Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18872

18872 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-11979 Interinfo DreamMaker - Unrestricted File Upload through Path Traversal — DreamMaker 9.8 Critical2024-11-29
CVE-2024-11978 Interinfo DreamMaker - Arbitrary File Reading through Path Traversal — DreamMakerCWE-36 7.5 High2024-11-29
CVE-2024-11103 Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover — Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & StripeCWE-640 9.8 Critical2024-11-28
CVE-2024-11599 Domain Restriction Bypass on Registration — MattermostCWE-754 8.2 High2024-11-28
CVE-2024-11684 Kudos Donations – Easy donations and payments with Mollie <= 3.2.9 - Reflected Cross-Site Scripting — Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & FormsCWE-79 6.1 Medium2024-11-28
CVE-2024-11458 FAQ Builder AYS <= 1.7.1 - Reflected Cross-Site Scripting — FAQ Builder AYSCWE-79 6.1 Medium2024-11-28
CVE-2024-11685 Kudos Donations – Easy donations and payments with Mollie <= 3.2.9 - Reflected Cross-Site Scripting via 'add_query_arg' — Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & FormsCWE-79 6.1 Medium2024-11-28
CVE-2024-11366 SEO Landing Page Generator <= 1.66.2 - Reflected Cross-Site Scripting — SEO Landing Page GeneratorCWE-79 6.1 Medium2024-11-28
CVE-2024-11925 WP JobSearch <= 2.6.7 - Authentication Bypass to Account Takeover and Privilege Escalation — JobSearch WP Job BoardCWE-288 9.8 Critical2024-11-28
CVE-2024-10521 WordPress Contact Forms by Cimatti <= 1.9.2 - Cross-Site Request Forgery via process_bulk_action Function — Contact Forms by CimattiCWE-352 4.3 Medium2024-11-27
CVE-2024-10580 Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unauthorized Form Submission — Hustle – Email Marketing, Lead Generation, Optins, PopupsCWE-862 5.3 Medium2024-11-27
CVE-2024-11219 Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 - Unauthetnicated Path Traversal to Arbitrary Image View — Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSECWE-22 5.3 Medium2024-11-27
CVE-2024-11083 ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePressCWE-200 5.3 Medium2024-11-27
CVE-2024-46054 OpenVidReview 安全漏洞 — n/a 9.1AICriticalAI2024-11-27
CVE-2024-53673 Hewlett Packard Enterprise Insight Remote Support 安全漏洞 — Insight Remote SupportCWE-502 8.1 High2024-11-26
CVE-2024-49035 Partner.Microsoft.Com Elevation of Privilege Vulnerability — Microsoft Partner CenterCWE-269 8.7 High2024-11-26
CVE-2024-10240 Exposure of Sensitive System Information to an Unauthorized Control Sphere in GitLab — GitLabCWE-497 5.3 Medium2024-11-26
CVE-2024-11145 Easy Folder Listing Pro deserialization vulnerability — Easy Folder Listing ProCWE-502 9.8 Critical2024-11-26
CVE-2024-10878 Sugar Calendar (Lite) <= 3.3.0 - Reflected Cross-Site Scripting — Sugar Calendar – Events Calendar, Event Tickets, and Events Management PlatformCWE-79 6.1 Medium2024-11-26
CVE-2024-52336 Tuned: `script_pre` and `script_post` options allow to pass arbitrary scripts executed by root CWE-269 7.8 High2024-11-26
CVE-2024-11024 AppPresser – Mobile App Framework <= 4.4.6 - Unauthenticated Privilege Escalation via Password Reset — AppPresser – Mobile App FrameworkCWE-230 9.8 Critical2024-11-26
CVE-2024-50375 Advantech EKI-6333AC-2G和Advantech EKI-6333AC-2GD 安全漏洞 — EKI-6333AC-2GCWE-78 9.8 Critical2024-11-26
CVE-2024-50374 Advantech EKI-6333AC-2G和Advantech EKI-6333AC-2GD 安全漏洞 — EKI-6333AC-2GCWE-78 9.8 Critical2024-11-26
CVE-2024-50373 Advantech EKI-6333AC-2G和Advantech EKI-6333AC-2GD 安全漏洞 — EKI-6333AC-2GCWE-78 9.8 Critical2024-11-26
CVE-2024-50372 Advantech EKI-6333AC-2G和Advantech EKI-6333AC-2GD 安全漏洞 — EKI-6333AC-2GCWE-78 9.8 Critical2024-11-26
CVE-2024-50371 Advantech EKI-6333AC-2G和Advantech EKI-6333AC-2GD 安全漏洞 — EKI-6333AC-2GCWE-78 9.8 Critical2024-11-26
CVE-2024-50370 Advantech EKI-6333AC-2G和Advantech EKI-6333AC-2GD 安全漏洞 — EKI-6333AC-2GCWE-78 9.8 Critical2024-11-26
CVE-2024-11680 ProjectSend Unauthenticated Configuration Modification — ProjectSendCWE-306 9.8 Critical2024-11-26
CVE-2024-11032 Parsi Date <= 5.1.1 - Reflected Cross-Site Scripting via add_query_arg Parameter — پارسی دیت – Parsi DateCWE-79 6.1 Medium2024-11-26
CVE-2024-11202 Multiple Plugins <= (Various Versions) - Reflected Cross-Site Scripting via cminds_free_guide Shortcode — CM Header and Footer – Add custom scripts and styles to your header and footer with easeCWE-79 6.1 Medium2024-11-26

Vulnerabilities classified as access:pre-auth represent 18872 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.