Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18872

18872 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2023-20125 Cisco BroadWorks Network Server TCP Denial of Service Vulnerability — Cisco BroadWorksCWE-400 8.6 High2024-11-15
CVE-2023-20154 Cisco Modeling Labs External Authentication Bypass Vulnerability — Cisco Modeling LabsCWE-305 9.1 Critical2024-11-15
CVE-2024-20373 Cisco IOS and Cisco IOS XE SNMP Extended ACL Bypass Vulnerability — Cisco IOS XE Catalyst SD-WANCWE-284 5.3 Medium2024-11-15
CVE-2024-41785 IBM Concert cross-site scripting — Concert SoftwareCWE-79 6.1 Medium2024-11-15
CVE-2024-10825 Hide My WP Ghost – Security & Firewall <= 5.3.01 - Reflected Cross-Site Scripting via URL — WP Ghost (Hide My WP Ghost) – Security & FirewallCWE-79 6.1 Medium2024-11-15
CVE-2024-10793 WP Activity Log <= 5.2.1 - Unauthenticated Stored Cross-Site Scripting via User_id Parameter — WP Activity LogCWE-79 7.2 High2024-11-15
CVE-2024-10260 Tripetto <= 8.0.11 - Unauthentiated Stored Cross-Site Scripting via Form File Upload — WordPress form builder plugin for contact forms, surveys and quizzes – TripettoCWE-79 7.2 High2024-11-15
CVE-2024-9356 Yotpo: Product & Photo Reviews for WooCommerce <= 1.7.9 - Reflected Cross-Site Scripting — Yotpo: Product & Photo Reviews for WooCommerceCWE-79 6.1 Medium2024-11-15
CVE-2024-9609 LearnPress Export Import – WordPress extension for LearnPress <= 4.0.4 - Reflected Cross-Site Scripting — LearnPress – Backup & Migration ToolCWE-79 6.1 Medium2024-11-15
CVE-2024-10924 Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass — Really Simple Security Pro multisiteCWE-288 9.8 Critical2024-11-15
CVE-2024-11120 GeoVision EOL devices - OS Command Injection — GV-VS12CWE-78 9.8 Critical2024-11-15
CVE-2024-10962 Migration, Backup, Staging – WPvivid <= 0.9.107 - Unauthenticated PHP Object Injection — WPvivid — Backup, Migration & StagingCWE-502 8.8 High2024-11-14
CVE-2024-10571 Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source — Chartify – WordPress Chart PluginCWE-98 9.8 Critical2024-11-14
CVE-2024-2550 PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway Using a Specially Crafted Packet — Cloud NGFWCWE-476 7.5AIHighAI2024-11-14
CVE-2024-2551 PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet — Cloud NGFWCWE-476 7.5AIHighAI2024-11-14
CVE-2024-9472 PAN-OS: Firewall Denial of Service (DoS) Using Specially Crafted Traffic — Cloud NGFWCWE-476 7.5AIHighAI2024-11-14
CVE-2024-9186 Automation By Autonami < 3.3.0 - Unauthenticated SQLi — Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit 9.8AICriticalAI2024-11-14
CVE-2024-28028 Intel Neural Compressor 安全漏洞 — Intel(R) Neural Compressor software 7.5 High2024-11-13
CVE-2024-33624 Intel PROSet/Wireless WiFi Software driver 输入验证错误漏洞 — Intel(R) PROSet/Wireless WiFi software for Windows 4.3 Medium2024-11-13
CVE-2024-32048 Intel Distribution of OpenVINO(TM) Toolkit 输入验证错误漏洞 — Intel(R) Distribution of OpenVINO(TM) Model Server software 6.5 Medium2024-11-13
CVE-2024-28049 Intel PROSet/Wireless Software和Intel Killer 安全漏洞 — Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi wireless products 5.7 Medium2024-11-13
CVE-2024-24984 Intel Wireless Bluetooth 输入验证错误漏洞 — Intel(R) Wireless Bluetooth(R) products for Windows 6.5 Medium2024-11-13
CVE-2024-23198 Intel PROSet/Wireless Software和Intel Killer 输入验证错误漏洞 — Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi products 6.6 Medium2024-11-13
CVE-2024-11028 MultiManager WP – Manage All Your WordPress Sites Easily <= 1.0.5 - Authentication Bypass via User Impersonation — MultiManager WP – Manage All Your WordPress Sites EasilyCWE-288 9.8 Critical2024-11-13
CVE-2024-10877 AFI – The Easiest Integration Plugin <= 1.92.0 - Reflected Cross-Site Scripting — AFI – The Easiest Integration PluginCWE-79 6.1 Medium2024-11-13
CVE-2024-11150 WordPress User Extra Fields <= 16.6 - Unauthenticated Arbitrary File Deletion — WordPress User Extra FieldsCWE-22 9.8 Critical2024-11-13
CVE-2024-10816 LUNA RADIO PLAYER <= 6.24.01.24 - Unauthenticated Arbitrary File Read — LUNA RADIO PLAYERCWE-22 7.5 High2024-11-13
CVE-2024-10174 WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.13 - Insecure Direct Object Reference to Unauthenticated Authorization Bypass — Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time TrackerCWE-639 7.3 High2024-11-13
CVE-2024-10820 WooCommerce Upload Files <= 84.3 - Unauthenticated Arbitrary File Upload — WooCommerce Upload FilesCWE-434 9.8 Critical2024-11-13
CVE-2024-10828 Advanced Order Export For WooCommerce <= 3.5.5 - Unauthenticated PHP Object Injection via Order Details — Advanced Order Export For WooCommerceCWE-502 8.1 High2024-11-13

Vulnerabilities classified as access:pre-auth represent 18872 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.