Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18893

18893 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-2541 Popup Builder <= 4.3.6 - Sensitive Information Exposure via Imported Subscribers CSV File — Popup Builder – Create highly converting, mobile friendly marketing popups.CWE-200 5.3 Medium2024-08-29
CVE-2024-6551 GiveWP <= 3.15.1 - Unauthenticated Full Path Disclosure — GiveWP – Donation Plugin and Fundraising PlatformCWE-200 5.3 Medium2024-08-29
CVE-2024-5857 Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary Media Deletion — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms FreeCWE-862 5.3 Medium2024-08-29
CVE-2024-45043 OpenTelemetry Collector AWS Firehose Receiver Authentication Bypass Vulnerability — opentelemetry-collector-contribCWE-200 5.3 Medium2024-08-28
CVE-2024-20446 Cisco NX-OS Software DHCPv6 Relay Agent Denial of Service Vulnerability — Cisco NX-OS SoftwareCWE-476 8.6 High2024-08-28
CVE-2024-8195 Permalink Manager Lite <= 2.4.4 - Missing Authorization to Unauthenticated Sensitive Information Exposure — Permalink Manager LiteCWE-862 5.3 Medium2024-08-28
CVE-2024-6450 Reflected XSS in HyperView Geoportal Toolkit — Geoportal ToolkitCWE-79 6.1AIMediumAI2024-08-28
CVE-2024-6449 Arbitrary cross-domain file inclusion in HyperView Geoportal Toolkit — Geoportal ToolkitCWE-942 6.5AIMediumAI2024-08-28
CVE-2024-7447 Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary Media Upload — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms FreeCWE-862 5.3 Medium2024-08-28
CVE-2024-39771 Safie QBiC CLOUD CC-2L和Safie One 安全漏洞 — QBiC CLOUD CC-2L 6.8AIMediumAI2024-08-28
CVE-2024-6448 Mollie Payments for WooCommerce <= 7.7.0 - Unauthenticated Full Path Disclosure — Mollie Payments for WooCommerceCWE-200 5.3 Medium2024-08-28
CVE-2024-8030 Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 2.0.3 - Unauthenticated PHP Object Injection — Ultimate Store Kit – Addon For WooCommerce, EDD and ElementorCWE-502 9.8 Critical2024-08-28
CVE-2024-7573 Relevanssi Live Ajax Search <= 2.4 - Unauthenticated WP_Query Argument Injection — Relevanssi Live Ajax SearchCWE-88 5.3 Medium2024-08-28
CVE-2024-45232 TYPO3 安全漏洞 — n/a 5.3AIMediumAI2024-08-28
CVE-2024-45233 TYPO3 安全漏洞 — n/a 9.1AICriticalAI2024-08-28
CVE-2024-8200 Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More <= 1.1.2 - Cross-Site Request Forgery — Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and MoreCWE-352 4.3 Medium2024-08-27
CVE-2024-8181 Flowise Authentication Bypass — Flowise 9.8 Critical2024-08-27
CVE-2024-8182 Flowise Denial of Service — Flowise 7.5 High2024-08-27
CVE-2024-43798 Chisel AUTH environment variable not respected in server entrypoint — chiselCWE-306 8.6 High2024-08-26
CVE-2024-45241 CentralSquare CryWolf 安全漏洞 — n/a 7.5AIHighAI2024-08-26
CVE-2024-45256 BYOB 安全漏洞 — n/a 9.8AICriticalAI2024-08-26
CVE-2024-6499 WordPress Button Plugin MaxButtons <= 9.7.8 - Full Path Disclosure — MaxButtons – Create buttonsCWE-200 5.3 Medium2024-08-24
CVE-2024-8120 ImageRecycle pdf & image compression <= 3.1.14 - Cross-Site Request in Several AJAX Actions — ImageRecycle pdf & image compressionCWE-352 4.7 Medium2024-08-24
CVE-2024-7568 Favicon Generator <= 1.5 - Cross-Site Request Forgery to Arbitrary File Deletion — Favicon Generator (CLOSED)CWE-352 9.6 Critical2024-08-24
CVE-2023-6987 String Locator <= 2.6.5 - Reflected Cross-Site Scripting — String locatorCWE-79 6.1 Medium2024-08-24
CVE-2024-7954 SPIP porte_plume Plugin Arbitrary PHP Execution — SPIPCWE-95 9.8 Critical2024-08-23
CVE-2024-43477 Microsoft Entra ID Elevation of Privilege Vulnerability — Microsoft EntraCWE-284 7.5 High2024-08-23
CVE-2024-42531 EZVIZ CS-CV246 安全漏洞 — n/a 5.8AIMediumAI2024-08-23
CVE-2024-8072 Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users CWE-200 5.3 Medium2024-08-22
CVE-2024-36441 Swissphone DiCal RED 4009 安全漏洞 — n/a 7.5AIHighAI2024-08-22

Vulnerabilities classified as access:pre-auth represent 18893 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.