Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18872

18872 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-10959 Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.5 - Unauthenticated Arbitrary Shortcode Execution via woot_get_smth — Active Products Tables for WooCommerce. Use constructor to create tablesCWE-94 7.3 High2024-12-10
CVE-2024-11106 Simple Restrict <= 1.2.7 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Simple RestrictCWE-200 5.3 Medium2024-12-10
CVE-2024-47484 Dell Avamar SQL注入漏洞 — AvamarCWE-89 8.2 High2024-12-10
CVE-2024-11973 Quran multilanguage Text & Audio <= 2.3.21 - Reflected Cross-Site Scripting via sourate and lang Parameters — Quran multilanguage Text & AudioCWE-79 6.1 Medium2024-12-10
CVE-2024-28138 OS Command Injection — Scan2NetCWE-78 9.8 -2024-12-10
CVE-2024-11107 System Dashboard < 2.8.15 - Unauthenticated Stored XSS — System Dashboard 6.1 -2024-12-10
CVE-2024-37143 Dell PowerFlex 后置链接漏洞 — Dell PowerFlex applianceCWE-59 10.0 Critical2024-12-10
CVE-2024-47582 XML Entity Expansion Vulnerability in SAP NetWeaver AS JAVA — SAP NetWeaver AS JAVACWE-611 5.3 Medium2024-12-10
CVE-2024-54151 Directus allows unauthenticated access to WebSocket events and operations — directusCWE-200 7.5 High2024-12-09
CVE-2024-12209 WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion — WP Umbrella: Update Backup Restore & MonitoringCWE-98 9.8 Critical2024-12-08
CVE-2024-11457 Feedpress Generator – External RSS Frontend Customizer <= 1.2.1 - Reflected Cross-Site Scripting — Feedpress Generator – External RSS Frontend CustomizerCWE-79 6.1 Medium2024-12-07
CVE-2024-11464 Easy Code Snippets <= 1.0.2 - Reflected Cross-Site Scripting — Easy Code SnippetsCWE-79 6.1 Medium2024-12-07
CVE-2024-12128 Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal <= 3.1.2 - Reflected Cross-Site Scripting via monthly_sales_current_year Parameter — Simple Ecommerce Shopping Cart Plugin- Sell products through PaypalCWE-79 6.1 Medium2024-12-07
CVE-2024-11367 Smoove connector for Elementor forms <= 4.1.0 - Reflected Cross-Site Scripting — Smoove connector for Elementor formsCWE-79 6.1 Medium2024-12-07
CVE-2024-12270 Beautiful Taxonomy Filters <= 2.4.3 - Unauthenticated SQL Injection — Beautiful taxonomy filtersCWE-89 7.5 High2024-12-07
CVE-2024-11374 TWChat – Send or receive messages from users <= 4.0.4 - Reflected Cross-Site Scripting — TWChat – Send or receive messages from usersCWE-79 6.1 Medium2024-12-07
CVE-2024-12253 Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal <= 3.1.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update / Data Access — Simple Ecommerce Shopping Cart Plugin- Sell products through PaypalCWE-862 5.4 Medium2024-12-07
CVE-2024-12115 Poll Maker <= 5.5.4 - Cross-Site Request Forgery to Poll Duplication — Poll Maker – Versus Polls, Anonymous Polls, Image PollsCWE-352 4.3 Medium2024-12-07
CVE-2024-7894 If Menu <= 0.19.1 - Missing Authorization to License Key Update — If Menu – Visibility control for MenusCWE-862 5.3 Medium2024-12-07
CVE-2024-12165 Mollie for Contact Form 7 <= 5.0.0 - Reflected Cross-Site Scripting — Mollie for Contact Form 7CWE-79 6.1 Medium2024-12-07
CVE-2024-12167 Shortcodes Blocks Creator Ultimate <= 2.2.0 - Reflected Cross-Site Scripting via _wpnonce — Shortcodes Blocks Creator UltimateCWE-79 6.1 Medium2024-12-07
CVE-2024-12257 CardGate Payments for WooCommerce <= 3.2.1 - Reflected Cross-Site Scripting — CardGate Payments for WooCommerceCWE-79 6.1 Medium2024-12-07
CVE-2024-12166 Shortcodes Blocks Creator Ultimate <= 2.2.0 - Reflected Cross-Site Scripting via 'page' — Shortcodes Blocks Creator UltimateCWE-79 6.1 Medium2024-12-07
CVE-2024-10046 افزونه پیامک ووکامرس Persian WooCommerce SMS <= 7.0.5 - Reflected Cross-Site Scripting — افزونه پیامک ووکامرس Persian WooCommerce SMSCWE-79 6.1 Medium2024-12-07
CVE-2024-11943 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 <= 5.2.2 - Reflected Cross-Site Scripting via add_query_arg Function — 워드프레스 결제 심플페이 – 우커머스 결제 플러그인CWE-79 6.1 Medium2024-12-07
CVE-2024-11436 Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! <= 1.4.19 - Reflected Cross-Site Scripting — Pie Forms — Drag & Drop Form BuilderCWE-79 6.1 Medium2024-12-07
CVE-2024-11329 Comfino Payment Gateway <= 4.1.1 - Reflected Cross-Site Scripting — Comfino Payment GatewayCWE-79 6.1 Medium2024-12-07
CVE-2024-52558 Planet Technology Planet WGS-804HPT Integer Underflow — Planet WGS-804HPTCWE-191 5.3 Medium2024-12-06
CVE-2024-52320 Planet Technology Planet WGS-804HPT Command Injection — Planet WGS-804HPTCWE-78 9.8 Critical2024-12-06
CVE-2024-48871 Planet Technology Planet WGS-804HPT Stack-based Buffer Overflow — Planet WGS-804HPTCWE-121 9.8 Critical2024-12-06

Vulnerabilities classified as access:pre-auth represent 18872 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.