Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18875

18875 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-10801 WordPress User Extra Fields <= 16.5 - Unauthenticated Arbitrary File Upload — WordPress User Extra FieldsCWE-434 9.8 Critical2024-11-09
CVE-2024-10547 WP Membership <= 1.6.2 - Unauthenticated Arbitrary File Upload — WP MembershipCWE-434 9.8 Critical2024-11-09
CVE-2024-10871 Category Ajax Filter <= 2.8.2 - Unauthenticated Local File Inclusion — Category AJAX Filter – Advanced Filter for Posts & Custom Post TypesCWE-98 9.8 Critical2024-11-09
CVE-2024-10876 Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.3 - Reflected Cross-Site Scripting — Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & MoreCWE-79 6.1 Medium2024-11-09
CVE-2024-10683 Contact Form 7 - PayPal & Stripe Add-on <= 2.3.1 - Reflected Cross-Site Scripting — Contact Form 7 – PayPal & Stripe Add-onCWE-79 6.1 Medium2024-11-09
CVE-2024-8756 Quform - WordPress Form Builder <= 2.20.0 - Unauthenticated Sensitive Information Exposure — Quform - WordPress Form BuilderCWE-200 5.3 Medium2024-11-09
CVE-2024-10470 WPLMS Learning Management System for WordPress <= 4.962 - Unauthenticated Arbitrary File Read and Deletion — WPLMS Learning Management System for WordPress, WordPress LMSCWE-22 9.8 Critical2024-11-09
CVE-2024-10627 WooCommerce Support Ticket System <= 17.7 - Unauthenticated Arbitrary File Upload — WooCommerce Support Ticket SystemCWE-434 9.8 Critical2024-11-09
CVE-2024-10625 WooCommerce Support Ticket System <= 17.7 - Unauthenticated Arbitrary File Deletion — WooCommerce Support Ticket SystemCWE-22 9.8 Critical2024-11-09
CVE-2024-9226 Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages <= 1.7.6 - Reflected Cross-Site Scripting — Landing Page Cat – Coming Soon & Maintenance PagesCWE-79 6.1 Medium2024-11-09
CVE-2024-10294 CE21 Suite <= 2.2.0 - Missing Authorization to Unauthenticated Plugin Settings Change — CE21 SuiteCWE-862 6.5 Medium2024-11-09
CVE-2024-10285 CE21 Suite <= 2.2.0 - JWT Token Disclosure — CE21 SuiteCWE-200 9.8 Critical2024-11-09
CVE-2024-10284 CE21 Suite <= 2.2.0 - Authentication Bypass — CE21 SuiteCWE-288 9.8 Critical2024-11-09
CVE-2024-10586 Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation — Debug ToolCWE-862 9.8 Critical2024-11-09
CVE-2024-10588 Debug Tool <= 2.2 - Missing Authorization to Information Exposure — Debug ToolCWE-862 4.3 Medium2024-11-09
CVE-2024-9262 User Meta – User Profile Builder and User management plugin <= 3.1.1 - Insecure Direct Object Reference to Sensitive Information Exposure — User Meta – User Profile Builder and User management pluginCWE-639 6.5 Medium2024-11-09
CVE-2024-45764 Dell Enterprise SONiC OS 安全漏洞 — Enterprise SONiC OSCWE-304 9.0 Critical2024-11-08
CVE-2024-50589 Unprotected FHIR API — ElefantCWE-306 5.7 -2024-11-08
CVE-2024-50588 Unprotected Exposed Firebird Database with default credentials — ElefantCWE-1393 8.8 -2024-11-08
CVE-2024-7982 Registrations for The Events Calendar < 2.12.4 - Unauthenticated Stored XSS — Registrations for the Events Calendar 6.1 -2024-11-08
CVE-2023-27195 Trimble TM4Web 权限许可和访问控制问题漏洞 — n/a 9.8AICriticalAI2024-11-08
CVE-2024-48950 Logpoint 安全漏洞 — n/a 8.1AIHighAI2024-11-07
CVE-2024-48952 Logpoint 安全漏洞 — n/a 9.1AICriticalAI2024-11-07
CVE-2024-48953 Logpoint 安全漏洞 — n/a 9.8AICriticalAI2024-11-07
CVE-2019-20457 Brother MFC-J491DW 安全漏洞 — n/a 9.8AICriticalAI2024-11-07
CVE-2020-11926 Luvion Grand Elite 3 Connect 安全漏洞 — n/a 9.8AICriticalAI2024-11-07
CVE-2024-20418 Cisco Ultra-Reliable Wireless Backhaul Software Command Injection Vulnerability — Cisco Aironet Access Point Software (IOS XE Controller)CWE-77 10.0 Critical2024-11-06
CVE-2024-20538 Cisco Identity Services Engine Cross-Site Scripting Vulnerability — Cisco Identity Services Engine SoftwareCWE-79 6.1 Medium2024-11-06
CVE-2024-20530 Cisco Identity Services Engine Reflected Cross-Site Scripting Vulnerability — Cisco Identity Services Engine SoftwareCWE-79 6.1 Medium2024-11-06
CVE-2024-20525 Cisco Identity Services Engine Reflected Cross-Site Scripting Vulnerability — Cisco Identity Services Engine SoftwareCWE-79 6.1 Medium2024-11-06

Vulnerabilities classified as access:pre-auth represent 18875 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.