Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18857

18857 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-13746 Booking Calendar and Notification <= 4.0.3 - Missing Authorization via wpcb_all_bookings, wpcb_update_booking_post, and wpcb_delete_posts Functions — Booking Calendar and NotificationCWE-862 6.5 Medium2025-03-01
CVE-2024-9217 Currency Switcher for WooCommerce <= 2.16.2 - Reflected Cross-Site Scripting — Currency Switcher for WooCommerceCWE-79 6.1 Medium2025-03-01
CVE-2024-13568 Fluent Support – Helpdesk & Customer Support Ticket System <= 1.8.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — Fluent Support – Helpdesk & Customer Support Ticket SystemCWE-200 7.5 High2025-03-01
CVE-2025-23405 Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Improper Output Neutralization For Logs — USB-C Blood Glucose Monitoring System Starter Kit Android ApplicationsCWE-117 5.3 Medium2025-02-28
CVE-2025-1319 Site Mailer <= 1.2.3 - Unauthenticated Stored Cross-Site Scripting — Site Mailer – SMTP Replacement, Email API Deliverability & Email LogCWE-79 7.2 High2025-02-28
CVE-2024-8420 DHVC Form <= 2.4.7 - Unauthenticated Privilege Escalation — DHVC FormCWE-266 9.8 Critical2025-02-28
CVE-2025-1570 Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.1 - Privilege Escalation and Account Takeover via Weak OTP — Directorist: AI-Powered Business Directory, Listings & Classified AdsCWE-640 8.1 High2025-02-28
CVE-2024-8425 WooCommerce Ultimate Gift Card <= 2.9.2 - Unauthenticated Arbitrary File Upload — WooCommerce Ultimate Gift CardCWE-434 9.8 Critical2025-02-28
CVE-2024-13638 Order Attachments for WooCommerce <= 2.5.1 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — Order Attachments for WooCommerceCWE-200 5.9 Medium2025-02-28
CVE-2024-9193 WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update — WHMpress - WHMCS WordPress Integration PluginCWE-98 9.8 Critical2025-02-28
CVE-2025-1506 Wp Social Login and Register Social Counter <= 3.1.0 - Cross-Site Request Forgery to Settings Update — Wp Social Login and Register Social CounterCWE-352 4.3 Medium2025-02-28
CVE-2025-1513 Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting — Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & StripeCWE-79 7.2 High2025-02-28
CVE-2025-1511 User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.0.4 - Reflected Cross-Site Scripting — User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login BuilderCWE-79 6.1 Medium2025-02-28
CVE-2025-0801 RateMyAgent Official <= 1.4.0 - Cross-Site Request Forgery to API Key Update — RateMyAgent OfficialCWE-352 4.3 Medium2025-02-28
CVE-2025-1505 Advanced AJAX Product Filters <= 1.6.8.1 - Reflected Cross-Site Scripting — Advanced AJAX Product FiltersCWE-79 6.1 Medium2025-02-28
CVE-2024-13796 Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure — Post GridCWE-200 5.3 Medium2025-02-28
CVE-2025-1687 Cardealer <= 1.6.4 - Cross-Site Request Forgery to User Update via update_user_profile — Car Dealer Automotive WordPress Theme – ResponsiveCWE-352 8.8 High2025-02-27
CVE-2025-1717 Login Me Now <= 1.7.2 - Authentication Bypass — Login Me Now – Passwordless, Magic Link, OTP & Social Login for WordPressCWE-288 8.1 High2025-02-27
CVE-2024-13647 School Management System – SakolaWP <= 1.0.8 - Cross-Site Request Forgery to Exam Setting Manipulation — School Management System – SakolaWPCWE-352 4.3 Medium2025-02-27
CVE-2024-13905 OneStore Sites <= 0.1.1 - Unauthenticated Blind Server-Side Request Forgery — OneStore SitesCWE-918 5.3 Medium2025-02-27
CVE-2024-53944 Tuoshi LT15D 安全漏洞 — n/a 9.8 -2025-02-27
CVE-2025-0941 MET ONE 3400+ Potential Credential Exposure — MET ONE 3400+CWE-209 5.8 Medium2025-02-26
CVE-2025-20111 Cisco Nexus 3000 and 9000 Series Switches Layer 2 Ethernet Denial of Service Vulnerability — Cisco NX-OS SoftwareCWE-1220 7.4 High2025-02-26
CVE-2025-0719 IBM Cloud Pak for Data cross-site scripting — Cloud Pak for DataCWE-79 6.1 Medium2025-02-26
CVE-2025-0731 SMA: Sunny Portal Remote Code Execution — www.sunnyportal.comCWE-434 6.5 Medium2025-02-26
CVE-2024-13560 Subscriptions & Memberships for PayPal <= 1.1.6 - Cross-Site Request Forgery to Arbitrary Post Deletion — Subscriptions & Memberships for PayPalCWE-352 4.3 Medium2025-02-26
CVE-2024-12434 SureMembers <= 1.10.6 - Sensitive Information Exposure — SureMembersCWE-200 5.3 Medium2025-02-26
CVE-2024-30150 An unauthenticated privilege escalation vulnerability affects HCL MyCloud — MyCloudCWE-269 5.3 Medium2025-02-25
CVE-2024-45424 Zoom Workplace Apps - Business Logic Error — Zoom Workplace AppsCWE-840 5.3 Medium2025-02-25
CVE-2025-21627 GLPI Cross-site Scripting vulnerability — glpiCWE-79 6.5 Medium2025-02-25

Vulnerabilities classified as access:pre-auth represent 18857 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.