Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18867

18867 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-46670 Fortinet FortiOS 缓冲区错误漏洞 — FortiOSCWE-125 7.5 High2025-01-14
CVE-2024-56841 Siemens Mendix 注入漏洞 — Mendix LDAPCWE-90 7.4 High2025-01-14
CVE-2024-47100 Siemens SIMATIC S7-1200 跨站请求伪造漏洞 — SIMATIC S7-1200 CPU 1211C AC/DC/RlyCWE-352 7.1 High2025-01-14
CVE-2024-12919 Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.7 - Authentication Bypass via pms_payment_id — Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content RestrictionCWE-287 9.8 Critical2025-01-14
CVE-2025-0393 Royal Elementor Addons and Templates <= 1.7.1006 - Cross-Site Request Forgery to Reflected Cross-Site Scripting — Royal Addons for Elementor – Addons and Templates Kit for ElementorCWE-352 6.1 Medium2025-01-14
CVE-2024-12006 W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation — W3 Total CacheCWE-862 5.3 Medium2025-01-14
CVE-2024-12008 W3 Total Cache <= 2.8.1 Information Exposure via Log Files — W3 Total CacheCWE-200 5.3 Medium2025-01-14
CVE-2025-23082 Veeam Backup 代码问题漏洞 — Backup for Microsoft Azure 6.5 -2025-01-14
CVE-2025-0061 Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform — SAP BusinessObjects Business Intelligence PlatformCWE-497 8.7 High2025-01-14
CVE-2025-0053 Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform — SAP NetWeaver Application Server for ABAP and ABAP PlatformCWE-209 5.3 Medium2025-01-14
CVE-2025-22983 IceCMS 安全漏洞 — n/a 7.5 -2025-01-14
CVE-2025-22984 IceCMS 安全漏洞 — n/a 7.5 -2025-01-14
CVE-2024-11396 Event monster <= 1.4.3 - Information Exposure Via Visitors List Export — Event Monster – Manager & Ticket BookingCWE-359 5.3 Medium2025-01-13
CVE-2024-12274 BookingPress < 1.1.23 - Unauthenticated Export File Download — Appointment Booking Calendar Plugin and Scheduling Plugin 7.5 -2025-01-13
CVE-2024-46310 Cfx.re FXServer 安全漏洞 — n/a 9.1 -2025-01-13
CVE-2024-12407 Push Notification for Post and BuddyPress <= 2.07 - Reflected Cross-Site Scripting — Push Notification for Post and BuddyPressCWE-79 6.1 Medium2025-01-11
CVE-2024-12877 GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection — GiveWP – Donation Plugin and Fundraising PlatformCWE-502 9.8 Critical2025-01-11
CVE-2024-12412 Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin <= 2.2.1 - Reflected Cross-Site Scripting — Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | EquipmentCWE-79 6.1 Medium2025-01-11
CVE-2025-0107 Expedition: OS Command Injection Vulnerability — Cloud NGFWCWE-78 10.0 -2025-01-11
CVE-2025-0106 Expedition: Wildcard Expansion Vulnerability — Cloud NGFWCWE-155 5.8 -2025-01-11
CVE-2025-0105 Expedition: Arbitrary File Deletion Vulnerability — Cloud NGFWCWE-73 10.0 -2025-01-11
CVE-2024-11327 ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages <= 2.4.1 - Reflected Cross-Site Scripting — ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link PagesCWE-79 6.1 Medium2025-01-11
CVE-2024-12404 CF Internal Link Shortcode <= 1.1.0 - Unauthenticated SQL Injection — CF Internal Link ShortcodeCWE-89 7.5 High2025-01-11
CVE-2024-12847 NETGEAR DGN setup.cgi OS Command Injection — DGN1000CWE-78 9.8 Critical2025-01-10
CVE-2024-13318 Essential WP Real Estate <= 1.1.3 - Missing Authorization to Arbitrary Post/Page Deletion — Essential WP Real EstateCWE-463 5.3 Medium2025-01-10
CVE-2024-10215 WPBookit <= 1.6.4 - Unauthenticated Arbitrary User Password Change — WPBookitCWE-639 9.8 Critical2025-01-09
CVE-2025-21598 Junos OS and Junos OS Evolved: When BGP traceoptions are configured, receipt of malformed BGP packets causes RPD to crash — Junos OSCWE-125 7.5 High2025-01-09
CVE-2025-21600 Junos OS and Junos OS Evolved: With certain BGP options enabled, receipt of specifically malformed BGP update causes RPD crash — Junos OSCWE-125 6.5 Medium2025-01-09
CVE-2025-21602 Junos OS and Junos OS Evolved: Receipt of specially crafted BGP update packet causes RPD crash — Junos OSCWE-755 6.5 Medium2025-01-09
CVE-2025-21599 Junos OS Evolved: Receipt of specifically malformed IPv6 packets causes kernel memory exhaustion leading to Denial of Service — Junos OS EvolvedCWE-401 7.5 High2025-01-09

Vulnerabilities classified as access:pre-auth represent 18867 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.