Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-30255 Intel PROSet/Wireless WiFi 缓冲区错误漏洞 — Intel(R) PROSet/Wireless WiFi Software for Windows 8.2 High2025-11-11
CVE-2025-24834 Intel CIP 安全漏洞 — Intel(R) CIP software 6.5 Medium2025-11-11
CVE-2025-33185 NVIDIA AIStore 安全漏洞 — AuthN component of NVIDIA AIStoreCWE-862 5.3 Medium2025-11-11
CVE-2025-12942 Improper input validation in NETGEAR R6260 and R6850 — R6260CWE-20 7.5 -2025-11-11
CVE-2025-8324 SQL Injection — ManageEngine Analytics PlusCWE-89 9.8 Critical2025-11-11
CVE-2025-12788 Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Missing Payment Verification to Unauthenticated Payment Bypass — Hydra Booking — Appointment Scheduling & Booking CalendarCWE-602 5.3 Medium2025-11-11
CVE-2025-12787 Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash Generation — Hydra Booking — Appointment Scheduling & Booking CalendarCWE-330 5.3 Medium2025-11-11
CVE-2025-12539 TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover — TNC Toolbox: Web PerformanceCWE-922 10.0 Critical2025-11-11
CVE-2025-11307 WP Google Maps < 9.0.48 - Unauthenticated Stored XSS — WP Go Maps (formerly WP Google Maps) 6.1 -2025-11-11
CVE-2025-11521 Astra Security Suite – Firewall & Malware Scan <= 0.2 - Unauthenticated Arbitrary File Upload — Astra Security Suite – Firewall & Malware ScanCWE-285 8.1 High2025-11-11
CVE-2025-11999 Add Multiple Marker <= 1.2 - Missing Authorization to Unauthenticated Settings Update — Multi Location MarkerCWE-862 5.3 Medium2025-11-11
CVE-2025-11986 Crypto Tool <= 2.22 - Unauthenticated Information Exposure via Global Authentication State — Crypto ToolCWE-306 5.3 Medium2025-11-11
CVE-2025-11532 Wisly <= 1.0.0 - Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation — WislyCWE-639 5.3 Medium2025-11-11
CVE-2025-11170 WP移行専用プラグイン for CPI <= 1.0.2 - Unauthenticated Arbitrary File Upload — WP移行専用プラグイン for CPICWE-434 9.8 Critical2025-11-11
CVE-2025-11457 EasyCommerce – AI-Powered, Blazing-Fast & Beautiful WordPress Ecommerce Plugin 0.9.0-beta2 - 1.8.2 - Unauthenticated Privilege Escalation — EasyCommerce – AI-Powered WordPress Ecommerce Plugin to Sell Digital Products, Subscriptions & Physical GoodsCWE-269 9.8 Critical2025-11-11
CVE-2025-12813 Holiday class post calendar <= 7.1 - Unauthenticated Remote Code Execution via 'contents' — Holiday class post calendarCWE-94 9.8 Critical2025-11-11
CVE-2025-12021 WP-OAuth <= 0.4.1 - Reflected Cross-Site Scripting — WP-OAuthCWE-79 6.1 Medium2025-11-11
CVE-2025-12588 USB Qr Code Scanner For Woocommerce <= 1.0.0 - Cross-Site Request Forgery to Settings Update — USB Qr Code Scanner For WoocommerceCWE-352 4.3 Medium2025-11-11
CVE-2025-12590 YSlider <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting — YSliderCWE-352 6.1 Medium2025-11-11
CVE-2025-12132 WP Custom Admin Login Page Logo <= 1.4.8.4 - Cross-Site Request Forgery to Settings Update — WP Custom Admin Login Page LogoCWE-352 4.3 Medium2025-11-11
CVE-2025-11997 Document Pro Elementor – Documentation & Knowledge Base <= 1.0.9 - Unauthenticated Information Exposure — Document Pro Elementor – Documentation & Knowledge BaseCWE-200 5.3 Medium2025-11-11
CVE-2025-12589 WP-Walla <= 0.5.3.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting — WP-WallaCWE-352 6.1 Medium2025-11-11
CVE-2025-11451 Auto Amazon Links – Amazon Associates Affiliate Plugin <= 5.4.3 - Unauthenticated Arbitrary File Read — Auto Amazon Links – Amazon Associates Affiliate PluginCWE-73 7.5 High2025-11-11
CVE-2025-11886 CTL Arcade Lite <= 1.0 - Cross-Site Request Forgery to Plugin Activation and Deactivation — CTL Arcade LiteCWE-352 4.3 Medium2025-11-11
CVE-2025-11996 Find Unused Images <= 1.0.7 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion — Find Unused ImagesCWE-862 5.3 Medium2025-11-11
CVE-2025-11988 Crypto Tool <= 2.22 - Missing Authentication to Unauthenticated Limited File Deletion — Crypto ToolCWE-862 5.3 Medium2025-11-11
CVE-2025-11891 Shelf Planner <= 2.8.1 - Unauthenticated Information Exposure via Log Files — Shelf Planner Inventory Management for WooCommerceCWE-538 5.3 Medium2025-11-11
CVE-2025-11894 Shelf Planner <= 2.8.1 - Missing Authorization to Unauthenticated Settings Update — Shelf Planner Inventory Management for WooCommerceCWE-862 5.3 Medium2025-11-11
CVE-2025-42924 Open Redirect vulnerabilities in SAP S/4HANA landscape (SAP E-Recruiting BSP) — SAP S/4HANA landscape (SAP E-Recruiting BSP)CWE-601 6.1 Medium2025-11-11
CVE-2025-42919 Information Disclosure vulnerability in SAP NetWeaver Application Server Java — SAP NetWeaver Application Server JavaCWE-22 5.3 Medium2025-11-11

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.