Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-34434 AVideo < 20.1 ImageGallery Plugin Unauthenticated File Upload and Deletion — AVideoCWE-306 9.1AICriticalAI2025-12-17
CVE-2025-34441 AVideo < 20.1 User Information Disclosure via Public API — AVideoCWE-359 7.5AIHighAI2025-12-17
CVE-2025-62521 ChurchCRM has unauthenticated RCE in its Install Wizard — CRMCWE-94 10.0 Critical2025-12-17
CVE-2025-20393 Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability — Cisco Secure EmailCWE-20 10.0 Critical2025-12-17
CVE-2025-14399 Download Plugins and Themes from Dashboard <= 1.9.6 - Cross-Site Request Forgery to Bulk Plugin/Theme Archival — Download Plugins and Themes in ZIP from DashboardCWE-352 4.3 Medium2025-12-17
CVE-2025-11924 Ninja Forms – The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token — Ninja Forms – The Contact Form Builder That Grows With YouCWE-639 7.5 High2025-12-17
CVE-2025-14061 Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.0.7 - Missing Authorization to Unauthenticated Arbitrary Post Deletion — Cookie Banner for GDPR / CCPA – WPLP Cookie ConsentCWE-862 5.3 Medium2025-12-17
CVE-2025-14154 Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.10.2 - Unauthenticated Stored Cross-Site Scripting — Better Messages – Live Chat, Chat Rooms, Real-Time Messaging & Private MessagesCWE-79 6.1 Medium2025-12-17
CVE-2025-13861 HTML Forms – Simple WordPress Forms Plugin <= 1.6.0 - Unauthenticated Stored Cross-Site Scripting — HTML Forms – Simple WordPress Forms PluginCWE-79 6.1 Medium2025-12-17
CVE-2025-13880 WP Social Ninja - Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) <= 4.0.1 - Missing Authorization to Unauthenticated Plugin's Settings Disclosure And Modification — WP Social Ninja – Embed Social Feeds, User Reviews & Chat WidgetsCWE-862 6.5 Medium2025-12-17
CVE-2025-14304 ASRock, ASRockRack, ASRockInd|Motherboard - Protection Mechanism Failure — Intel 500 chipset motherboardCWE-693 6.8 Medium2025-12-17
CVE-2025-14303 MSI|Motherboard - Protection Mechanism Failure — Intel 600 chipset motherboardCWE-693 6.8 Medium2025-12-17
CVE-2025-14302 GIGABYTE|Motherboard - Protection Mechanism Failure — intel 600 chipset MotherboardCWE-693 6.8 Medium2025-12-17
CVE-2025-11009 Information Disclosure Vulnerability in GT Designer3 — GT Designer3 Version1 (GOT2000)CWE-312 5.1 Medium2025-12-17
CVE-2025-14701 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafty Controller — Crafty ControllerCWE-79 7.1 High2025-12-17
CVE-2025-65855 Netun Solutions HelpFlash IoT 安全漏洞 — n/a 6.8AIMediumAI2025-12-17
CVE-2025-14466 Güralp Systems Fortimus Series, Minimus Series, and Certimus Series have an Allocation of Resources Without Limits or Throttling vulnerability — Fortimus SeriesCWE-770 5.3 Medium2025-12-16
CVE-2025-14553 Password Hash Leak Could Lead to Unauthorized Access on Tapo App via Local Network — TP-Link Tapo AppCWE-200 7.3AIHighAI2025-12-16
CVE-2025-68155 @vitejs/plugin-rsc has Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint on Development — vite-plugin-reactCWE-22 7.5 High2025-12-16
CVE-2023-53896 D-Link DAP-1325 Hardware A1 Unauthenticated Configuration Download — DAP-1325CWE-306 7.5 High2025-12-16
CVE-2025-59935 GLPI Vulnerable to Unauthenticated Stored XSS on the Inventory page — glpiCWE-79 6.5 Medium2025-12-16
CVE-2025-14002 WPCOM Member <= 1.7.16 - Authentication Bypass via Weak OTP — WPCOM MemberCWE-287 8.1 High2025-12-16
CVE-2025-13231 Fancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Server-Side Request Forgery via Race Condition — Fancy Product DesignerCWE-362 6.5 Medium2025-12-16
CVE-2025-11991 JetFormBuilder <= 3.5.3 - Missing Authorization to Unauthenticated Form Generation — JetFormBuilder — Dynamic Blocks Form BuilderCWE-862 5.3 Medium2025-12-16
CVE-2025-13439 Fancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Information Disclosure and PHAR Deserialization via 'url' Parameter — Fancy Product DesignerCWE-200 5.9 Medium2025-12-16
CVE-2025-12809 dokan pro <= 4.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure — Dokan ProCWE-862 5.3 Medium2025-12-16
CVE-2025-13956 LearnPress – WordPress LMS Plugin <= 4.3.1 - Missing Authorization to Unauthenticated Orders Statistics Exposure — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-862 5.3 Medium2025-12-16
CVE-2025-63414 Allsky Camera 安全漏洞 — n/a 9.8AICriticalAI2025-12-16
CVE-2025-14038 EnterpriseDB Hybrid Manager - LTS 安全漏洞 — Hybrid Manager - LTSCWE-862 7.0 High2025-12-15
CVE-2025-34179 NetSupport Manager < 14.12.0001 Unauthenticated SQLi Local File Disclosure — ManagerCWE-89 9.1AICriticalAI2025-12-15

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.