Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18872

18872 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-12356 Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA) — Remote SupportCWE-77 9.8 Critical2024-12-17
CVE-2024-12239 PowerPack Lite for Beaver Builder <= 1.3.0.5 - Reflected Cross-Site Scripting via Navigate Parameter — PowerPack Lite for Beaver BuilderCWE-79 6.1 Medium2024-12-17
CVE-2024-36831 D-Link DAP-1520 安全漏洞 — n/a 7.5 -2024-12-17
CVE-2024-36832 D-Link DAP-1513 安全漏洞 — n/a 7.5 -2024-12-17
CVE-2024-49775 Siemens Opcenter Execution Foundation 安全漏洞 — Opcenter Execution FoundationCWE-122 9.8 Critical2024-12-16
CVE-2024-12646 Chunghwa Telecom topm-client - Arbitrary File Delete — topm-clientCWE-352 8.1 High2024-12-16
CVE-2024-12645 Chunghwa Telecom topm-client - Arbitrary File Read — topm-clientCWE-352 6.5 Medium2024-12-16
CVE-2024-12644 Chunghwa Telecom tbm-client - Arbitrary File Copy and Paste — tbm-clientCWE-352 7.1 High2024-12-16
CVE-2024-12643 Chunghwa Telecom tbm-client - Arbitrary File Delete — tbm-clientCWE-352 8.1 High2024-12-16
CVE-2024-12642 Chunghwa Telecom TenderDocTransfer - Arbitrary File Write — TenderDocTransferCWE-352 8.1 High2024-12-16
CVE-2024-12641 Chunghwa Telecom TenderDocTransfer - Reflected Cross-site Scripting to RCE — TenderDocTransferCWE-79 9.6 Critical2024-12-16
CVE-2024-5333 The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure — The Events Calendar 5.3 -2024-12-16
CVE-2024-11721 Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Privilege Escalation — Frontend Admin by DynamiAppsCWE-269 8.1 High2024-12-14
CVE-2024-11720 Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Stored Cross-Site Scripting — Frontend Admin by DynamiAppsCWE-79 7.2 High2024-12-14
CVE-2024-11712 WP Job Portal <= 2.2.2 - Missing Authorization to Unauthenticated Arbitrary Resume Download — WP Job Portal – AI-Powered Recruitment System for Company or Job Board websiteCWE-359 5.3 Medium2024-12-14
CVE-2024-11711 WP Job Portal <= 2.2.1 - Unauthenticated SQL Injection — WP Job Portal – AI-Powered Recruitment System for Company or Job Board websiteCWE-89 7.5 High2024-12-14
CVE-2024-11715 WP Job Portal <= 2.2.2 - Missing Authorization to Limited Privilege Escalation — WP Job Portal – AI-Powered Recruitment System for Company or Job Board websiteCWE-862 4.8 Medium2024-12-14
CVE-2024-12422 Import Eventbrite Events <= 1.7.4 - Reflected Cross-Site Scripting — Import Eventbrite EventsCWE-79 6.1 Medium2024-12-14
CVE-2024-10646 Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting via Form Subject — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form BuilderCWE-79 7.2 High2024-12-14
CVE-2024-12411 WP Ad Guru – Banner ad, Responsive popup, Popup maker, Ad rotator & More <= 2.5.4 - Reflected Cross-Site Scripting — WP Ad Guru – Banner ad, Responsive popup, Popup maker, Ad rotator & MoreCWE-79 6.1 Medium2024-12-14
CVE-2024-11462 Filestack Official <= 2.1.0 - Reflected Cross-Site Scripting — Filestack WP UploadCWE-79 6.1 Medium2024-12-14
CVE-2024-12578 Tickera – WordPress Event Ticketing <= 3.5.4.8 - Unauthenticated Customer Data Exposure — Tickera – Sell Tickets & Manage EventsCWE-200 5.3 Medium2024-12-14
CVE-2024-12555 SIP Calculator <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting — SIP CalculatorCWE-352 6.1 Medium2024-12-14
CVE-2024-28980 Dell RecoverPoint for Virtual Machines 加密问题漏洞 — RecoverPoint for Virtual MachinesCWE-327 6.5 Medium2024-12-13
CVE-2024-48007 Dell RecoverPoint for Virtual Machines 安全漏洞 — RecoverPoint for Virtual Machines 5.3 Medium2024-12-13
CVE-2024-11986 Stored XSS in CrushFTP — CrushFTPCWE-79 9.6 Critical2024-12-13
CVE-2024-9608 MyParcel <= 4.24.1 - Reflected Cross-Site Scripting — MyParcelCWE-79 6.1 Medium2024-12-13
CVE-2024-9290 Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload — Super Backup & Clone - Migrate for WordPressCWE-434 9.8 Critical2024-12-13
CVE-2024-10783 MainWP Child <= 5.3.3 - Missing Authorization to Unauthenticated Privilege Escalation — MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple SitesCWE-862 8.1 High2024-12-13
CVE-2024-12309 Rate My Post – Star Rating Plugin by FeedbackWP <= 4.2.4 - Unauthenticated Voting On Scheduled Posts — Rate My Post – Star Rating Plugin by FeedbackWPCWE-639 5.3 Medium2024-12-13

Vulnerabilities classified as access:pre-auth represent 18872 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.