Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2022-50695 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x ICMP Flood Attack via Network Commands — Impact/Pulse/FirstCWE-770 7.5 High2025-12-30
CVE-2022-50691 MiniDVBLinux 5.4 Remote Root Command Execution via commands.sh — MiniDVBLinuxCWE-78 9.8 Critical2025-12-30
CVE-2025-15355 NetVision Information|ISOinsight - Reflected Cross-site Scripting — ISOinsightCWE-79 6.1 Medium2025-12-30
CVE-2025-69217 Coturn has unsafe nonce and relay port randomization due to weak random number generation. — coturnCWE-338 7.7 High2025-12-30
CVE-2025-15284 arrayLimit bypass in bracket notation allows DoS via memory exhaustion CWE-20 3.7 Low2025-12-29
CVE-2025-14280 PixelYourSite <= 11.1.5 - Sensitive Information Exposure via Log File — PixelYourSite – Your smart PIXEL (TAG) & API ManagerCWE-200 5.3 Medium2025-12-29
CVE-2025-69211 Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU) — nestCWE-367 8.1 -2025-12-29
CVE-2025-69200 phpMyFAQ has unauthenticated config backup download via /api/setup/backup — phpMyFAQCWE-202 7.5 High2025-12-29
CVE-2025-15228 WELLTEND TECHNOLOGY| BPMFlowWebkit - Arbitrary File Upload — BPMFlowWebkitCWE-434 9.8 Critical2025-12-29
CVE-2025-15227 WELLTEND TECHNOLOGY| BPMFlowWebkit - Arbitrary File Read — BPMFlowWebkitCWE-36 7.5 High2025-12-29
CVE-2025-15226 Sunnet|WMPro - Arbitrary File Upload — WMProCWE-434 9.8 Critical2025-12-29
CVE-2025-15225 Sunnet|WMPro - Arbitrary File Read — WMProCWE-23 7.5 High2025-12-29
CVE-2025-52691 Upload Arbitrary Files — SmarterMail 10.0 Critical2025-12-29
CVE-2025-15129 ChenJinchuang Lin-CMS-TP5 File Upload LocalUploader.php upload code injection — Lin-CMS-TP5CWE-94 6.3 Medium2025-12-28
CVE-2025-67014 DEV 7113 RF over Fiber Distribution System 安全漏洞 — n/a 9.8 -2025-12-26
CVE-2025-14913 Frontend Post Submission Manager Lite <= 1.2.6 - Incorrect Authorization to Unauthenticated Arbitrary Attachment Deletion — Frontend Post Submission Manager Lite – Frontend Posting WordPress PluginCWE-862 5.3 Medium2025-12-25
CVE-2025-15082 TOZED ZLT M30s Web Management proc_post information disclosure — ZLT M30sCWE-200 5.3 Medium2025-12-25
CVE-2025-3232 Mitsubishi Electric Europe smartRTU Missing Authentication for Critical Function — smartRTUCWE-306 7.5 High2025-12-24
CVE-2019-25253 KYOCERA Net Admin 3.4.0906 Unauthenticated XML External Entity Injection — KYOCERA Net AdminCWE-611 7.5 High2025-12-24
CVE-2019-25248 Beward N100 M2.1.6 Unauthenticated RTSP Video Stream Disclosure — N100 H.264 VGA IP CameraCWE-306 7.5 High2025-12-24
CVE-2019-25240 Rifatron 5brid DVR 5brid DVR (HD6-532/516, DX6-516/508/504, MX6-516/508/504, EH6-504) Unauthenticated Live Stream Disclosure via animate.cgi — DVRCWE-306 9.8 Critical2025-12-24
CVE-2019-25241 FaceSentry Access Control System 6.4.8 Remote SSH Root Access — FaceSentry Access Control SystemCWE-798 7.5 High2025-12-24
CVE-2019-25239 V-SOL GPON/EPON OLT Platform 2.03 Unauthenticated Configuration Download — GPON/EPON OLT PlatformCWE-552 7.5 High2025-12-24
CVE-2019-25235 Smartwares HOME easy 1.0.9 Client-Side Authentication Bypass via Web Pages — Smartwares HOME easyCWE-639 9.8 Critical2025-12-24
CVE-2019-25236 iSeeQ Hybrid DVR WH-H4 1.03R Unauthenticated Live Stream Disclosure — Hybrid DVR WH-H4CWE-306 9.8 Critical2025-12-24
CVE-2018-25152 Ecessa Edge EV150 10.7.4 Cross-Site Request Forgery via User Configuration — Ecessa Edge EV150CWE-352 5.3 Medium2025-12-24
CVE-2018-25150 Ecessa ShieldLink SL175EHQ 10.7.4 Cross-Site Request Forgery via User Configuration — Ecessa ShieldLink SL175EHQCWE-352 5.3 Medium2025-12-24
CVE-2018-25140 FLIR Thermal Traffic Cameras V1.01-0bb5b27 Unauthenticated Websocket Device Manipulation — Thermal Traffic CamerasCWE-306 7.5 High2025-12-24
CVE-2018-25141 FLIR Thermal Traffic Cameras V1.01-0bb5b27 Unauthenticated RTSP Stream Disclosure — FLIR Thermal Traffic CamerasCWE-306 7.5 High2025-12-24
CVE-2018-25142 NovaRad NovaPACS Diagnostics Viewer 8.5 XML External Entity Injection — NovaPACS Diagnostics ViewerCWE-611 9.8 Critical2025-12-24

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.