Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18872

18872 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-10516 Swift Performance Lite <= 2.3.7.1 - Unauthenticated Local PHP File Inclusion via 'ajaxify' — Swift Performance LiteCWE-22 8.1 High2024-12-06
CVE-2024-10774 SICK InspectorP61x and SICK InspectorP62x have unauthenticated CROWN APIs — SICK InspectorP61xCWE-306 7.3 High2024-12-06
CVE-2024-11289 Soledad <= 8.5.9 - Unauthenticated Limited Local File Inclusion — SoledadCWE-98 8.1 High2024-12-06
CVE-2024-11460 Verowa Connect <= 3.0.1 - Unauthenticated SQL Injection — Verowa ConnectCWE-89 7.5 High2024-12-06
CVE-2024-11728 KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Unauthenticated SQL Injection — KiviCare – Clinic & Patient Management System (EHR)CWE-89 7.5 High2024-12-06
CVE-2024-11204 ForumWP – Forum & Discussion Board <= 2.1.2 - Reflected Cross-Site Scripting via url Parameter — ForumWP – Forum & Discussion BoardCWE-79 6.1 Medium2024-12-06
CVE-2024-11687 Next-Cart Store to WooCommerce Migration <= 3.9.2 - Reflected Cross-Site Scripting — Next-Cart Store to WooCommerce MigrationCWE-79 6.1 Medium2024-12-06
CVE-2024-12155 SV100 Companion <= 2.0.02 - Missing Authorization to Unuathenticated Arbitrary Options Update — SV100 CompanionCWE-862 9.8 Critical2024-12-06
CVE-2024-12028 Friends <= 3.2.1 - Missing Authorization — FriendsCWE-862 5.3 Medium2024-12-06
CVE-2024-9706 Ultimate Coming Soon & Maintenance <= 1.0.9 - Missing Authorization to Unauthenticated Template Activation — Ultimate Coming Soon & MaintenanceCWE-862 5.3 Medium2024-12-06
CVE-2024-11276 PDF Builder for WooCommerce. Create invoices,packing slips and more <= 1.2.136 - Reflected Cross-Site Scripting — PDF Builder for WooCommerce. Create invoices,packing slips and moreCWE-79 6.1 Medium2024-12-06
CVE-2024-11336 Clickbank WordPress Plugin (Storefront) <= 1.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Clickbank WordPress Plugin (Storefront)CWE-352 6.1 Medium2024-12-06
CVE-2024-11368 Splash Sync <= 2.0.7 - Reflected Cross-Site Scripting — Splash SyncCWE-79 6.1 Medium2024-12-06
CVE-2024-11292 WP Private Content Plus <= 3.6.1 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — WP Private Content PlusCWE-200 5.3 Medium2024-12-06
CVE-2024-10879 ForumWP – Forum & Discussion Board <= 2.1.2 - Reflected Cross-Site Scripting — ForumWP – Forum & Discussion BoardCWE-79 6.1 Medium2024-12-06
CVE-2024-11444 CLUEVO LMS, E-Learning Platform <= 1.13.2 - Cross-Site Request Forgery to Module Deletion — CLUEVO LMS, E-Learning PlatformCWE-352 4.3 Medium2024-12-06
CVE-2024-12060 WP Media Optimizer (.webp) <= 1.4.0 - Reflected Cross-Site Scripting via wpmowebp-css-resources and wpmowebp-js-resources Parameters — WP Media Optimizer (.webp)CWE-79 6.1 Medium2024-12-06
CVE-2024-12003 WP System <= 1.1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting — WP SystemCWE-352 6.1 Medium2024-12-06
CVE-2024-11178 Login With OTP <= 1.4.2 - Authentication Bypass via Weak OTP — Login with OTPCWE-288 8.1 High2024-12-06
CVE-2024-11585 WP Hide & Security Enhancer <= 2.5.1 - Missing Authorization to Unauthenticated Arbitrary File Contents Deletion — WP Hide & Security EnhancerCWE-22 7.5 High2024-12-06
CVE-2024-11379 Broadcast <= 51.01 - Reflected Cross-Site Scripting — BroadcastCWE-79 6.1 Medium2024-12-06
CVE-2024-10836 Flixita <= 1.0.82 - Reflected Cross-Site Scripting via id Parameter — FlixitaCWE-79 6.1 Medium2024-12-06
CVE-2024-11324 Accounting for WooCommerce <= 1.6.6 - Reflected Cross-Site Scripting — Accounting for WooCommerceCWE-79 6.1 Medium2024-12-05
CVE-2024-11341 Simple Redirection <= 1.5 - Cross-Site Request Forgery to Arbitrary Site Redirect — Simple RedirectionCWE-352 4.3 Medium2024-12-05
CVE-2024-10937 Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.0.58 - Sensitive Information Exposure — Related Posts By PickPluginsCWE-284 5.3 Medium2024-12-05
CVE-2024-20397 Cisco NX-OS Software Image Verification Bypass Vulnerability — Cisco NX-OS SoftwareCWE-284 5.2 Medium2024-12-04
CVE-2024-54155 JetBrains YouTrack 安全漏洞 — YouTrackCWE-862 3.7 Low2024-12-04
CVE-2024-54153 JetBrains YouTrack 安全漏洞 — YouTrackCWE-862 3.1 Low2024-12-04
CVE-2024-11814 Additional Custom Order Status for WooCommerce <= 1.6.0 - Reflected Cross-Site Scripting — Additional Custom Order Status for WooCommerceCWE-79 6.1 Medium2024-12-04
CVE-2024-10567 TI WooCommerce Wishlist <= 2.9.1 - Missing Authorization to Unauthenticated Plugin Setup Wizard Access — TI WooCommerce WishlistCWE-862 7.5 High2024-12-04

Vulnerabilities classified as access:pre-auth represent 18872 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.