Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18887

18887 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-8477 Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.87 - Cross-Site Request Forgery — Brevo – Email, SMS, Web Push, Chat, and more.CWE-352 4.3 Medium2024-10-10
CVE-2024-8729 Easy Social Share Buttons <= 1.4.5 - Reflected Cross-Site Scripting — Easy Social Share ButtonsCWE-79 6.1 Medium2024-10-10
CVE-2024-9377 Products, Order & Customers Export for WooCommerce <= 2.0.15 - Reflected Cross-Site Scripting — Export Products, Orders & Customers for WooCommerceCWE-79 6.1 Medium2024-10-10
CVE-2024-9581 Shortcodes AnyWhere <= 1.0.1 - Unauthenticated Arbitrary Shortcode Execution — Shortcodes AnyWhereCWE-94 7.3 High2024-10-10
CVE-2024-9065 WP Helper Premium <= 4.6.1 - Missing Authorization in whp_smtp_send_mail_test — WP Helper PremiumCWE-862 5.3 Medium2024-10-10
CVE-2024-9518 UserPlus <= 2.0 - Unauthenticated Privilege Escalation — User registration & user profile – UserPlusCWE-269 9.8 Critical2024-10-10
CVE-2024-8513 QA Analytics <= 4.1.1.1 - Missing Authorization to Unauthenticated Settings Update — QA Assistants – Driven by dataCWE-862 5.3 Medium2024-10-10
CVE-2024-9205 Maximum Products per User for WooCommerce <= 4.2.8 - Reflected Cross-Site Scripting — Maximum Products per User for WooCommerceCWE-79 6.1 Medium2024-10-10
CVE-2024-39525 Junos OS and Junos OS Evolved: When BGP traceoptions is enabled, receipt of specially crafted BGP packet causes RPD crash — Junos OSCWE-755 7.5 High2024-10-09
CVE-2024-39516 Junos OS and Junos OS Evolved: With certain BGP options enabled, receipt of specifically malformed BGP update causes RPD crash — Junos OSCWE-125 7.5 High2024-10-09
CVE-2024-39515 Junos OS and Junos OS Evolved: With BGP traceoptions enabled, receipt of specifically malformed BGP update causes RPD crash — Junos OSCWE-1288 7.5 High2024-10-09
CVE-2024-38815 VMware NSX 安全漏洞 — VMware NSX, VMware Cloud FoundationCWE-79 4.3 Medium2024-10-09
CVE-2024-9468 PAN-OS: Firewall Denial of Service (DoS) via a Maliciously Crafted Packet — Cloud NGFWCWE-787 7.5AIHighAI2024-10-09
CVE-2024-9465 Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure — ExpeditionCWE-89 9.1AICriticalAI2024-10-09
CVE-2024-9463 Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure — ExpeditionCWE-78 10.0AICriticalAI2024-10-09
CVE-2024-43610 Copilot Studio Information Disclosure Vulnerability — Microsoft Copilot StudioCWE-200 7.4 High2024-10-09
CVE-2024-43488 Visual Studio Code extension for Arduino Remote Code Execution Vulnerability — Visual Studio CodeCWE-306 8.8 High2024-10-08
CVE-2024-47011 Ivanti Avalanche 安全漏洞 — AvalancheCWE-22 7.5 High2024-10-08
CVE-2024-47010 Ivanti Avalanche 安全漏洞 — AvalancheCWE-22 7.3 High2024-10-08
CVE-2024-47009 Ivanti Avalanche 安全漏洞 — AvalancheCWE-22 7.3 High2024-10-08
CVE-2024-47008 Ivanti Avalanche 安全漏洞 — AvalancheCWE-918 7.5 High2024-10-08
CVE-2024-47007 Ivanti Avalanche 安全漏洞 — AvalancheCWE-476 7.5 High2024-10-08
CVE-2024-9207 BuddyPress Docs <= 2.2.3 - Reflected Cross-Site Scripting — BuddyPress DocsCWE-79 6.1 Medium2024-10-08
CVE-2024-8629 WooCommerce Multilingual & Multicurrency with WPML <= 5.3.7 - Reflected Cross-Site Scripting — WPML Multilingual & Multicurrency for WooCommerceCWE-79 6.1 Medium2024-10-08
CVE-2024-47563 Siemens SINEC Security Monitor 路径遍历漏洞 — SINEC Security MonitorCWE-22 5.3 Medium2024-10-08
CVE-2024-46887 Siemens SIMATIC S7-1500 CPU 安全漏洞 — SIMATIC Drive Controller CPU 1504D TFCWE-288 5.3 Medium2024-10-08
CVE-2023-52952 Siemens HiMed Cockpit 安全漏洞 — HiMed Cockpit 12 proCWE-424 8.5 High2024-10-08
CVE-2024-8943 LatePoint <= 5.0.12 - Authentication Bypass — LatePoint PluginCWE-288 9.8 Critical2024-10-08
CVE-2024-8911 LatePoint <= 5.0.11 - Unauthenticated Arbitrary User Password Change via SQL Injection — LatePoint PluginCWE-89 9.8 Critical2024-10-08
CVE-2024-44349 Anteeo WMS 安全漏洞 — n/a 9.8AICriticalAI2024-10-08

Vulnerabilities classified as access:pre-auth represent 18887 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.