Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-13494 SSP Debug <= 1.0.0 - Unauthenticated Sensitive Information Exposure — SSP DebugCWE-200 5.3 Medium2025-12-05
CVE-2025-11759 Backup, Restore and Migrate your sites with XCloner <= 4.8.2 - Cross-Site Request Forgery in Xcloner_Remote_Storage:save() — Backup, Restore and Migrate your sites with XClonerCWE-352 4.3 Medium2025-12-05
CVE-2025-64052 Fanvil x210 安全漏洞 — n/a 7.8 -2025-12-05
CVE-2025-64056 Fanvil x210 安全漏洞 — n/a 7.1 -2025-12-05
CVE-2025-64057 Fanvil x210 安全漏洞 — n/a 7.8 -2025-12-05
CVE-2025-1545 WatchGuard Firebox XPath Injection Vulnerability in Web CGI — Fireware OSCWE-91 7.5AIHighAI2025-12-04
CVE-2025-11838 WatchGuard Firebox iked Memory Corruption Vulnerability — Fireware OSCWE-763 7.5AIHighAI2025-12-04
CVE-2025-65959 Open WebUI vulnerable to Stored DOM XSS via Note 'Download PDF' — open-webuiCWE-79 8.7 High2025-12-04
CVE-2025-66576 Remote Keyboard Desktop 1.0.1 - Remote Code Execution (RCE) — Remote Keyboard DesktopCWE-78 9.8AICriticalAI2025-12-04
CVE-2025-66573 Solstice Pod API Session Key Extraction via API Endpoint — Solstice Pod API Session Key Extraction via API EndpointCWE-319 7.5AIHighAI2025-12-04
CVE-2025-66572 Loaded Commerce 6.6 Client-Side Template Injection(CSTI) — Loaded CommerceCWE-78 9.8AICriticalAI2025-12-04
CVE-2025-66571 UNA CMS 9.0.0-RC1 - 14.0.0-RC4 PHP Object Injection — UNA CMSCWE-502 9.8AICriticalAI2025-12-04
CVE-2025-66555 AirKeyboard iOS App 1.0.5 - Remote Input Injection — AirKeyboard iOS AppCWE-306 9.8AICriticalAI2025-12-04
CVE-2024-58277 R Radio Network FM Transmitter 1.07 System Settings Disclosure — Radio Network FM TransmitterCWE-312 9.8AICriticalAI2025-12-04
CVE-2024-58276 Obi08-Enrollment System 1.0 login.php SQL Injection — Obi08/Enrollment SystemCWE-89 9.1AICriticalAI2025-12-04
CVE-2023-53735 WEBIGniter 28.7.23 Cross-Site Scripting (XSS) in User Creation Process — WEBIGniterCWE-79 6.1AIMediumAI2025-12-04
CVE-2023-53734 dawa-pharma-1.0 - SQL Injection via Email Parameter — dawa-pharmaCWE-89 9.8AICriticalAI2025-12-04
CVE-2025-12995 Medtronic CareLink Network 安全漏洞 — CareLink NetworkCWE-307 8.1 High2025-12-04
CVE-2025-12994 Medtronic CareLink Network 安全漏洞 — CareLink NetworkCWE-204 5.3 Medium2025-12-04
CVE-2025-14012 JIZHICMS Batch Delete Comments deleteAll.html delete sql injection — JIZHICMSCWE-89 4.7 Medium2025-12-04
CVE-2025-13513 Clik stats <= 0.8 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — Clik statsCWE-79 6.1 Medium2025-12-04
CVE-2025-11727 Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration - Powered by Codisto <= 1.3.65 - Unauthenticated Stored Cross-Site Scripting — Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by CodistoCWE-79 7.2 High2025-12-04
CVE-2025-11379 WebP Express <= 0.25.9 - Unauthenticated Information Exposure — WebP ExpressCWE-200 5.3 Medium2025-12-04
CVE-2025-63363 Waveshare RS232/485 TO WIFI ETH (B) 安全漏洞 — n/a 5.3AIMediumAI2025-12-04
CVE-2025-65899 Kalmia 安全漏洞 — n/a 5.3AIMediumAI2025-12-04
CVE-2025-12819 Untrusted search path in auth_query connection in PgBouncer — PgBouncerCWE-426 7.5 High2025-12-03
CVE-2025-20384 Unauthenticated Log Injection in Splunk Enterprise — Splunk EnterpriseCWE-117 5.3 Medium2025-12-03
CVE-2025-34319 TOTOLINK N300RT <= V2.1.8-B20201030.1539 Boa formWsc RCE — N300RTCWE-78 9.8AICriticalAI2025-12-03
CVE-2024-32641 Masa CMS Vulnerable to Pre-Auth RCE via JSON API — MasaCMSCWE-94 9.8 Critical2025-12-03
CVE-2025-13390 WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover — WP Directory KitCWE-303 10.0 Critical2025-12-03

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.