Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-12406 Project Honey Pot Spam Trap <= 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Project Honey Pot Spam TrapCWE-352 6.1 Medium2025-11-18
CVE-2025-12173 WP Admin Microblog <= 3.1.1 - Cross-Site Request Forgery to Message Creation — WP Admin MicroblogCWE-352 4.3 Medium2025-11-18
CVE-2025-12937 ACF Flexible Layouts Manager <= 1.1.6 - Missing Authorization to Unauthenticated Custom Field Update — ACF Flexible Layouts ManagerCWE-862 6.5 Medium2025-11-18
CVE-2025-12404 Like-it <= 2.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Like-itCWE-352 6.1 Medium2025-11-18
CVE-2025-12827 Top Friends <= 0.3 - Cross-Site Request Forgery to Settings Update — Top FriendsCWE-352 4.3 Medium2025-11-18
CVE-2025-9625 Coil Web Monetization <= 2.0.2 - Cross-Site Request Forgery — Coil Web MonetizationCWE-352 4.3 Medium2025-11-18
CVE-2025-12528 Pie Forms for WP <= 1.6 - Unauthenticated Arbitrary File Upload — Pie Forms — Drag & Drop Form BuilderCWE-434 8.1 High2025-11-18
CVE-2025-12974 Gravity Forms <= 2.9.21.1 - Unauthenticated Arbitrary File Upload via Legacy Chunked Upload — Gravity FormsCWE-434 8.1 High2025-11-18
CVE-2025-63228 DB Electronica Mozart FM Transmitter 安全漏洞 — n/a 9.8AICriticalAI2025-11-18
CVE-2025-63408 iSpy Agent DVR 安全漏洞 — n/a 7.8AIHighAI2025-11-18
CVE-2025-64076 cbor2 安全漏洞 — n/a 7.5 High2025-11-18
CVE-2025-13165 Digiwin|EasyFlow GP - Denial of service — EasyFlow GPCWE-770 7.5 High2025-11-17
CVE-2025-9501 W3 Total Cache < 2.8.13 - Unauthenticated Command Injection — W3 Total Cache 9.8AICriticalAI2025-11-17
CVE-2025-13284 ThinPLUS|ThinPLUS - OS Command Injection — ThinPLUSCWE-78 9.8 Critical2025-11-17
CVE-2025-13283 Chunghwa Telecom|TenderDocTransfer - Arbitrary File Copy and Paste — TenderDocTransferCWE-352 7.1 High2025-11-17
CVE-2025-13282 Chunghwa Telecom|TenderDocTransfer - Arbitrary File Delete — TenderDocTransferCWE-352 8.1 High2025-11-17
CVE-2025-12482 Booking for Appointments and Events Calendar – Amelia <= 1.2.35 - Unauthenticated SQL Injection via search — Booking for Appointments and Events Calendar – AmeliaCWE-89 7.5 High2025-11-16
CVE-2025-12849 Contest Gallery <= 28.0.2 - Missing Authorization — Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & StripeCWE-862 5.3 Medium2025-11-15
CVE-2025-64309 Brightpick Mission Control / Internal Logic Control Unprotected Transport of Credentials — Brightpick Mission Control / Internal Logic ControlCWE-523 8.6 High2025-11-14
CVE-2021-4469 Denver SHO-110 IP Camera Unauthenticated Snapshot Access — SHO-110CWE-306 7.5 -2025-11-14
CVE-2021-4468 PLANEX CS-QP50F-ING2 Smart Camera Remote Configuration Disclosure — CS-QP50F-ING2CWE-306 9.8 -2025-11-14
CVE-2021-4467 Positive Technologies MaxPatrol 8 & XSpider Remote DoS — MaxPatrol 8 (Server)CWE-400 7.5 -2025-11-14
CVE-2021-4465 ReQuest Serious Play F3 Media Server <= 7.0.3 Remote DoS — ReQuest Serious Play ProCWE-400 7.5 -2025-11-14
CVE-2023-7328 Screen SFT DAB 600/C <= 1.9.3 Unauthenticated Information Disclosure — Screen SFT DAB 600/CCWE-306 7.5 -2025-11-14
CVE-2021-4470 TG8 Firewall Unauthenticated RCE via runphpcmd.php — TG8 FirewallCWE-78 9.8 -2025-11-14
CVE-2021-4471 TG8 Firewall Unauthenticated User Password Disclosure — TG8 FirewallCWE-538 7.5 -2025-11-14
CVE-2016-15056 Ubee EVW3226 Unauthenticated Backup File Disclosure — Ubee EVW3226CWE-538 9.8 -2025-11-14
CVE-2022-4985 Vodafone H500s WiFi Password Disclosure via activation.json — Vodafone H500sCWE-497 7.5 -2025-11-14
CVE-2025-55070 Lack of MFA enforcement in WebSocket connections — MattermostCWE-306 6.5 Medium2025-11-14
CVE-2025-13161 IQ Service International|IQ-Support - Arbitrary File Read — IQ-SupportCWE-23 7.5 High2025-11-14

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.