Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18882

18882 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-8739 ReCaptcha Integration for WordPress <= 1.2.5 - Reflected Cross-Site Scripting — ReCaptcha Integration for WordPressCWE-79 6.1 Medium2024-11-02
CVE-2024-41745 IBM CICS TX Standard cross-site scripting — CICS TX StandardCWE-79 6.1 Medium2024-11-01
CVE-2024-10652 CHANGING Information Technology IDExpert - Reflected XSS — IDExpertCWE-79 6.1 Medium2024-11-01
CVE-2024-22733 TP-LINK MR200 安全漏洞 — n/a 7.5AIHighAI2024-11-01
CVE-2024-6479 SIP Reviews Shortcode for WooCommerce <= 1.2.3 - Authenticated (Contributor+) SQL Injection — SIP Reviews Shortcode for WooCommerceCWE-89 6.5 Medium2024-10-31
CVE-2024-9434 WPGlobus Translate Options <= 2.2.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting — WPGlobus Translate OptionsCWE-352 6.1 Medium2024-10-31
CVE-2024-9430 Get Quote For Woocommerce – Request A Quote For Woocommerce <= 1.0.0 - Missing Authorization to Unauthenticated Quote PDF and CSV Download — Get Quote For Woocommerce – Request A Quote For WoocommerceCWE-306 5.3 Medium2024-10-31
CVE-2024-9700 Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.36.0 - Insecure Direct Object Reference to Submission Manipulation — Forminator Forms – Contact Form, Payment Form & Custom Form BuilderCWE-639 5.3 Medium2024-10-31
CVE-2024-10392 AI Power: Complete AI Pack <= 1.8.89 - Unauthenticated Arbitrary File Upload — AI Puffer – Your AI engine for WordPress (formerly AI Power)CWE-434 9.8 Critical2024-10-31
CVE-2024-10544 Woo Manage Fraud Orders <= 2.6.1 - Unauthenticated Information Exposure via Log Files — Woo Manage Fraud OrdersCWE-532 5.3 Medium2024-10-31
CVE-2024-33603 LevelOne WBR-6012 信息泄露漏洞 — WBR-6012CWE-200 5.3 Medium2024-10-30
CVE-2024-33626 LevelOne WBR-6012 信息泄露漏洞 — WBR-6012CWE-200 5.3 Medium2024-10-30
CVE-2024-10108 WPAdverts – Classifieds Plugin <= 2.1.6 - Unauthenticated Stored Cross-Site Scripting via adverts_add Shortcode — WPAdverts – Classifieds PluginCWE-79 7.2 High2024-10-30
CVE-2024-8871 Pricing Tables WordPress Plugin – Easy Pricing Tables <= 3.2.5 - Reflected Cross-Site Scripting — Pricing Table WordPress Plugin – Easy Pricing TablesCWE-79 6.1 Medium2024-10-30
CVE-2024-8792 Subscribe to Comments <= 2.3 - Reflected Cross-Site Scripting — Subscribe to CommentsCWE-79 6.1 Medium2024-10-30
CVE-2024-9846 Enable Shortcodes inside Widgets,Comments and Experts <= 1.0.0 - Unauthenticated Arbitrary Shortcode Execution — Enable Shortcodes inside Widgets,Comments and ExpertsCWE-94 7.3 High2024-10-30
CVE-2024-48214 Kerui HD 3MP 1080P Tuya Camera 安全漏洞 — n/a 8.8AIHighAI2024-10-30
CVE-2024-9989 Crypto <= 2.18 - Authentication Bypass via log_in — Crypto ToolCWE-288 9.8 Critical2024-10-29
CVE-2024-9988 Crypto <= 2.19 - Authentication Bypass via register — Crypto ToolCWE-288 9.8 Critical2024-10-29
CVE-2024-9990 Crypto <= 2.15 - Cross-Site Request Forgery to Authentication Bypass — Crypto ToolCWE-352 8.8 High2024-10-29
CVE-2024-8924 Unauthenticated Blind SQL Injection in Core Platform — Now PlatformCWE-89 7.5 High2024-10-29
CVE-2024-8923 Sandbox Escape in Now Platform — Now PlatformCWE-94 9.8 Critical2024-10-29
CVE-2024-50334 Semicolon Path Injection on API /api;/config — scooldCWE-288 7.5AIHighAI2024-10-29
CVE-2024-7472 Email Injection Vulnerability in lunary-ai/lunary — lunary-ai/lunaryCWE-93 5.3AIMediumAI2024-10-29
CVE-2024-9438 SEUR Oficial <= 2.2.11 - Reflected Cross-Site Scripting — SEUR OficialCWE-80 6.1 Medium2024-10-29
CVE-2024-10048 Post Status Notifier Lite and Premium <= 1.11.6 - Reflected Cross-Site Scripting via page — Post Status NotifierCWE-79 6.1 Medium2024-10-29
CVE-2024-48572 AquilaCMS 安全漏洞 — n/a 5.3AIMediumAI2024-10-29
CVE-2024-48573 AquilaCMS 安全漏洞 — n/a 9.1AICriticalAI2024-10-29
CVE-2024-51568 CyberPanel 安全漏洞 — n/a 10.0 Critical2024-10-29
CVE-2024-10440 Sunnet eHRD CTMS - SQL Injection — eHRD CTMSCWE-89 9.8 Critical2024-10-28

Vulnerabilities classified as access:pre-auth represent 18882 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.