Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-14132 Category Dropdown List <= 1.0 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — Category Dropdown ListCWE-79 6.1 Medium2025-12-12
CVE-2025-13988 评论小秘书 <= 1.3.2 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — 评论小秘书CWE-79 6.1 Medium2025-12-12
CVE-2025-14161 Truefy Embed <= 1.1.0 - Cross-Site Request Forgery to 'truefy_embed_options_update' Settings Update — Truefy EmbedCWE-352 4.3 Medium2025-12-12
CVE-2025-14354 Resource Library for Logged In Users <= 1.5 - Cross-Site Request Forgery to Multiple Administrative Actions — Resource Library for Logged In UsersCWE-352 4.3 Medium2025-12-12
CVE-2025-13363 IMAQ Core <= 1.2.1 - Cross-Site Request Forgery to URL Structure Update — IMAQ CORECWE-352 4.3 Medium2025-12-12
CVE-2025-14165 Kirim.Email WooCommerce Integration <= 1.2.9 - Cross-Site Request Forgery to Settings Update — Kirim.Email WooCommerce IntegrationCWE-352 4.3 Medium2025-12-12
CVE-2025-14044 Visitor Logic Lite <= 1.0.3 - Unauthenticated PHP Object Injection via 'lpblocks' Cookie — Visitor Logic LiteCWE-502 8.1 High2025-12-12
CVE-2025-14158 Coding Blocks <= 1.1.0 - Cross-Site Request Forgery to Settings Update — Coding BlocksCWE-352 4.3 Medium2025-12-12
CVE-2025-13408 Foxtool All-in-One: Contact chat button, Custom login, Media optimize images <= 2.5.2 - Cross-Site Request Forgery to Google OAuth Connection — Foxtool All-in-One: Contact chat button, Custom login, Media optimize imagesCWE-352 4.3 Medium2025-12-12
CVE-2025-12883 Campay Woocommerce Payment Gateway <= 1.2.2 - Unauthenticated Payment Bypass — Campay Woocommerce Payment GatewayCWE-639 5.3 Medium2025-12-12
CVE-2025-14344 Multi Uploader for Gravity Forms <= 1.1.7 - Unauthenticated Arbitrary File Deletion — Multi Uploader for Gravity FormsCWE-22 9.8 Critical2025-12-12
CVE-2025-14129 Like DisLike Voting <= 1.0.1 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — Like DisLike VotingCWE-79 6.1 Medium2025-12-12
CVE-2025-14125 Complag <= 1.0.2 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — ComplagCWE-79 6.1 Medium2025-12-12
CVE-2025-14162 BMLT WordPress Plugin <= 3.11.4 - Cross-Site Request Forgery to Settings Creation and Deletion — BMLT WordPress SatelliteCWE-352 4.3 Medium2025-12-12
CVE-2025-67780 SpaceX Starlink Dish 安全漏洞 — Starlink DishCWE-306 4.2 Medium2025-12-11
CVE-2024-58312 xbtitFM 4.1.18 Unauthenticated Path Traversal in nfogen.php — xbtitFMCWE-22 7.5AIHighAI2025-12-11
CVE-2024-58310 APC Network Management Card 4 Path Traversal via Directory Traversal — Network Management Card 4CWE-22 7.5AIHighAI2025-12-11
CVE-2024-58309 xbtitFM 4.1.18 Unauthenticated SQL Injection in shoutedit.php — xbtitFMCWE-89 9.8AICriticalAI2025-12-11
CVE-2024-58308 Quick.CMS 6.7 SQL Injection Authentication Bypass via Admin Login — Quick.CMSCWE-89 9.8AICriticalAI2025-12-11
CVE-2024-58300 Siklu MultiHaul TG Series < 2.0.0 Unauthenticated Credential Disclosure Vulnerability — MultiHaul TG seriesCWE-306 9.8AICriticalAI2025-12-11
CVE-2024-58298 Compuware iStrobe Web 20.13 Pre-Auth Remote Code Execution via File Upload — Compuware iStrobe WebCWE-434 9.8AICriticalAI2025-12-11
CVE-2025-14534 UTT 进取 512W Endpoint formNatStaticMap strcpy buffer overflow — 进取 512WCWE-120 9.8 Critical2025-12-11
CVE-2025-12029 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab — GitLabCWE-79 8.0 High2025-12-11
CVE-2025-12562 Allocation of Resources Without Limits or Throttling in GitLab — GitLabCWE-770 7.5 High2025-12-11
CVE-2025-13764 WP CarDealer <= 1.2.16 - Unauthenticated Privilege Escalation — WP CarDealerCWE-269 9.8 Critical2025-12-11
CVE-2025-11467 RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 5.1.1 - Unauthenticated Blind Server-Side Request Forgery — RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds AggregatorCWE-918 5.8 Medium2025-12-11
CVE-2025-67718 Formio improperly authorized permission elevation through specially crafted request path — formioCWE-178 7.5AIHighAI2025-12-11
CVE-2020-36902 UBICOD Medivision Digital Signage 1.5.1 Authorization Bypass via User Privileges — UBICOD Medivision Digital SignageCWE-862 9.8AICriticalAI2025-12-10
CVE-2020-36899 QiHang Media Web Digital Signage 3.0.9 Unauthenticated Arbitrary File Disclosure — QiHang Media Web Digital SignageCWE-530 7.5AIHighAI2025-12-10
CVE-2020-36898 QiHang Media Web Digital Signage 3.0.9 Unauthenticated Arbitrary File Deletion — QiHang Media Web Digital SignageCWE-22 9.1AICriticalAI2025-12-10

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.