Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18866

18866 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-35145 IBM Maximo Application Suite cross-site scripting — Maximo Application SuiteCWE-79 6.1 Medium2025-01-25
CVE-2024-13562 Import WP – Export and Import CSV and XML files to WordPress <= 2.14.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — Import WP – Export and Import CSV and XML files to WordPressCWE-200 7.5 High2025-01-25
CVE-2024-12826 GoHero Store Customizer for WooCommerce <= 3.5 - Missing Authorization to Unuthenticated Settings Update — GoHero Store Customizer for WooCommerceCWE-862 4.3 Medium2025-01-25
CVE-2024-13467 WP Contact Form7 Email Spam Blocker <= 1.0.0 - Reflected Cross-Site Scripting — WP Contact Form7 Email Spam BlockerCWE-79 6.1 Medium2025-01-25
CVE-2024-12076 Target Video Easy Publish <= 3.8.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Target Video Easy PublishCWE-79 6.1 Medium2025-01-25
CVE-2024-13709 Linear <= 2.8.1 - Cross-Site Request Forgery to Cache Reset — LinearCWE-352 4.3 Medium2025-01-25
CVE-2025-0357 WPBookit <= 1.6.9 - Unauthenticated Arbitrary File Upload — WPBookitCWE-434 9.8 Critical2025-01-25
CVE-2024-13698 Jobify - Job Board WordPress Theme <= 4.2.7 - Missing Authorization to Unauthenticated Server-Side Request Forgery, Arbitrary Image Upload, and Image Generation — Jobify - Job Board WordPress ThemeCWE-862 6.5 Medium2025-01-24
CVE-2024-13545 Bootstrap Ultimate <= 1.4.9 - Unauthenticated Limited Local File Inclusion — Bootstrap UltimateCWE-22 9.8 Critical2025-01-24
CVE-2024-13683 Automate Hub Free by Sperse.IO <= 1.7.0 - Cross-Site Request Forgery to Activation Status Update — Automate Hub Free by Sperse.IOCWE-352 4.3 Medium2025-01-24
CVE-2025-23011 Fedora Repository archive extraction path traversal — Fedora RepositoryCWE-23 8.8 High2025-01-23
CVE-2024-12078 ECOVACS lawnmowers and vacuums static BLE GATT encryption key — Unspecified robotsCWE-321 6.3 Medium2025-01-23
CVE-2024-52330 ECOVACS lawnmowers and vacuums do not properly validate TLS certificates — DEEBOT X5 PRO PLUSCWE-295 7.4 High2025-01-23
CVE-2024-52329 ECOVACS HOME mobile app plugins do not properly validate TLS certificates — ECOVACS HOMECWE-295 7.4 High2025-01-23
CVE-2024-52325 ECOVACS robot lawnmowers and vacuums command injection — GOAT G1CWE-77 9.6 Critical2025-01-23
CVE-2025-0637 Inadequate access control in Beta10 — Beta10CWE-287 9.8 Critical2025-01-23
CVE-2025-23006 SonicWALL SMA1000 代码问题漏洞 — SMA1000CWE-502 9.8 -2025-01-23
CVE-2024-13422 SEO Blogger to WordPress Migration using 301 Redirection <= 0.4.8 - Reflected Cross-Site Scripting — SEO Blogger to WordPress Migration using 301 RedirectionCWE-79 6.1 Medium2025-01-23
CVE-2024-13234 Product Table by WBW <= 2.1.2 - Unuthenticated SQL Injection — Product Table for WooCommerce by WBWCWE-89 7.5 High2025-01-23
CVE-2025-0635 Denial of Service condition in M-Files Server — M-Files ServerCWE-770 7.5 -2025-01-23
CVE-2024-55971 Logitime WebClock 安全漏洞 — n/a 9.8 -2025-01-23
CVE-2025-20165 Cisco BroadWorks SIP Denial of Service Vulnerability — Cisco BroadWorksCWE-789 7.5 High2025-01-22
CVE-2025-20128 ClamAV OLE2 File Format Decryption Denial of Service Vulnerability — Cisco Secure EndpointCWE-122 5.3 Medium2025-01-22
CVE-2024-13496 GamiPress <= 7.3.1 - Unauthenticated SQL Injection via orderby Parameter — GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressCWE-89 7.5 High2025-01-22
CVE-2024-13499 GamiPress <= 7.2.1 - Unauthenticated Arbitrary Shortcode Execution via gamipress_do_shortcode() Function — GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressCWE-94 7.3 High2025-01-22
CVE-2024-13495 GamiPress <= 7.2.1 - Unauthenticated Arbitrary Shortcode Execution via gamipress_ajax_get_logs Function — GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressCWE-94 7.3 High2025-01-22
CVE-2024-13319 Themify Builder <= 7.6.5 - Reflected Cross-Site Scripting — Themify BuilderCWE-79 6.1 Medium2025-01-22
CVE-2024-12857 AdForest <= 5.1.8 - Authentication Bypass — AdForestCWE-288 9.8 Critical2025-01-22
CVE-2024-13406 XML for Google Merchant Center <= 3.0.11 - Reflected Cross-Site Scripting — XML for Google Merchant CenterCWE-79 6.1 Medium2025-01-22
CVE-2024-13426 WP-Polls <= 2.77.2 - Unauthenticated SQL Injection to Stored Cross-Site Scripting — WP-PollsCWE-89 5.4 Medium2025-01-22

Vulnerabilities classified as access:pre-auth represent 18866 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.