Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18829

18829 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-69806 bareiron 安全漏洞 — n/a 5.3AIMediumAI2026-02-12
CVE-2025-69807 bareiron 安全漏洞 — n/a 7.5AIHighAI2026-02-12
CVE-2026-26215 manga-image-translator Shared API Unsafe Deserialization RCE — manga-image-translatorCWE-502 9.8AICriticalAI2026-02-11
CVE-2020-37158 AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset) — AVideo PlatformCWE-640 5.3 Medium2026-02-11
CVE-2020-37104 ASTPP 4.0.1 VoIP Billing - Database Backup Download — ASTPPCWE-538 7.5 High2026-02-11
CVE-2019-25313 FlexNet Publisher 11.12.1 - Cross-Site Request Forgery (Add Local Admin) — FlexNet PublisherCWE-352 4.0 Medium2026-02-11
CVE-2020-37172 AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset) — AVideo PlatformCWE-640 5.3 Medium2026-02-11
CVE-2026-0229 PAN-OS: Denial of Service in Advanced DNS Security Feature — Cloud NGFWCWE-754 7.5AIHighAI2026-02-11
CVE-2025-13391 Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) <= 4.9.60 - Missing Authorization to Unauthenticated Arbitrary Attachment and Dropbox File Deletion — Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium)CWE-862 5.8 Medium2026-02-11
CVE-2019-25312 InoERP 0.7.2 - Persistent Cross-Site Scripting — InoERPCWE-79 5.4 Medium2026-02-11
CVE-2026-2250 Unauthenticated Data Export and Source Code Disclosure via /dbviewer/ in METIS WIC — METIS WICCWE-284 7.5 High2026-02-11
CVE-2025-7659 Origin Validation Error in GitLab — GitLabCWE-346 8.0 High2026-02-11
CVE-2025-8099 Allocation of Resources Without Limits or Throttling in GitLab — GitLabCWE-770 7.5 High2026-02-11
CVE-2026-0958 Interpretation Conflict in GitLab — GitLabCWE-436 7.5 High2026-02-11
CVE-2026-1456 Allocation of Resources Without Limits or Throttling in GitLab — GitLabCWE-770 6.5 Medium2026-02-11
CVE-2026-1458 Allocation of Resources Without Limits or Throttling in GitLab — GitLabCWE-770 6.5 Medium2026-02-11
CVE-2026-2295 WPZOOM Addons for Elementor – Starter Templates & Widgets <= 1.3.2 - Unauthenticated Protected Post Exposure via ajax_post_grid_load_more — WPZOOM Addons for Elementor – Starter Templates & WidgetsCWE-200 5.3 Medium2026-02-11
CVE-2026-1786 Twitter posts to Blog <= 1.11.25 - Missing Authorization to Unauthenticated Plugin Settings Update — Twitter posts to BlogCWE-862 6.5 Medium2026-02-11
CVE-2026-1215 MMA Call Tracking <= 2.3.15 - Cross-Site Request Forgery to Plugin Settings Update — MMA Call TrackingCWE-352 4.3 Medium2026-02-11
CVE-2025-15440 iONE360 configurator <= 2.0.57 - Unauthenticated Stored Cross-Site Scripting via Contact Form Parameters — iONE360 configuratorCWE-79 7.2 High2026-02-11
CVE-2026-1235 WP eCommerce <= 3.15.1 - Unauthenticated PHP Object Injection — WP eCommerce 9.8AICriticalAI2026-02-11
CVE-2026-1357 Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload — WPvivid — Backup, Migration & StagingCWE-434 9.8 Critical2026-02-11
CVE-2025-65127 ZBT WE2001 安全漏洞 — n/a 9.1AICriticalAI2026-02-11
CVE-2025-65128 ZBT WE2001 安全漏洞 — n/a 6.2AIMediumAI2026-02-11
CVE-2025-69871 Medusa 安全漏洞 — n/a 3.7AILowAI2026-02-11
CVE-2026-25872 JUNG Smart Panel 5.1 KNX Unauthenticated Path Traversal — JUNG Smart Panel 5.1 KNXCWE-22 5.3 Medium2026-02-10
CVE-2026-1507 Uncaught Exception vulnerability in AVEVA PI Data Archive — PI Data Archive PI ServerCWE-248 7.5 High2026-02-10
CVE-2026-25611 Pre-Authentication Memory Exhaustion Denial of Service in MongoDB Server — MongoDB ServerCWE-405 7.5 High2026-02-10
CVE-2026-26003 FastGPT Plugin forwarding request is not authenticated, posing a serious risk of attack — FastGPTCWE-601 6.5AIMediumAI2026-02-10
CVE-2026-0651 Path Traversal on TP-Link Tapo D235 and C260 via Local https — Tapo C260 v1CWE-22 6.1AIMediumAI2026-02-10

Vulnerabilities classified as access:pre-auth represent 18829 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.