Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-13160 IQ Service International|IQ-Support - Exposure of Sensitive Information — IQ-SupportCWE-497 5.3 Medium2025-11-14
CVE-2025-12904 SNORDIAN's H5PxAPIkatchu <= 0.4.17 - Unauthenticated Stored Cross-Site Scripting via insert_data — SNORDIAN's H5PxAPIkatchuCWE-79 7.2 High2025-11-14
CVE-2025-63891 SourceCodester Simple Online Book Store System 安全漏洞 — n/a 7.5 -2025-11-14
CVE-2025-4619 PAN-OS: Firewall Denial of Service (DoS) Using Specially Crafted Packets — Cloud NGFWCWE-754 7.5 -2025-11-13
CVE-2022-4984 ZenTao Biz < 6.5, Max < 3.0, & Open Source Edition 16.5/16.5beta1 SQL Injection via user-login.html — ZenTao BizCWE-89 7.5 -2025-11-13
CVE-2025-43515 Apple Compressor 安全漏洞 — Compressor 8.8 -2025-11-13
CVE-2025-20355 Cisco Catalyst Center Software HTTP Open Redirect Vulnerability — Cisco Digital Network Architecture Center (DNA Center)CWE-601 4.7 Medium2025-11-13
CVE-2025-20353 Cisco Catalyst Center Cross-Site Scripting Vulnerability — Cisco Digital Network Architecture Center (DNA Center)CWE-79 6.1 Medium2025-11-13
CVE-2025-64717 ZITADEL vulnerable to Account Takeover with deactivated Instance IdP — zitadelCWE-287 3.8 -2025-11-13
CVE-2025-64714 PrivateBin's template-switching feature allows arbitrary local file inclusion through path traversal — PrivateBinCWE-23 5.8 Medium2025-11-13
CVE-2025-62484 Zoom Workplace Clients - Inefficient Regular Expression Complexity — Zoom WorkplaceCWE-1333 8.1 High2025-11-13
CVE-2025-62483 Zoom Clients - Improper Removal of Sensitive Information — Zoom ClientsCWE-212 5.3 Medium2025-11-13
CVE-2025-62482 Zoom Workplace for Windows - Cross-site Scripting — Zoom WorkplaceCWE-79 4.3 Medium2025-11-13
CVE-2025-30669 Zoom Workplace Clients - Improper Certificate Validation — Zoom Workplace ClientsCWE-295 4.8 Medium2025-11-13
CVE-2025-64741 Zoom Workplace for Android - Improper Authorization Handling — Zoom Workplace for AndroidCWE-74 8.1 High2025-11-13
CVE-2025-64739 Zoom Clients - External Control of File Name or Path — Zoom ClientsCWE-73 4.3 Medium2025-11-13
CVE-2025-11260 WP Headless CMS Framework <= 1.15 - Unauthenticated Protection Mechanism Bypass — WP Headless CMS FrameworkCWE-693 5.3 Medium2025-11-13
CVE-2025-12681 Comment Edit Core – Simple Comment Editing <= 3.1.0 - Unauthenticated Sensitive Information Exposure — Comment Edit Core – Simple Comment EditingCWE-200 5.3 Medium2025-11-13
CVE-2025-12891 Survey Maker <= 5.1.9.4 - Missing Authorization to Unauthenticated Information Exposure — Survey MakerCWE-862 5.3 Medium2025-11-13
CVE-2025-12536 SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure — SureForms – Contact Form, Payment Form & Other Custom Form BuilderCWE-359 5.3 Medium2025-11-13
CVE-2025-12892 Survey Maker <= 5.1.9.4 - Missing Authorization to Unauthenticated Limited Option Update — Survey MakerCWE-862 5.3 Medium2025-11-13
CVE-2025-12979 Welcart e-Commerce <= 2.11.24 - Missing Authorization to Unauthenticated Information Exposure — Welcart e-CommerceCWE-862 5.3 Medium2025-11-13
CVE-2025-60672 D-Link DIR-878 安全漏洞 — n/a 9.8 -2025-11-13
CVE-2025-60673 D-Link DIR-878 安全漏洞 — n/a 9.8 -2025-11-13
CVE-2025-60676 D-Link DIR-878 安全漏洞 — n/a 9.8 -2025-11-13
CVE-2025-60682 TOTOLINK A720R 安全漏洞 — n/a 9.8 -2025-11-13
CVE-2025-60684 TOTOLINK LR1200GB 安全漏洞 — n/a 9.8 -2025-11-13
CVE-2025-60687 TOTOLINK LR1200GB 安全漏洞 — n/a 9.8 -2025-11-13
CVE-2025-60689 Linksys E1200 安全漏洞 — n/a 9.8 -2025-11-13
CVE-2025-60690 Linksys E1200 安全漏洞 — n/a 9.8 -2025-11-13

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.