Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18866

18866 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2023-37024 Magma 安全漏洞 — n/a 7.5 -2025-01-21
CVE-2023-37029 Magma 安全漏洞 — n/a 6.5 -2025-01-21
CVE-2023-37032 Magma 安全漏洞 — n/a 6.5 -2025-01-21
CVE-2024-51738 Sunshine improperly enforces pairing protocol request order — SunshineCWE-305 5.9 -2025-01-20
CVE-2025-0585 aEnrich Technology a+HRD - SQL Injection — a+HRDCWE-89 9.8 Critical2025-01-20
CVE-2025-0584 aEnrich Technology a+HRD - Server-Side Request Forgery (SSRF) — a+HRDCWE-918 5.3 Medium2025-01-20
CVE-2025-0583 aEnrich Technology a+HRD - Reflected Cross-site Scripting(XSS) — a+HRDCWE-79 6.1 Medium2025-01-20
CVE-2024-13375 Adifier System <= 3.1.7 - Unauthenticated Arbitrary Password Reset — Adifier SystemCWE-620 9.8 Critical2025-01-18
CVE-2024-13184 The Ultimate WordPress Toolkit – WP Extended <= 3.0.12 - Unauthenticated SQL Injection via Login Attempts Module — The Ultimate WordPress Toolkit – WP ExtendedCWE-89 7.5 High2025-01-18
CVE-2024-12385 WP Abstracts <= 2.7.2 - Cross-Site Request Forgery to Reflected Cross-Site Scripting — WP AbstractsCWE-352 6.1 Medium2025-01-18
CVE-2024-13317 ShipWorks Connector for Woocommerce <= 5.2.5 - Cross-Site Request Forgery to Service Password/Username Update — ShipWorks Connector for WoocommerceCWE-352 4.3 Medium2025-01-18
CVE-2024-13432 Webcamconsult <= 1.5.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting — WebcamconsultCWE-352 6.1 Medium2025-01-18
CVE-2024-13515 Image Source Control Lite – Show Image Credits and Captions <= 2.28.0 - Reflected Cross-Site Scripting — Image Source Control Lite – Show Image Credits and CaptionsCWE-79 6.1 Medium2025-01-18
CVE-2024-13516 Kubio AI Page Builder <= 2.3.5 - Reflected Cross-Site Scripting — Kubio AI Page BuilderCWE-79 6.1 Medium2025-01-18
CVE-2025-0308 Ultimate Member <= 2.9.1 - Unauthenticated SQL Injection — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership PluginCWE-89 7.5 High2025-01-18
CVE-2025-0318 Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 - Information Exposure — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership PluginCWE-200 5.3 Medium2025-01-18
CVE-2024-12071 Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media <= 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Post Deletion — Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social MediaCWE-862 5.3 Medium2025-01-18
CVE-2024-12757 Nedap Librix Ecoreader Missing Authentication for Critical Function — EcoreaderCWE-306 8.6 High2025-01-17
CVE-2024-13378 GravityForms 2.9.0.1 - 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'style_settings' parameter — Gravity FormsCWE-79 5.4 Medium2025-01-17
CVE-2024-13377 GravityForms <= 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'alt' parameter — Gravity FormsCWE-79 7.2 High2025-01-17
CVE-2024-11425 Schneider Electric Modicon M580 安全漏洞 — Modicon M580 CPU (part numbers BMEP* and BMEH*, excluding M580 CPU Safety)CWE-131 7.5 High2025-01-17
CVE-2024-12370 WP Hotel Booking <= 2.1.5 - Missing Authorization — WP Hotel BookingCWE-284 5.3 Medium2025-01-17
CVE-2024-12466 Proofreading <= 1.2.1.1 - Reflected Cross-Site Scripting — ProofreadingCWE-79 6.1 Medium2025-01-17
CVE-2024-12637 Moving Users <= 1.05 - Unauthenticated Sensitive Information Exposure — Moving UsersCWE-200 5.3 Medium2025-01-17
CVE-2024-13366 Sandbox <= 0.4 - Reflected Cross-Site Scripting — SandboxCWE-79 6.1 Medium2025-01-17
CVE-2024-13434 WP Inventory Manager <= 2.3.2 - Reflected Cross-Site Scripting — WP Inventory ManagerCWE-79 6.1 Medium2025-01-17
CVE-2024-50967 DATAGerry 安全漏洞 — n/a 7.5 -2025-01-17
CVE-2024-56136 /api/v1/jwt/fetch_api_key endpoint can leak if an email address has an account in Zulip server — zulipCWE-200 5.3 -2025-01-16
CVE-2024-36402 Unauthenticated writes to the media repository allow planting of problematic content in Matrix Media Repo — matrix-media-repoCWE-287 5.3 Medium2025-01-16
CVE-2024-36403 Denial of service/high operating costs through unauthenticated downloads in Matrix Media Repo — matrix-media-repoCWE-770 5.3 Medium2025-01-16

Vulnerabilities classified as access:pre-auth represent 18866 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.