Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-12123 Customer Reviews Collector for WooCommerce <= 4.6.1 - Reflected Cross-Site Scripting — Customer Reviews Collector for WooCommerceCWE-79 6.1 Medium2025-11-27
CVE-2025-13539 FindAll Membership <= 1.0.4 - Authentication Bypass via Social Login — FindAll MembershipCWE-288 9.8 Critical2025-11-27
CVE-2025-13540 Tiare Membership <= 1.2 - Unauthenticated Privilege Escalation — Tiare MembershipCWE-269 9.8 Critical2025-11-27
CVE-2025-13675 Tiger <= 101.2.1 - Unauthenticated Privilege Escalation — TigerCWE-269 9.8 Critical2025-11-27
CVE-2025-7820 SKT PayPal for WooCommerce <= 1.4 - Unauthenticated Payment Bypass — SKT PayPal for WooCommerceCWE-602 7.5 High2025-11-27
CVE-2025-13538 FindAll Listing <= 1.0.5 - Unauthenticated Privilege Escalation — FindAll ListingCWE-269 9.8 Critical2025-11-27
CVE-2025-12579 Reuters Direct <= 3.0.0 - Missing Authorization to Unauthenticated Settings Reset — Reuters DirectCWE-862 5.3 Medium2025-11-27
CVE-2025-12578 Reuters Direct <= 3.0.0 - Cross-Site Request Forgery to Settings Reset — Reuters DirectCWE-352 4.3 Medium2025-11-27
CVE-2025-66030 node-forge ASN.1 OID Integer Truncation — forgeCWE-190 9.1AICriticalAI2025-11-26
CVE-2025-66031 node-forge ASN.1 Unbounded Recursion — forgeCWE-674 7.5AIHighAI2025-11-26
CVE-2019-25227 Tellion HN-2204AP Unauthenticated Configuration Disclosure — HN-2204AP RouterCWE-306 9.8AICriticalAI2025-11-26
CVE-2020-36871 ESCAM QD-900 Unauthenticated Configuration Disclosure — QD-900 WIFI HD CameraCWE-306 9.1AICriticalAI2025-11-26
CVE-2019-25226 Dongyoung Media DM-AP240T/W Unauthenticated Configuration Disclosure — DM-AP240T/W Wireless Access PointCWE-306 9.8AICriticalAI2025-11-26
CVE-2020-36872 BACnet Test Server 1.01 Malformed BVLC Length DoS — BACnet Test ServerCWE-400 7.5AIHighAI2025-11-26
CVE-2020-36873 Astak CM-818T3 Unauthenticated Configuration Disclosure — CM-818T3 2.4GHz Wireless Security Surveillance CameraCWE-306 9.1AICriticalAI2025-11-26
CVE-2020-36874 ACE SECURITY WIP-90113 Unauthenticated Configuration Disclosure — WIP-90113 HD CameraCWE-306 9.1AICriticalAI2025-11-26
CVE-2025-12571 Allocation of Resources Without Limits or Throttling in GitLab — GitLabCWE-770 7.5 High2025-11-26
CVE-2025-12653 Authentication Bypass by Spoofing in GitLab — GitLabCWE-290 6.5 Medium2025-11-26
CVE-2025-64128 Zenitel TCIV-3+ OS Command Injection — TCIV-3+CWE-78 10.0 Critical2025-11-26
CVE-2025-64127 Zenitel TCIV-3+ OS Command Injection — TCIV-3+CWE-78 10.0 Critical2025-11-26
CVE-2025-64126 Zenitel TCIV-3+ OS Command Injection — TCIV-3+CWE-78 10.0 Critical2025-11-26
CVE-2025-9163 Houzez <= 4.1.6 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload — HouzezCWE-79 6.1 Medium2025-11-26
CVE-2025-12061 Tax Service Electronic HDM < 1.2.1 - Unauthenticated Arbitrary SQL Execution — TAX SERVICE Electronic HDM 9.8AICriticalAI2025-11-26
CVE-2025-66022 FACTION Unauthenticated Custom Extension Upload leads to RCE — factionCWE-829 9.7 Critical2025-11-26
CVE-2025-12848 XSS vulnerability when rendering filename in Webform Multiform — DrupalCWE-79 6.1AIMediumAI2025-11-26
CVE-2025-66263 Unauthenticated Arbitrary File Read via Null Byte Injection — Mozart FM TransmitterCWE-158 7.5AIHighAI2025-11-26
CVE-2025-66262 Arbitrary File Overwrite via Tar Extraction Path Traversal — Mozart FM TransmitterCWE-22 8.1AIHighAI2025-11-26
CVE-2025-66261 Unauthenticated OS Command Injection (restore_settings.php) — Mozart FM TransmitterCWE-78 9.8AICriticalAI2025-11-26
CVE-2025-66257 Unauthenticated Arbitrary File Deletion (patch_contents.php) — Mozart FM TransmitterCWE-73 6.5AIMediumAI2025-11-26
CVE-2025-66256 Unauthenticated Arbitrary File Upload (patch_contents.php) — Mozart FM TransmitterCWE-434 9.8AICriticalAI2025-11-26

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.