Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18882

18882 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-20458 Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities — Cisco Analog Telephone Adaptor (ATA) SoftwareCWE-78 8.2 High2024-10-16
CVE-2024-20421 Cisco ATA 190 Series Analog Telephone Adapter Firmware Cross-Site Request Forgery Vulnerability — Cisco Analog Telephone Adaptor (ATA) SoftwareCWE-352 7.1 High2024-10-16
CVE-2024-9893 Nextend Social Login Pro <= 3.1.14 - Authentication Bypass via WordPress.com OAuth provider — Nextend Social Login ProCWE-288 9.8 Critical2024-10-16
CVE-2020-36841 WooCommerce Smart Coupons <= 4.6.0 - Unauthenticated Coupon Creation — WooCommerce Smart CouponsCWE-285 5.3 Medium2024-10-16
CVE-2023-32193 Norman API Cross-site Scripting Vulnerability — normanCWE-80 8.3 High2024-10-16
CVE-2023-32192 Rancher API Server Cross-site Scripting Vulnerability — apiserverCWE-80 8.3 High2024-10-16
CVE-2023-7295 Video Grid <= 1.21 - Reflected Cross-Site Scripting — Video GridCWE-79 6.1 Medium2024-10-16
CVE-2017-20194 Formidable Form Builder < 2.05.03 - Unauthenticated Information Disclosure — Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form BuilderCWE-200 5.3 Medium2024-10-16
CVE-2017-20193 Product Vendors <= 2.0.35 - Reflected Cross Site Scripting — Product VendorsCWE-79 4.7 Medium2024-10-16
CVE-2020-36840 Timetable and Event Schedule by MotoPress <= 2.3.8 - Missing Authorization — Timetable and Event Schedule by MotoPressCWE-862 7.3 High2024-10-16
CVE-2016-15042 Frontend File Manager < 4.0 & N-Media Post Front-end Form < 1.1 & - Arbitrary File Upload — N-Media Post Front-end FormCWE-434 9.8 Critical2024-10-16
CVE-2024-9061 WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add — WP Popup Builder – Popup Forms and Marketing Lead GenerationCWE-94 7.3 High2024-10-16
CVE-2024-8507 File Manager Pro <= 8.3.9 - Cross-Site Request Forgery to Arbitrary File Upload — File Manager ProCWE-352 8.8 High2024-10-16
CVE-2020-36839 WP Lead Plus X <= 0.99 - Cross-Site Request Forgery — WordPress Landing Page – Squeeze Page – Responsive Landing Page Builder Free – WP Lead Plus XCWE-352 8.3 High2024-10-16
CVE-2019-25216 Rich Reviews <= 1.7.4 - Stored Cross-Site Scripting — Rich Reviews by StarfishCWE-79 7.2 High2024-10-16
CVE-2019-25214 ShopWP <= 2.0.4 - Missing Authorization to Stored Cross-Site Scripting — ShopWPCWE-862 7.2 High2024-10-16
CVE-2016-15041 MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance Plugin <= 3.1.2 - Stored Cross-Site Scripting — MainWP Dashboard: Self-hosted WordPress Management for AgenciesCWE-79 7.2 High2024-10-16
CVE-2018-25105 File Manager <= 3.0 - Unauthenticated Arbitrary File Upload/Download — File ManagerCWE-862 9.8 Critical2024-10-16
CVE-2022-4972 Download Monitor <= 4.7.51 - Missing Authorization to Unauthenticated Data Export — Download MonitorCWE-862 7.5 High2024-10-16
CVE-2020-36832 Indeed Membership Pro 7.3 - 8.6 - Authentication Bypass — Indeed Membership ProCWE-287 9.8 Critical2024-10-16
CVE-2017-20192 Formidable Form Builder < 2.05.03 - Unauthenticated Stored Cross-Site Scripting — Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form BuilderCWE-79 8.3 High2024-10-16
CVE-2022-4971 Sassy Social Share <= 3.3.3 - Reflected Cross-Site Scripting — Social Sharing Plugin – Sassy Social ShareCWE-79 6.1 Medium2024-10-16
CVE-2024-8746 File Manager Pro <= 8.3.9 - Unauthenticated Backup File Download and Upload — File Manager ProCWE-434 7.5 High2024-10-16
CVE-2019-25215 ARI-Adminer <= 1.1.14 - Missing Authorization and No Direct File Access Restrictions — ARI Adminer – WordPress Database ManagerCWE-862 7.3 High2024-10-16
CVE-2019-25213 Advanced Access Manager <= 5.9.8.1 - Unauthenticated Arbitrary File Read — Advanced Access Manager – Access Governance for WordPressCWE-22 9.8 Critical2024-10-16
CVE-2016-15040 Kento Post View Counter <= 2.8 - SQL Injection — Kento Post View CounterCWE-89 9.8 Critical2024-10-16
CVE-2021-4448 Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization — Kaswara Modern VC AddonsCWE-862 7.3 High2024-10-16
CVE-2021-4444 Product Filter by WooBeWoo <= 1.4.9 - Missing Authorization — Product Filter for WooCommerce by WBWCWE-862 7.3 High2024-10-16
CVE-2021-4449 ZoomSounds <= 5.96 - Unauthenticated Arbitrary File Upload — ZoomSounds - WordPress Wave Audio Player with PlaylistCWE-434 9.8 Critical2024-10-16
CVE-2021-4443 WordPress Mega Menu <= 2.0.6 - Arbitrary File Creation — QuadMenu – Mega MenuCWE-434 9.8 Critical2024-10-16

Vulnerabilities classified as access:pre-auth represent 18882 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.