13490 LTL Freight Quotes – XPO Edition <= 4.3.7 - Unauthenticated SQL Injection — LTL Freight Quotes – XPO EditionCWE-89 7.5 High2025-02-12
CVE-2024-13435 Ebook Downloader <= 1.0 - Unauthenticated SQL Injection — Ebook DownloaderCWE-89 7.5 High2025-02-12
CVE-2024-13473 LTL Freight Quotes - Worldwide Express Edition <= 5.0.20 - Unauthenticated SQL Injection — LTL Freight Quotes – Worldwide Express EditionCWE-89 7.5 High2025-02-12
CVE-2024-12315 Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Information Disclosure Through Unprotected Directory — Export All Posts, Products, Orders, Refunds & UsersCWE-922 7.5 High2025-02-12
CVE-2024-13794 Hide My WP Ghost – Security & Firewall <= 5.3.02 - Unauthenticated Login Page Disclosure — WP Ghost (Hide My WP Ghost) – Security & FirewallCWE-693 5.3 Medium2025-02-12
CVE-2024-13821 WP Booking Calendar <= 10.10 - Unauthenticated Post-Confirmation Booking Manipulation — Booking CalendarCWE-285 5.3 Medium2025-02-12
CVE-2024-13600 Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin <= 1.0.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — Majestic Support – The Leading-Edge Help Desk & Customer Support PluginCWE-200 7.5 High2025-02-12
CVE-2024-13421 Real Estate 7 WordPress <= 3.5.1 - Unauthenticated Privilege Escalation to Administrator — Real Estate 7 WordPressCWE-266 9.8 Critical2025-02-12
CVE-2024-13749 StaffList <= 3.2.3 - Cross-Site Request Forgery to Reflected Cross-Site Scripting — StaffListCWE-79 6.1 Medium2025-02-12
CVE-2025-0808 Houzez Property Feed <= 2.4.21 - Cross-Site Request Forgery to Property Feed Export Deletion — Houzez Property FeedCWE-352 4.3 Medium2025-02-12
CVE-2024-13539 AForms Eats <= 1.3.1 - Unauthenticated Full Path Disclosure — AForms EatsCWE-209 5.3 Medium2025-02-12
CVE-2024-13554 The Ultimate WordPress Toolkit – WP Extended <= 3.0.13 - Missing Authorization to Unauthenticated Post Order Manipulation — The Ultimate WordPress Toolkit – WP ExtendedCWE-862 5.3 Medium2025-02-12
CVE-2022-3180 WPGateway <= 3.5 - Unauthenticated Privilege Escalation — WPGatewayCWE-290 9.8 -2025-02-11
CVE-2025-24406 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Adobe CommerceCWE-22 7.5 High2025-02-11
CVE-2025-24472 Fortinet FortiOS 安全漏洞 — FortiProxyCWE-288 8.1 High2025-02-11

Vulnerabilities classified as access:pre-auth represent 18865 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.