Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18872

18872 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2019-2483 Oracle iStore 安全漏洞 — Oracle iStore 6.1 -2024-12-24
CVE-2024-10584 DirectoryPress <= 3.6.16 - Authenticated (Author+) Stored Cross-Site Scripting — DirectoryPress – Business Directory And Classified Ad ListingCWE-434 5.4 Medium2024-12-24
CVE-2024-12103 Content No Cache: prevent specific content from being cached <= 0.1.2 - Unauthenticated Private Content Disclosure — Content No Cache | Serve uncached partial content even when you add it to a page that is fully cached.CWE-639 5.3 Medium2024-12-24
CVE-2024-12468 WP Datepicker <= 2.1.4 - Reflected Cross-Site Scripting — WP DatepickerCWE-79 6.1 Medium2024-12-24
CVE-2024-12100 Bitcoin Lightning Publisher for WordPress <= 1.4.1 - Reflected Cross-Site Scripting — Bitcoin Lightning Publisher for WordPressCWE-79 6.1 Medium2024-12-24
CVE-2024-12405 Export Customers Data <= 1.2.3 - Reflected Cross-Site Scripting — Export Customers DataCWE-79 6.1 Medium2024-12-24
CVE-2024-12034 Advanced Google reCAPTCHA <= 1.25 - Brute Force Protection IP Unblock — Advanced Google reCAPTCHACWE-340 5.3 Medium2024-12-24
CVE-2024-12266 ELEX WooCommerce Dynamic Pricing and Discounts <= 2.1.7 - Missing Authorization — ELEX WooCommerce Dynamic Pricing and DiscountsCWE-862 6.5 Medium2024-12-24
CVE-2024-12710 WP-Appbox <= 4.5.3 - Reflected Cross-Site Scripting — WP-AppboxCWE-79 6.1 Medium2024-12-24
CVE-2024-52321 Sharp多款产品 安全漏洞 — home 5G HR02CWE-497 7.5 -2024-12-23
CVE-2024-47864 Sharp HR02、Sharp SH-52B和Sharp SH-54C 安全漏洞 — home 5G HR02CWE-120 7.5 -2024-12-23
CVE-2024-46873 Sharp SH-05L、SH-52B、SH-54C和HR02 安全漏洞 — home 5G HR02CWE-489 9.8 -2024-12-23
CVE-2024-11688 LaTeX2HTML <= 2.5.5 - Reflected Cross-Site Scripting — LaTeX2HTMLCWE-79 6.1 Medium2024-12-21
CVE-2024-11722 Frontend Admin by DynamiApps <= 3.25.1 - Unauthenticated SQL Injection — Frontend Admin by DynamiAppsCWE-89 5.9 Medium2024-12-21
CVE-2024-12408 WP on AWS <= 5.2.1 - Reflected Cross-Site Scripting — WP on AWSCWE-79 6.1 Medium2024-12-21
CVE-2024-11808 Pingmeter Uptime Monitoring <= 1.0.3 - Reflected Cross-Site Scripting — Pingmeter Uptime MonitoringCWE-79 6.1 Medium2024-12-21
CVE-2024-11682 G Web Pro Store Locator <= 2.1 - Reflected Cross-Site Scripting — G Web Pro Store LocatorCWE-79 6.1 Medium2024-12-21
CVE-2024-11975 Reactflow Visitor Recording and Heatmaps <= 1.0.10 - Reflected Cross-Site Scripting — Reactflow Visitor Recording and HeatmapsCWE-79 6.1 Medium2024-12-21
CVE-2024-12262 Ebook Store <= 5.8001 - Reflected Cross-Site Scripting via 'step' — Ebook StoreCWE-79 6.1 Medium2024-12-21
CVE-2024-12771 eCommerce Product Catalog Plugin for WordPress <= 3.3.43 - Cross-Site Request Forgery to Password Reset — eCommerce Product Catalog Plugin for WordPressCWE-352 8.8 High2024-12-21
CVE-2024-11287 Ebook Store <= 5.8001 - Reflected Cross-Site Scripting — Ebook StoreCWE-79 6.1 Medium2024-12-21
CVE-2024-11977 kk Star Ratings – Rate Post & Collect User Feedbacks <= 5.4.10 - Unauthenticated Arbitrary Shortcode Execution — kk Star Ratings – Rate Post & Collect User FeedbacksCWE-94 7.3 High2024-12-21
CVE-2024-11349 AdForest <= 5.1.6 - Authentication Bypass — AdForestCWE-288 9.8 Critical2024-12-21
CVE-2024-11811 Feedify – Web Push Notifications <= 2.4.2 - Reflected Cross-Site Scripting — Feedify – Web Push NotificationsCWE-79 6.1 Medium2024-12-20
CVE-2024-12867 Server-Side Request Forgery in Arctic Hub URL Mapper allows an unauthenticated remote attacker to exfiltrate and modify configurations and data — Arctic HubCWE-918 9.1 -2024-12-20
CVE-2024-12014 Path Traversal vulnerability in eSignaViewer Allow Unauthorized File Access — eSignaCWE-20 7.5 -2024-12-20
CVE-2024-7726 Arbitrary Code execution via exposed JTAG port in Kioxia CM6, PM6, PM7 — CM6CWE-306 6.1 -2024-12-20
CVE-2024-11806 PKT1 Centro de envios <= 1.2.1 - Reflected Cross-Site Scripting — PKT1 Centro de enviosCWE-79 6.1 Medium2024-12-20
CVE-2024-11331 isee-products-extractor <= 2.1.3 - Reflected Cross-Site Scripting — استخراج محصولات ووکامرس برای آیسیCWE-79 6.1 Medium2024-12-20
CVE-2024-11297 Page Restriction WordPress (WP) – Protect WP Pages/Post <= 1.3.6 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Page and Post RestrictionCWE-200 5.3 Medium2024-12-20

Vulnerabilities classified as access:pre-auth represent 18872 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.