Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18885

18885 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-21172 Oracle Hospitality Applications 安全漏洞 — Oracle Hospitality OPERA 5 9.0 Critical2024-10-15
CVE-2024-45276 MB connect line/Helmholz: tmp directory exposed via webservice — mbNET.miniCWE-306 7.5 High2024-10-15
CVE-2024-45275 MB connect line/Helmholz: Hardcoded user accounts with hard-coded passwords — mbNET.miniCWE-798 9.8 Critical2024-10-15
CVE-2024-45274 MB connect line/Helmholz: Remote code execution via confnet service — mbNET.miniCWE-306 9.8 Critical2024-10-15
CVE-2024-45273 MB connect line/Helmholz: Weak encryption of configuration file — mbNET.miniCWE-261 8.4 High2024-10-15
CVE-2024-45272 MB connect line/Helmholz: Generation of weak passwords vulnerability — mbCONNECT24CWE-1391 7.5 High2024-10-15
CVE-2024-45271 MB connect line/Helmholz: Remote code execution due to improper input validation — mbNET.miniCWE-94 8.4 High2024-10-15
CVE-2024-47944 Missing Protection Mechanism for Alternate Hardware Interface — IoT Interface & CMC III Processing UnitCWE-1299 6.8 -2024-10-15
CVE-2024-9984 Ragic Enterprise Cloud Database - Missing Authentication — Enterprise Cloud DatabaseCWE-306 9.8 Critical2024-10-15
CVE-2024-9983 Ragic Enterprise Cloud Database - Arbitrary File Read through Path Traversal — Enterprise Cloud DatabaseCWE-23 7.5 High2024-10-15
CVE-2024-9982 ESi Technology AIM LINE Marketing Platform - SQL Injection — AIM LINE Marketing PlatformCWE-89 9.8 Critical2024-10-15
CVE-2024-9837 AADMY – Add Auto Date Month Year Into Posts <= 2.0.1 - Unauthenticated Arbitrary Shortcode Execution — AADMY – Add Auto Date Month Year Into PostsCWE-94 7.3 High2024-10-15
CVE-2024-9972 ChanGate Property Management System - SQL Injection — Property Management SystemCWE-89 9.8 Critical2024-10-15
CVE-2024-9944 WooCommerce <= 9.0.2 - Unauthenticated HTML Injection — WooCommerceCWE-79 5.3 Medium2024-10-15
CVE-2024-9548 Slimstat Analytics <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting — SlimStat AnalyticsCWE-79 7.2 High2024-10-14
CVE-2024-9546 WPIDE <= 3.4.9 - Unauthenticated Full Path Dislcosure — WPIDE – File Manager & Code EditorCWE-200 5.3 Medium2024-10-14
CVE-2024-6762 Jetty PushSessionCacheFilter can cause remote DoS attacks — JettyCWE-400 3.1 Low2024-10-14
CVE-2024-9924 Hgiga OAKlouds - Arbitrary File Read And Delete — OAKloudsCWE-36 9.8 Critical2024-10-14
CVE-2024-9922 TEAMPLUS TECHNOLOGY Team+ - Arbitrary File Read through Path Traversal — team+CWE-23 7.5 High2024-10-14
CVE-2024-9921 TEAMPLUS TECHNOLOGY Team+ - SQL Injection — team+CWE-89 9.8 Critical2024-10-14
CVE-2024-8760 Stackable – Page Builder Gutenberg Blocks <= 3.13.6 - Unauthenticated CSS Injection — Stackable – Page Builder Gutenberg BlocksCWE-94 5.3 Medium2024-10-12
CVE-2024-9047 WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php — Iptanus File UploadCWE-22 9.8 Critical2024-10-12
CVE-2024-9670 2D Tag Cloud <= 6.0.2 - Reflected Cross-Site Scripting via add_query_arg Parameter — 2D Tag CloudCWE-79 6.1 Medium2024-10-12
CVE-2024-9778 ImagePress – Image Gallery <= 1.2.2 - Cross-Site Request Forgery to Plugin Settings Update — ImagePress – Image GalleryCWE-352 4.3 Medium2024-10-12
CVE-2024-9592 Easy PayPal Gift Certificate <= 1.2.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting via wpppgc_plugin_options — Easy PayPal Gift CertificateCWE-352 6.1 Medium2024-10-12
CVE-2024-47507 Junos OS and Junos OS Evolved: BGP update message containing aggregator attribute with an ASN value of zero (0) is accepted — Junos OSCWE-754 5.8 Medium2024-10-11
CVE-2024-47506 Junos OS: SRX Series: A large amount of traffic being processed by ATP Cloud can lead to a PFE crash — Junos OSCWE-833 5.9 Medium2024-10-11
CVE-2024-47504 Junos OS: SRX5000 Series: Receipt of a specific malformed packet will cause a flowd crash — Junos OSCWE-1287 7.5 High2024-10-11
CVE-2024-47503 Junos OS: SRX4600 and SRX5000 Series: Sequence of specific PIM packets causes a flowd crash — Junos OSCWE-754 6.5 Medium2024-10-11
CVE-2024-47502 Junos OS Evolved: TCP session state is not always cleared on the Routing Engine leading to DoS — Junos OS EvolvedCWE-770 7.5 High2024-10-11

Vulnerabilities classified as access:pre-auth represent 18885 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.