Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-51741 Echo 安全漏洞 — n/a 7.5AIHighAI2025-11-25
CVE-2025-64066 Primakon Pi Portal 安全漏洞 — n/a 9.8AICriticalAI2025-11-25
CVE-2023-7330 Ruijie Networks NBR Routers Unauthenticated Arbitrary File Upload via fileupload.php — NBR Series RoutersCWE-434 9.8AICriticalAI2025-11-24
CVE-2024-14007 TVT NVMS-9000 < 1.3.4 Unauthenticated Administrative Queries & Information Disclosure — NVMS-9000CWE-306 9.8AICriticalAI2025-11-24
CVE-2018-25126 TVT NVMS-9000 Hard-coded API Credentials & Command Injection — NVMS-9000CWE-798 9.8AICriticalAI2025-11-24
CVE-2025-12969 CVE-2025-12969 — Fluent Bit 5.3AIMediumAI2025-11-24
CVE-2025-41729 DoS via Modbus Read Command — UMG 96-PACWE-1287 7.5 High2025-11-24
CVE-2025-13596 Improper Error Handling Leading to Sensitive Information Disclosure in CIGES ≤ 2.15.6 — CIGESCWE-209 5.3AIMediumAI2025-11-24
CVE-2025-12394 Backup Migration < 2.0.0 - Unauthenticated Backup Download — Backup Migration 5.3AIMediumAI2025-11-24
CVE-2025-7402 Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.95 - Unauthenticated SQL Injection via site_id — Ads Pro Plugin - Multi-Purpose WordPress Advertising ManagerCWE-89 7.5 High2025-11-24
CVE-2025-13589 Otsuka Information Technology|FMS - Reflected Cross-site Scripting — FMSCWE-79 6.1AIMediumAI2025-11-24
CVE-2025-63435 Xtool AnyScan App 安全漏洞 — n/a 7.5AIHighAI2025-11-24
CVE-2025-63958 Millensys Vision Tools Workspace 安全漏洞 — n/a 9.8AICriticalAI2025-11-24
CVE-2025-13562 D-Link DIR-852 gena.cgi command injection — DIR-852CWE-77 7.3 High2025-11-23
CVE-2025-13526 OneClick Chat to Order <= 1.0.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure — OneClick Chat to OrderCWE-200 7.5 High2025-11-22
CVE-2025-13318 Booking Calendar Contact Form <= 1.2.60 - Missing Authorization to Unauthenticated Arbitrary Booking Confirmation via 'dex_bccf_ipn' Parameter — Booking Calendar Contact FormCWE-862 5.3 Medium2025-11-22
CVE-2025-12752 Subscriptions & Memberships for PayPal <= 1.1.7 - Unauthenticated Fake Payment Creation — Subscriptions & Memberships for PayPalCWE-345 5.3 Medium2025-11-22
CVE-2025-12877 IDonate – Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to Unauthenticated Arbitrary Post Deletion — IDonate – Blood Donation, Request And Donor Management SystemCWE-862 5.3 Medium2025-11-22
CVE-2025-13384 CP Contact Form with PayPal <= 1.3.56 - Missing Authorization to Unauthenticated Arbitrary Payment Confirmation — CP Contact Form with PayPalCWE-862 7.5 High2025-11-22
CVE-2025-13317 Appointment Booking Calendar <= 1.3.96 - Missing Authorization to Arbitrary Booking Confirmation via 'cpabc_ipncheck' Parameter — Appointment Booking CalendarCWE-862 5.3 Medium2025-11-22
CVE-2025-11936 Potential DoS Vulnerability through Multiple KeyShareEntry with Same Group in TLS 1.3 ClientHello — wolfSSLCWE-20 7.5 -2025-11-21
CVE-2025-11933 DoS Vulnerability in wolfSSL TLS 1.3 CKS Extension — wolfSSLCWE-20 7.5 -2025-11-21
CVE-2025-11087 Zegen Core <= 2.0.1 - Cross-Site Request Forgery to Arbitrary File Upload — Zegen CoreCWE-352 8.8 High2025-11-21
CVE-2025-12747 Tainacan <= 1.0.0 - Unauthenticated Information Exposure — TainacanCWE-552 5.3 Medium2025-11-21
CVE-2025-13357 Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method — ToolingCWE-1188 7.4 High2025-11-21
CVE-2025-11127 Mstoreapp Mobile (App <= 2.08, Multivendor <= 9.0.1) - Unauthenticated Privilege Escalation — Mstoreapp Mobile App 7.5 -2025-11-21
CVE-2025-12160 Simple User Registration <= 6.6 - Unauthenticated Stored Cross-Site Scripting — Simple User RegistrationCWE-79 7.2 High2025-11-21
CVE-2025-13138 WP Directory Kit <= 1.4.3 - Unauthenticated SQL Injection via select_2_ajax() Function — WP Directory KitCWE-89 7.5 High2025-11-21
CVE-2025-12039 BigBuy Dropshipping Connector for WooCommerce <= 2.0.5 - Unauthenticated IP Spoofing to phpinfo() Exposure — BigBuy Dropshipping Connector for WooCommerceCWE-200 5.3 Medium2025-11-21
CVE-2025-11771 Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO <= 2.4.7 - Missing Authentication to Unauthenticated Presale Update — Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICOCWE-306 5.3 Medium2025-11-21

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.