Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18885

18885 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2021-4444 Product Filter by WooBeWoo <= 1.4.9 - Missing Authorization — Product Filter for WooCommerce by WBWCWE-862 7.3 High2024-10-16
CVE-2021-4449 ZoomSounds <= 5.96 - Unauthenticated Arbitrary File Upload — ZoomSounds - WordPress Wave Audio Player with PlaylistCWE-434 9.8 Critical2024-10-16
CVE-2021-4443 WordPress Mega Menu <= 2.0.6 - Arbitrary File Creation — QuadMenu – Mega MenuCWE-434 9.8 Critical2024-10-16
CVE-2024-8918 File Manager Pro <= 8.3.9 - Unauthenticated Limited JavaScript File Upload — File Manager ProCWE-434 7.4 High2024-10-16
CVE-2024-9937 Woo Manage Fraud Orders <= 2.6.1 - Reflected Cross-Site Scripting — Woo Manage Fraud OrdersCWE-79 6.1 Medium2024-10-16
CVE-2024-9105 UltimateAI <= 2.8.3 - Authentication Bypass — Ultimate AICWE-288 9.8 Critical2024-10-16
CVE-2024-9634 GiveWP – Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code Execution — GiveWP – Donation Plugin and Fundraising PlatformCWE-502 9.8 Critical2024-10-16
CVE-2024-9647 Kama SpamBlock <= 1.8.2 - Reflected Cross-Site Scripting — Kama SpamBlockCWE-79 6.1 Medium2024-10-16
CVE-2024-9652 Locatoraid Store Locator <= 3.9.47 - Reflected Cross-Site Scripting — Locatoraid Store LocatorCWE-79 6.1 Medium2024-10-16
CVE-2024-9305 AppPresser – Mobile App Framework <= 4.4.4 - Privilege Escalation and Account Takeover via Weak OTP — AppPresser – Mobile App FrameworkCWE-640 8.1 High2024-10-16
CVE-2024-9649 WP ULike <= 4.7.4 - Cross-Site Request Forgery to Statistic Deletion — WP ULike – Like & Dislike Buttons for Engagement and FeedbackCWE-352 4.3 Medium2024-10-16
CVE-2024-9104 UltimateAI <= 2.8.3 - Limited User Password Change due to Improper Empty and Missing Default Value Check — Ultimate AICWE-703 5.6 Medium2024-10-16
CVE-2024-8787 Smart Online Order for Clover <= 1.5.7 - Reflected Cross-Site Scripting — Smart Online Order for CloverCWE-79 6.1 Medium2024-10-16
CVE-2024-8541 Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons <= 2.6.5 - Reflected Cross-Site Scripting — Discount Rules for WooCommerceCWE-79 4.7 Medium2024-10-16
CVE-2024-38190 Power Platform Information Disclosure Vulnerability — Microsoft Power PlatformCWE-862 8.6 High2024-10-15
CVE-2024-21274 Oracle Fusion Middleware 安全漏洞 — Oracle WebLogic Server 7.5 High2024-10-15
CVE-2024-21262 Oracle MySQL 安全漏洞 — MySQL Connectors 6.5 Medium2024-10-15
CVE-2024-21258 Oracle E-Business Suite 安全漏洞 — Oracle Installed Base 5.3 Medium2024-10-15
CVE-2024-21260 Oracle Fusion Middleware 安全漏洞 — Oracle WebLogic Server 7.5 High2024-10-15
CVE-2024-21246 Oracle Fusion Middleware 安全漏洞 — Oracle Service Bus 7.5 High2024-10-15
CVE-2024-21234 Oracle Fusion Middleware 安全漏洞 — Oracle WebLogic Server 7.5 High2024-10-15
CVE-2024-21235 Oracle Java SE 安全漏洞 — Oracle Java SE 4.8 Medium2024-10-15
CVE-2024-21217 Oracle Java SE 安全漏洞 — Oracle Java SE 3.7 Low2024-10-15
CVE-2024-21215 Oracle Fusion Middleware 安全漏洞 — Oracle WebLogic Server 7.5 High2024-10-15
CVE-2024-21216 Oracle Fusion Middleware 安全漏洞 — Oracle WebLogic Server 9.8 Critical2024-10-15
CVE-2024-21210 Oracle Java SE 安全漏洞 — Oracle Java SE 3.7 Low2024-10-15
CVE-2024-21211 Oracle Java SE 安全漏洞 — GraalVM 3.7 Low2024-10-15
CVE-2024-21208 Oracle Java SE 安全漏洞 — Oracle Java SE 3.7 Low2024-10-15
CVE-2024-21202 Oracle PeopleSoft Enterprise PeopleTools 安全漏洞 — PeopleSoft Enterprise PeopleTools 6.1 Medium2024-10-15
CVE-2024-21190 Oracle Fusion Middleware 安全漏洞 — Oracle Global Lifecycle Management FMW Installer 7.5 High2024-10-15

Vulnerabilities classified as access:pre-auth represent 18885 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.