Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-42878 Sensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM) — SAP Web Dispatcher and Internet Communication Manager (ICM)CWE-1244 8.2 High2025-12-09
CVE-2025-42877 Memory Corruption vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server — SAP Web Dispatcher, Internet Communication Manager and SAP Content ServerCWE-787 7.5 High2025-12-09
CVE-2025-42872 Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal — SAP NetWeaver Enterprise PortalCWE-489 6.1 Medium2025-12-09
CVE-2025-66507 1Panel – CAPTCHA Bypass via Client-Controlled Flag — 1PanelCWE-602 7.5 High2025-12-09
CVE-2025-65287 prolink SNMP Web Pro 安全漏洞 — n/a 7.5AIHighAI2025-12-09
CVE-2025-66202 Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765 — astroCWE-647 6.5 Medium2025-12-08
CVE-2025-27020 Improper configuration of SSH service in Infinera MTC-9 — MTC-9CWE-306 9.8 Critical2025-12-08
CVE-2025-26488 Improper input validation in XML Management service in Infinera MTC-9 — MTC-9CWE-20 7.5 High2025-12-08
CVE-2025-26487 Server Side Request Forgery (SSRF) in the web server of Infinera MTC-9 — MTC-9CWE-918 8.6 High2025-12-08
CVE-2025-12499 Rich Shortcodes for Google Reviews <= 6.8 - Unauthenticated Stored Cross-Site Scripting via Google Review — Rich Showcase for Google ReviewsCWE-79 7.2 High2025-12-06
CVE-2025-13748 Fluent Forms <= 6.1.7 - Unauthenticated Insecure Direct Object Reference to Payment Status Tampering via submission_id — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form BuilderCWE-639 5.3 Medium2025-12-06
CVE-2025-13894 CSV Sumotto <= 1.0 - Reflected Cross-Site Scripting — CSV SumottoCWE-79 6.1 Medium2025-12-06
CVE-2025-13308 Application Passwords <= 0.1.3 - Reflected Cross-Site Scripting via reject_url — Application PasswordsCWE-79 5.4 Medium2025-12-06
CVE-2025-13666 Helloprint <= 2.1.2 - Missing Authorization to Unauthenticated Arbitrary Order Status Modification — Plug your WooCommerce into the largest catalog of customized print products from HelloprintCWE-862 5.3 Medium2025-12-06
CVE-2025-12673 Flex QR Code Generator <= 1.2.7 - Unauthenticated Arbitrary File Upload — Flex QR Code GeneratorCWE-434 9.8 Critical2025-12-06
CVE-2025-13629 WP Landing Page <= 0.9.3 - Cross-Site Request Forgery to Arbitrary Post Meta Update — WP Landing PageCWE-352 4.3 Medium2025-12-06
CVE-2025-12720 g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion — g-FFL CockpitCWE-285 5.3 Medium2025-12-06
CVE-2025-12721 g-FFL Cockpit <= 1.7.1 - Missing Authorization to Unauthenticated Information Exposure — g-FFL CockpitCWE-862 5.3 Medium2025-12-06
CVE-2025-13137 Live Sales Notification for Woocommerce – Woomotiv <= 3.6.3 - Reflected Cross-Site Scripting — Live Sales Notification for Woocommerce – WoomotivCWE-79 6.1 Medium2025-12-06
CVE-2025-13626 myLCO <= 0.8.1 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — myLCOCWE-79 6.1 Medium2025-12-06
CVE-2025-11263 Link Whisper Free <= 0.8.8 - Reflected Cross-Site Scripting — Link Whisper FreeCWE-79 6.1 Medium2025-12-06
CVE-2025-12510 Widgets for Google Reviews <= 13.2.4 - Unauthenticated Stored Cross-Site Scripting via Google Reviews — Widgets for Google ReviewsCWE-79 7.2 High2025-12-06
CVE-2025-46603 Dell CloudBoost Virtual Appliance 安全漏洞 — CloudBoost Virtual ApplianceCWE-307 7.0 High2025-12-05
CVE-2020-36882 Flexsense DiskBoss Application Crash Denial of Service — DiskBossCWE-434 7.5 -2025-12-05
CVE-2020-36881 Flexsense DiskBoss 'Add Input Directory' Buffer Overflow — DiskBossCWE-119 8.4 -2025-12-05
CVE-2025-34256 Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass — WISE-DeviceOn ServerCWE-321 9.8 -2025-12-05
CVE-2020-36879 Flexsense DiskBoss Service Unquoted Service Path Vulnerability — DiskBossCWE-428 9.8 -2025-12-05
CVE-2020-36878 ReQuest Serious Play F3 Media Player <= 3.0.0 Directory Traversal File Disclosure — ReQuest Serious Play Media PlayerCWE-73 7.5 -2025-12-05
CVE-2020-36877 ReQuest Serious Play F3 Media Server <= 7.0.3 code execution — ReQuest Serious Play ProCWE-78 9.8 -2025-12-05
CVE-2020-36876 ReQuest Serious Play F3 Media Server <= 7.0.3 Debug Log Disclosure2020 — ReQuest Serious Play ProCWE-532 7.5 -2025-12-05

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.