Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18866

18866 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-46436 Tenda W18E 信任管理问题漏洞 — n/a 9.8 -2025-02-10
CVE-2024-46437 Tenda W18E 信息泄露漏洞 — n/a 9.8 -2025-02-10
CVE-2024-13440 Super Store Finder <= 7.0 - Unauthenticated SQL Injection to Stored Cross-Site Scripting — Super Store FinderCWE-89 8.2 High2025-02-09
CVE-2025-0316 WP Directorybox Manager <= 2.5 - Authentication Bypass — WP Directorybox ManagerCWE-288 9.8 Critical2025-02-08
CVE-2024-7419 WP All Export Pro <= 1.9.1 - Unauthenticated Remote Code Execution via Custom Export Fields — WP All Export ProCWE-94 8.3 High2025-02-07
CVE-2024-9661 WP All Import Pro <= 4.9.7 - Cross-Site Request Forgery to Imported Content Deletion — WP All Import ProCWE-352 4.3 Medium2025-02-07
CVE-2025-1108 Insufficient data authenticity vulnerability in Janto — JantoCWE-345 8.6 High2025-02-07
CVE-2025-1107 Unverified password change vulnerability in Janto — JantoCWE-620 9.9 Critical2025-02-07
CVE-2025-1077 Remote Code Execution vulnerability in IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weather) — Visual WeatherCWE-502 9.8 -2025-02-07
CVE-2025-1061 Nextend Social Login Pro <= 3.1.16 - Authentication Bypass via Apple OAuth provider — Nextend Social Login ProCWE-288 9.8 Critical2025-02-07
CVE-2025-0675 Elber Communications Equipment Hidden Functionality — Signum DVB-S/S2 IRDCWE-912 7.5 High2025-02-06
CVE-2024-52892 IBM Jazz for Service Management Cross-Site Scripting — Jazz for Service ManagementCWE-79 6.1 Medium2025-02-06
CVE-2025-24786 Path traversal opening Sqlite3 database in WhoDB — whodbCWE-35 10.0 Critical2025-02-06
CVE-2024-37358 Apache James: denial of service through the use of IMAP literals — Apache James serverCWE-770 8.6 High2025-02-06
CVE-2024-13487 CURCY – Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via get_products_price Function — CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.xCWE-94 7.3 High2025-02-06
CVE-2025-23094 Mitel OpenScape 4000和OpenScape 4000 Manager 安全漏洞 — n/a 9.8 -2025-02-06
CVE-2025-20183 Cisco Secure Web Appliance Range Request Bypass Vulnerability — Cisco Secure Web ApplianceCWE-20 5.8 Medium2025-02-05
CVE-2025-20179 Cisco Expressway Series Cross-Site Scripting Vulnerability — Cisco TelePresence Video Communication Server (VCS) ExpresswayCWE-79 6.1 Medium2025-02-05
CVE-2024-13829 WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto <= 8.0.8 - Unauthenticated Sensitive Information Exposure — WordPress form builder plugin for contact forms, surveys and quizzes – TripettoCWE-200 5.3 Medium2025-02-05
CVE-2025-1028 Contact Manager <= 8.6.4 - Unauthenticated Arbitrary Double File Extension Upload — Contact ManagerCWE-434 8.1 High2025-02-05
CVE-2025-25246 NETGEAR XR1000和NETGEAR XR500 安全漏洞 — XR1000CWE-94 8.1 High2025-02-05
CVE-2024-13722 Checkmk NagVis Reflected Cross-site Scripting — NagVisCWE-79 6.1 -2025-02-04
CVE-2024-40700 IBM Security Verify Access cross-site scripting — Security Verify Access ApplianceCWE-79 6.1 Medium2025-02-04
CVE-2025-0364 BigAntSoft BigAnt Server Account Registration Bypass to File Upload RCE — BigAnt ServerCWE-288 9.8 Critical2025-02-04
CVE-2024-9644 Four-Faith F3x36 bapply.cgi Auth Bypass — F3x36CWE-489 9.8 Critical2025-02-04
CVE-2024-13510 ShopSite <= 1.5.10 - Cross-Site Request Forgery to Stored Cross-Site Scripting — ShopSiteCWE-352 6.1 Medium2025-02-04
CVE-2024-13356 DSGVO All in one for WP <= 4.6 - Cross-Site Request Forgery to Account Deletion — DSGVO All in one for WPCWE-352 6.5 Medium2025-02-04
CVE-2025-0466 Sensei LMS < 4.24.4 - Unauthenticated sensei_email/sensei_message Disclosure — Sensei LMS 5.3 -2025-02-04
CVE-2025-0368 Banner Garden Plugin for WordPress <= 0.1.3 - Reflected XSS — Banner Garden Plugin for WordPress 6.1 -2025-02-04
CVE-2025-0148 Zoom Jenkins Marketplace plugin - Missing Password Field Masking — Zoom Jenkins Marketplace pluginCWE-549 2.6 Low2025-02-03

Vulnerabilities classified as access:pre-auth represent 18866 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.