Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18872

18872 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-55556 Crater 代码问题漏洞 — n/a 8.1 -2025-01-07
CVE-2024-11356 Tourmaster < 5.3.4 - Unauthenticated Stored XSS via Room Booking — tourmaster 6.1 -2025-01-06
CVE-2024-54763 ipTIME A2004 安全漏洞 — n/a 7.5 -2025-01-06
CVE-2024-54764 ipTIME A2004 安全漏洞 — n/a 7.5 -2025-01-06
CVE-2024-54767 AVM FRITZ!Box 7530 AX 安全漏洞 — n/a 7.5 -2025-01-06
CVE-2024-10957 UpdraftPlus: WP Backup & Migration Plugin 1.23.8 - 1.24.11 - Unauthenticated PHP Object Injection — UpdraftPlus: WP Backup & Migration PluginCWE-502 8.8 High2025-01-04
CVE-2024-12279 WP Social AutoConnect <= 4.6.2 - Cross-Site Request Forgery to Reflected Cross-Site Scripting — WP Social AutoConnectCWE-352 6.1 Medium2025-01-04
CVE-2024-12221 Turnkey bbPress by WeaverTheme <= 1.6.3 - Reflected Cross-Site Scripting via _wpnonce Parameter — Turnkey bbPress by WeaverThemeCWE-79 6.1 Medium2025-01-04
CVE-2024-10932 Backup Migration <= 1.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialize_replace' — BackupBliss – Backup & Migration with Free Cloud StorageCWE-502 8.8 High2025-01-04
CVE-2024-11974 Media Library Assistant <= 3.23 - Reflected Cross-Site Scripting via smc_settings_tab, unattachfixit-action, and woofixit-action Parameters — Media Library AssistantCWE-79 6.1 Medium2025-01-04
CVE-2024-12545 Scratch & Win – Giveaways and Contests <= 2.7.1 - Cross-Site Request Forgery via reset_installation Function — Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and moreCWE-352 5.4 Medium2025-01-04
CVE-2024-12047 WP Compress – Instant Performance & Speed Optimization <= 6.30.03 - Reflected Cross-Site Scripting via custom_server Parameter — WP Compress – Instant Performance & Speed OptimizationCWE-79 6.1 Medium2025-01-04
CVE-2024-12701 WP Smart Import : Import any XML File to WordPress <= 1.1.2 - Reflected Cross-Site Scripting — WP Smart Import : Import any XML File to WordPressCWE-79 6.1 Medium2025-01-04
CVE-2024-11733 WordPress Popular Posts <= 7.1.0 - Unauthenticated Arbitrary Shortcode Execution — WP Popular PostsCWE-94 7.3 High2025-01-03
CVE-2024-9950 Abuse of Unauthenticated Compliance Recheck in SecureConnector — SecureConnectorCWE-379 6.2 -2025-01-02
CVE-2024-13061 2100 Technology Electronic Official Document Management System - Authentication Bypass — Official Document Management SystemCWE-290 9.8 Critical2024-12-31
CVE-2024-12106 WhatsUp Gold - LDAP configuration interface leading to allowing attacker to configure LDAP settings without authentication — WhatsUp GoldCWE-306 9.4 Critical2024-12-31
CVE-2024-11972 Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation — Hunk Companion 9.1 -2024-12-31
CVE-2024-12839 Changing Information Technology CGFIDO - Authentication Bypass — CGFIDOCWE-294 8.8 High2024-12-31
CVE-2024-12856 Four-Faith Industrial Router adjust_sys_time OS Command Injection — F3x24CWE-78 7.2 High2024-12-27
CVE-2024-3393 PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet — Cloud NGFWCWE-754 7.5 -2024-12-27
CVE-2020-9086 Huawei 4G Router B612安全漏洞 — HUAWEI 4G Router B612CWE-124 4.3 Medium2024-12-27
CVE-2024-53850 The Addressing GLPI plugin allows data enumeration through uncontrolled object instantiation — addressingCWE-470 8.2 High2024-12-26
CVE-2024-53291 Dell NativeEdge 安全漏洞 — NativeEdgeCWE-1230 7.5 High2024-12-25
CVE-2023-5117 Exposure of Sensitive Information Due to Incompatible Policies in GitLab — GitLabCWE-213 3.7 Low2024-12-25
CVE-2024-10862 NEX-Forms <= 8.7.15 - Authenticated (Admin+) SQL Injection — NEX-Forms – Ultimate Forms Plugin for WordPressCWE-89 4.9 Medium2024-12-25
CVE-2024-11281 WooCommerce Point of Sale <= 6.1.0 - Insecure Direct Object Reference to Privilege Escalation via Arbitrary User Email Change — WooCommerce Point of SaleCWE-862 9.8 Critical2024-12-25
CVE-2024-12428 WP Data Access – App, Table, Form and Chart Builder plugin <= 5.5.22 - Unauthenticated SQL Injection — WP Data Access – App Builder for Tables, Forms, Charts, Maps & DashboardsCWE-89 7.5 High2024-12-25
CVE-2024-12636 Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.2.7 - Cross-Site Request Forgery — Privacy Policy Generator – WPLP Legal PagesCWE-352 4.3 Medium2024-12-25
CVE-2024-12413 MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution <= 2.0.00 - Missing Authorization — MarketKing — Ultimate WooCommerce Multivendor Marketplace SolutionCWE-862 5.3 Medium2024-12-25

Vulnerabilities classified as access:pre-auth represent 18872 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.