Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18893

18893 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-36444 Swissphone DiCal RED 4009 安全漏洞 — n/a 5.3AIMediumAI2024-08-22
CVE-2024-36445 Swissphone DiCal RED 4009 安全漏洞 — n/a 9.8AICriticalAI2024-08-22
CVE-2024-42772 Kashipara Hotel Management System 安全漏洞 — n/a 5.3AIMediumAI2024-08-22
CVE-2024-42773 Kashipara Hotel Management System 安全漏洞 — n/a 7.5AIHighAI2024-08-22
CVE-2024-42774 Kashipara Hotel Management System 安全漏洞 — n/a 7.5AIHighAI2024-08-22
CVE-2024-42775 Kashipara Hotel Management System 安全漏洞 — n/a 7.5AIHighAI2024-08-22
CVE-2024-45163 Mirai Botnet 安全漏洞 — n/a 7.5AIHighAI2024-08-22
CVE-2024-28987 SolarWinds Web Help Desk Hardcoded Credential Vulnerability — Web Help DeskCWE-798 9.1 Critical2024-08-21
CVE-2024-20486 Cisco Identity Services Engine Cross-Site Request Forgery Vulnerability — Cisco Identity Services Engine SoftwareCWE-352 6.5 Medium2024-08-21
CVE-2024-20488 Cisco Unified Communications Manager Cross-Site Scripting Vulnerability — Cisco Unified Communications ManagerCWE-79 6.1 Medium2024-08-21
CVE-2024-20375 Cisco Unified Communications Manager 安全漏洞 — Cisco Unified Communications ManagerCWE-787 8.6 High2024-08-21
CVE-2024-21690 Atlassian Confluence Data Center and Server 安全漏洞 — Confluence Data Center 9.6AICriticalAI2024-08-21
CVE-2024-43410 Russh has an OOM Denial of Service due to allocation of untrusted amount — russhCWE-770 7.5 High2024-08-21
CVE-2024-5335 Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 1.6.4 - Unauthenticated PHP Object Injection — Ultimate Store Kit – Addon For WooCommerce, EDD and ElementorCWE-502 9.8 Critical2024-08-21
CVE-2024-6339 Phlox PRO <= 5.16.4 - Reflected Cross-Site Scripting via Search Parameters — Phlox PROCWE-79 6.1 Medium2024-08-21
CVE-2024-6568 Flamix: Bitrix24 and Contact Form 7 integrations <= 3.1.0 - Unauthenticated Full Path Disclosure — Flamix: Bitrix24 and Contact Form 7 integrationsCWE-200 5.3 Medium2024-08-21
CVE-2024-7651 App Builder – Create Native Android & iOS Apps On The Flight <= 4.3.3 - Unauthenticated Limited SQL Injection via app-builder-search — App Builder – Create Native Android & iOS Apps On The FlightCWE-89 5.6 Medium2024-08-21
CVE-2024-7090 LH Add Media From Url <= 1.23 - Reflected Cross-Site Scripting — LH Add Media From UrlCWE-79 6.1 Medium2024-08-21
CVE-2024-7647 OTA Sync Booking Engine Widget 1.2.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting — OTA Sync Booking Engine WidgetCWE-352 6.1 Medium2024-08-21
CVE-2024-7032 Smart Online Order for Clover <= 1.5.6 - Missing Authorization to Plugin Deactivation and Data Deletion — Smart Online Order for CloverCWE-862 6.5 Medium2024-08-21
CVE-2024-7390 WP Testimonial Widget <= 3.1 - Missing Authorization — WP Testimonial WidgetCWE-862 5.3 Medium2024-08-21
CVE-2024-7134 LiquidPoll <= 3.3.78 - Unauthenticated Stored Cross-Site Scripting via form_data Parameter — LiquidPoll – Polls, Surveys, NPS and Feedback ReviewsCWE-79 7.2 High2024-08-21
CVE-2024-5880 Hide My Site <= 2.2 - Unauthenticated Information Exposure — Hide My SiteCWE-200 4.3 Medium2024-08-21
CVE-2024-7854 Woo Inquiry <= 0.1 - Unauthenticated SQL Injection — Woo InquiryCWE-89 10.0 Critical2024-08-21
CVE-2024-6847 SmartSearch WP <= 2.4.4 - Unauthenticated SQLi — Chatbot with ChatGPT WordPress 9.8AICriticalAI2024-08-20
CVE-2024-5940 GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings Update — GiveWP – Donation Plugin and Fundraising PlatformCWE-862 6.5 Medium2024-08-20
CVE-2024-5939 GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Limited Information Exposure — GiveWP – Donation Plugin and Fundraising PlatformCWE-862 5.3 Medium2024-08-20
CVE-2024-5932 GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution — GiveWP – Donation Plugin and Fundraising PlatformCWE-502 10.0 Critical2024-08-20
CVE-2024-7850 BP Profile Search <= 5.7.5 - Cross-Site Request Forgery to Reflected Cross-Site Scripting — BP Profile SearchCWE-352 6.1 Medium2024-08-20
CVE-2024-43379 TruffleHog has a Blind SSRF in some Detectors — trufflehogCWE-918 3.4 Low2024-08-19

Vulnerabilities classified as access:pre-auth represent 18893 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.