Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18865

18865 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-13622 File Uploads Addon for WooCommerce <= 1.7.1 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — File Uploads Addon for WooCommerceCWE-200 7.5 High2025-02-18
CVE-2024-12314 Rapid Cache <= 1.2.3 - Unauthenticated Cache Poisoning — Rapid CacheCWE-524 7.2 High2025-02-18
CVE-2024-13535 Actionwear products sync <= 2.3.2 - Unauthenticated Full Patch Disclosure — Actionwear products syncCWE-209 5.3 Medium2025-02-18
CVE-2024-13725 Keap Official Opt-in Forms <= 2.0.1 - Unauthenticated Limited Local File Inclusion — Keap Official Opt-in FormsCWE-22 9.8 Critical2025-02-18
CVE-2024-13540 WooODT Lite – Delivery & pickup date time location for WooCommerce <= 2.5.1 - Unauthenticated Full Path Dsiclosure — WooODT Lite – Delivery & pickup date time location for WooCommerceCWE-209 5.3 Medium2025-02-18
CVE-2024-13852 Option Editor <= 1.0 - Cross-Site Request Forgery to Arbitrary Options Update — Option EditorCWE-352 8.8 High2025-02-18
CVE-2025-0796 Mortgage Lead Capture System <= 8.2.11 - Cross-Site Request Forgery to Settings Reset — WPrequalCWE-352 4.3 Medium2025-02-18
CVE-2024-13684 Reset <= 1.6 - Cross-Site Request Forgery to Database Reset — ResetCWE-352 8.1 High2025-02-18
CVE-2024-13538 BigBuy Dropshipping Connector for WooCommerce <= 2.0.0 - Unauthenticated Full Path Disclosute — BigBuy Dropshipping Connector for WooCommerceCWE-209 5.3 Medium2025-02-18
CVE-2024-13522 magayo Lottery Results <= 2.0.12 - Cross-Site Request Forgery to Stored Cross-Site Scripting — magayo Lottery ResultsCWE-352 6.1 Medium2025-02-18
CVE-2025-21103 Dell NetWorker Management Console 安全漏洞 — NetWorker Management ConsoleCWE-97 7.8 High2025-02-17
CVE-2024-13726 Themes Coder <= 1.3.4 - Unauthenticated SQLi — Themes Coder 9.8 -2025-02-17
CVE-2024-13603 Wise Forms <= 1.2.0 - Unauthenticated Stored XSS — Wise Forms 6.1 -2025-02-17
CVE-2025-0924 WP Activity Log <= 5.2.2 - Unauthenticated Stored Cross-Site Scripting — WP Activity LogCWE-79 7.2 High2025-02-17
CVE-2025-1387 Learning Digital Orca HCM - Improper Authentication — Orca HCMCWE-1390 9.8 Critical2025-02-17
CVE-2024-13488 LTL Freight Quotes – Estes Edition <= 3.3.7 - Unauthenticated SQL Injection — LTL Freight Quotes – Estes EditionCWE-89 7.5 High2025-02-15
CVE-2024-10581 DirectoryPress Frontend <= 2.7.9 - Cross-Site Request Forgery to Listing Status Update — DirectoryPress FrontendCWE-352 4.3 Medium2025-02-15
CVE-2024-12562 s2Member Pro <= 241216 - Unauthenticated PHP Object Injection — s2Member ProCWE-502 9.8 Critical2025-02-15
CVE-2024-13513 Oliver POS – A WooCommerce Point of Sale (POS) <= 2.4.2.3 - Sensitive Information Exposure to Privilege Escalation — Oliver POS – A WooCommerce Point of Sale (POS)CWE-862 9.8 Critical2025-02-15
CVE-2022-26083 Intel IPP Cryptography 安全漏洞 — Intel(R) IPP Cryptography software library 7.5 High2025-02-14
CVE-2024-13641 Return Refund and Exchange For WooCommerce <= 4.4.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — Return Refund and Exchange For WooCommerceCWE-200 5.9 Medium2025-02-14
CVE-2024-13692 Return Refund and Exchange For WooCommerce <= 4.4.5 - Authenticated (Subscriber+) Insecure Direct Object Reference — Return Refund and Exchange For WooCommerceCWE-285 5.4 Medium2025-02-14
CVE-2024-57725 Arcadyan Livebox Fibra PRV3399B_B_LT 安全漏洞 — n/a 6.5 -2025-02-14
CVE-2025-24865 mySCADA myPRO Manager Missing Authentication for Critical Function — myPRO ManagerCWE-306 10.0 Critical2025-02-13
CVE-2024-12011 Nozomi Networks TCP/IP Gateway 安全漏洞 — 130.8005CWE-126 7.6 High2025-02-13
CVE-2025-0426 Kubernetes 安全漏洞 — kubeletCWE-400 6.2 Medium2025-02-13
CVE-2024-13182 WP Directorybox Manager <= 2.5 - Authentication Bypass — WP Directorybox ManagerCWE-288 9.8 Critical2025-02-13
CVE-2024-13606 JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.8 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — JS Help Desk – AI-Powered Support & Ticketing SystemCWE-200 7.5 High2025-02-13
CVE-2024-13867 Listivo - Classified Ads WordPress Theme <= 2.3.67 - Reflected Cross-Site Scripting — Listivo - Classified Ads WordPress ThemeCWE-79 6.1 Medium2025-02-13
CVE-2024-13345 Avada Builder <= 3.11.13 - Unauthenticated Arbitrary Shortcode Execution — Avada (Fusion) BuilderCWE-94 7.3 High2025-02-13

Vulnerabilities classified as access:pre-auth represent 18865 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.