Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18942

18942 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-13682 Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery — Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription PaymentsCWE-352 4.3 Medium2025-03-04
CVE-2025-1306 Newscrunch <= 1.8.4 - Cross-Site Request Forgery to Arbitrary File Upload — NewscrunchCWE-352 8.8 High2025-03-04
CVE-2025-0912 GiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection — GiveWP – Donation Plugin and Fundraising PlatformCWE-502 9.8 Critical2025-03-04
CVE-2024-50704 Uniguest Tripleplay 代码注入漏洞 — n/a 9.8 -2025-03-04
CVE-2024-50705 Uniguest Tripleplay 跨站请求伪造漏洞 — n/a 6.1 -2025-03-04
CVE-2024-50706 Uniguest Tripleplay SQL注入漏洞 — n/a 9.8 -2025-03-04
CVE-2024-50707 Uniguest Tripleplay 代码注入漏洞 — n/a 9.8 -2025-03-04
CVE-2024-51961 Local file inclusion (LFI) vulnerability in ArcGIS Server — ArcGIS ServerCWE-73 7.5 High2025-03-03
CVE-2025-27419 Denial of Service (DoS) in WeGIA due to Recursive Crawling of Dynamic URLs — WeGIACWE-770 7.5 -2025-03-03
CVE-2025-24023 Observable Response Discrepancy in flask-appbuilder — Flask-AppBuilderCWE-204 3.7 Low2025-03-03
CVE-2025-25280 Century Systems FutureNet AS series和Century Systems FutureNet FA series 安全漏洞 — FutureNet AS-250/SCWE-120 5.3 Medium2025-03-03
CVE-2025-24846 Century Systems FutureNet AS series 安全漏洞 — FutureNet AS-250/SCWE-288 7.5 High2025-03-03
CVE-2025-27590 Oxidized Web 路径遍历漏洞 — Oxidized WebCWE-22 9.0 Critical2025-03-03
CVE-2025-1404 Secure Copy Content Protection and Content Locking <= 4.4.7 - Missing Authorization to Unauthenticated User Email Retrieval via ays_sccp_reports_user_search Function — Secure Copy Content Protection and Content LockingCWE-862 5.3 Medium2025-03-01
CVE-2024-13697 Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.7.4 - Unauthenticated Limited Server-Side Request Forgery in nice_links — Better Messages – Live Chat, Chat Rooms, Real-Time Messaging & Private MessagesCWE-918 4.8 Medium2025-03-01
CVE-2024-13611 Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.6.9 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — Better Messages – Live Chat, Chat Rooms, Real-Time Messaging & Private MessagesCWE-200 7.5 High2025-03-01
CVE-2024-13806 Authors List <= 2.0.6 - Unauthenticated Arbitrary Shortcode Execution — Authors ListCWE-94 6.5 Medium2025-03-01
CVE-2025-1564 SetSail Membership <= 1.0.3 - Authentication Bypass via Account Takeover — SetSail MembershipCWE-288 9.8 Critical2025-03-01
CVE-2025-1671 Academist Membership <= 1.1.6 - Authentication Bypass via Account Takeover — Academist MembershipCWE-288 9.8 Critical2025-03-01
CVE-2025-1638 Alloggio Membership <= 1.1 - Authentication Bypass via Social Login Account Takeover — Alloggio MembershipCWE-288 9.8 Critical2025-03-01
CVE-2025-1502 IP2Location Redirection <= 1.33.3 - Missing Authorization to Unauthenticated Settings Export — IP2Location RedirectionCWE-862 5.3 Medium2025-03-01
CVE-2024-13373 Exertio Framework <= 1.3.1 - Unauthenticated Arbitrary User Password Update — Exertio FrameworkCWE-620 8.1 High2025-03-01
CVE-2024-12824 Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change — Nokri – Job Board WordPress ThemeCWE-620 9.8 Critical2025-03-01
CVE-2024-9212 SKU Generator for WooCommerce <= 1.6.2 - Reflected Cross-Site Scripting — SKU Generator for WooCommerceCWE-79 6.1 Medium2025-03-01
CVE-2024-13518 Simple:Press <= 6.10.12 - Cross-Site Request Forgery to Unauthorized Post Editing — Simple:Press ForumCWE-352 4.3 Medium2025-03-01
CVE-2024-13746 Booking Calendar and Notification <= 4.0.3 - Missing Authorization via wpcb_all_bookings, wpcb_update_booking_post, and wpcb_delete_posts Functions — Booking Calendar and NotificationCWE-862 6.5 Medium2025-03-01
CVE-2024-9217 Currency Switcher for WooCommerce <= 2.16.2 - Reflected Cross-Site Scripting — Currency Switcher for WooCommerceCWE-79 6.1 Medium2025-03-01
CVE-2024-13568 Fluent Support – Helpdesk & Customer Support Ticket System <= 1.8.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — Fluent Support – Helpdesk & Customer Support Ticket SystemCWE-200 7.5 High2025-03-01
CVE-2025-23405 Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Improper Output Neutralization For Logs — USB-C Blood Glucose Monitoring System Starter Kit Android ApplicationsCWE-117 5.3 Medium2025-02-28
CVE-2025-1319 Site Mailer <= 1.2.3 - Unauthenticated Stored Cross-Site Scripting — Site Mailer – SMTP Replacement, Email API Deliverability & Email LogCWE-79 7.2 High2025-02-28

Vulnerabilities classified as access:pre-auth represent 18942 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.