Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18892

18892 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-8175 CODESYS: web server vulnerable to DoS — CODESYS Control for BeagleBone SLCWE-754 7.5 High2024-09-25
CVE-2024-3866 Ninja Forms Contact Form <= 3.8.15 - Reflected Self-Based Cross-Site Scripting via Referer — Ninja Forms – The Contact Form Builder That Grows With YouCWE-79 4.7 Medium2024-09-25
CVE-2024-8678 Revolut Gateway for WooCommerce <= 4.17.3 - Missing Authorization to Unauthenticated Order Status Update — Revolut Gateway for WooCommerceCWE-862 5.3 Medium2024-09-25
CVE-2024-6845 SmartSearchWP < 2.4.6 - Unauthenticated OpenAI Key Disclosure — Chatbot with ChatGPT WordPress 7.5AIHighAI2024-09-25
CVE-2024-8658 myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification <= 2.7.3 - Missing Authorization to Unauthenticated Database Upgrade — Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCredCWE-862 5.3 Medium2024-09-25
CVE-2024-8275 The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection — The Events CalendarCWE-89 9.8 Critical2024-09-25
CVE-2024-8485 REST API TO MiniProgram <= 4.7.1 - Unauthenticated Arbitrary User Email Update and Privilege Escalation via Account Takeover — REST API TO MiniProgramCWE-639 9.8 Critical2024-09-25
CVE-2024-8484 REST API TO MiniProgram <= 4.7.1 - Unauthenticated SQL Injection — REST API TO MiniProgramCWE-89 7.5 High2024-09-25
CVE-2024-8476 Easy PayPal Events <= 1.2.1 - Cross-Site Request Forgery to Arbitrary Post Deletion — Easy PayPal Events & TicketsCWE-352 4.3 Medium2024-09-25
CVE-2024-8713 Kodex Posts likes <= 2.5.0 - Reflected Cross-Site Scripting — Kodex Posts likesCWE-79 6.1 Medium2024-09-25
CVE-2024-7617 Contact Form to Any API <= 1.2.4 - Unauthenticated Stored Cross-Site Scripting via Contact Form — Contact Form to Any APICWE-79 7.2 High2024-09-25
CVE-2024-8741 Beam me up Scotty – Back to Top Button <= 1.0.21 - Reflected Cross-Site Scripting — Beam me up Scotty – Back to Top ButtonCWE-79 6.1 Medium2024-09-25
CVE-2024-7426 Community by PeepSo – Social Network, Membership, Registration, User Profiles <= 6.4.6.0 - Unauthenticated Full Path Disclosure — Community by PeepSo – Download from PeepSo.comCWE-200 5.3 Medium2024-09-25
CVE-2024-8549 Simple Calendar – Google Calendar Plugin <= 3.4.2 - Reflected Cross-Site Scripting — Simple Calendar – Google Calendar PluginCWE-79 6.1 Medium2024-09-25
CVE-2024-8481 Special Text Boxes <= 6.2.4 - Unauthenticated Arbitrary Shortcode Execution — Special Text BoxesCWE-94 7.3 High2024-09-25
CVE-2024-7386 Premium Packages – Sell Digital Products Securely <= 5.9.1 - Cross-Site Request Forgery — Premium Packages – Sell Digital Products SecurelyCWE-352 4.3 Medium2024-09-25
CVE-2024-42507 Unauthenticated Command Injection Vulnerabilities in the CLI Service Accessed by the PAPI Protocol — Aruba OS 9.8 Critical2024-09-24
CVE-2024-42506 Unauthenticated Command Injection Vulnerabilities in the CLI Service Accessed by the PAPI Protocol — Aruba OS 9.8 Critical2024-09-24
CVE-2024-42505 Unauthenticated Command Injection Vulnerabilities in the CLI Service Accessed by the PAPI Protocol — Aruba OS 9.8 Critical2024-09-24
CVE-2024-8941 Path Traversal vulnerability on Scriptcase — ScriptcaseCWE-22 7.5 High2024-09-24
CVE-2023-5359 W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext — W3 Total CacheCWE-200 3.7 Low2024-09-24
CVE-2024-8914 Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam <= 2.0.1 - Unauthenticated Stored Cross-Site Scripting — Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt NamCWE-79 7.2 High2024-09-24
CVE-2024-8671 WooEvents <= 4.1.2 - Unauthenticated Arbitrary File Overwrite — WooEvents - Calendar and Event BookingCWE-22 9.1 Critical2024-09-24
CVE-2024-8623 MDTF – Meta Data and Taxonomies Filter <= 1.3.3.3 - Unauthenticated Arbitrary Shortcode Execution — MDTF – Meta Data and Taxonomies FilterCWE-94 7.3 High2024-09-24
CVE-2024-8791 Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress <= 1.8.1.14 - Insecure Direct Object Reference to Account Takeover and Privilege Escalation — Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & MoreCWE-639 9.8 Critical2024-09-24
CVE-2024-8794 BA Book Everything <= 1.6.20 - Unauthenticated Arbitrary User Password Reset — BA Book EverythingCWE-620 5.3 Medium2024-09-24
CVE-2024-8544 Pixel Cat – Conversion Pixel Manager <= 3.0.5 - Reflected Cross-Site Scripting — Pixel Cat – Conversion Pixel ManagerCWE-79 6.1 Medium2024-09-24
CVE-2024-8662 Koko Analytics <= 1.3.12 - Reflected Cross-Site Scripting — Koko Analytics – Privacy Friendly Statistics for WordPressCWE-79 6.1 Medium2024-09-24
CVE-2024-8738 Seriously Simple Stats <= 1.6.0 - Reflected Cross-Site Scripting — Seriously Simple StatsCWE-79 6.1 Medium2024-09-24
CVE-2024-8795 BA Book Everything <= 1.6.20 - Cross-Site Request Forgery to Email Address Update/Account Takeover — BA Book EverythingCWE-352 8.8 High2024-09-24

Vulnerabilities classified as access:pre-auth represent 18892 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.