Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18893

18893 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-6843 SmartSearch WP <= 2.4.4 - Unauthenticated Stored XSS — Chatbot with ChatGPT WordPress 6.1AIMediumAI2024-08-19
CVE-2024-6330 GEO my WordPress < 4.4.0.2 - Unauthenticated RCE via LFI — GEO my WP 9.8AICriticalAI2024-08-19
CVE-2024-44069 Pi-hole 安全漏洞 — n/a 5.3AIMediumAI2024-08-19
CVE-2023-0714 Metform Elementor Contact Form Builder <= 3.2.4 - Unauthenticated Double-Extension Arbitrary File Upload — MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for ElementorCWE-434 8.1 High2024-08-17
CVE-2023-3408 Bricks <= 1.8.1 - Cross-Site Request Forgery via save_settings — BricksCWE-352 4.3 Medium2024-08-17
CVE-2023-3409 Bricks <= 1.8.1 - Cross-Site Request Forgery via reset_settings — BricksCWE-352 5.4 Medium2024-08-17
CVE-2023-4604 Slideshow, Image Slider by 2J <= 1.3.54 - Reflected Cross-Site Scripting via 'post' — Slideshow, Image Slider by 2JCWE-79 6.1 Medium2024-08-17
CVE-2023-1604 Short URL <= 1.6.8 - Cross-Site Request Forgery via configuration_page — Short URLCWE-352 4.7 Medium2024-08-17
CVE-2023-4025 Radio Player <= 2.0.73 - Missing Authorization to Player Update — Radio Player – Live Shoutcast, Icecast and Any Audio Stream PlayerCWE-862 5.3 Medium2024-08-17
CVE-2023-4730 LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.3 - Missing Authorization via init_endpoint — LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…CWE-862 5.3 Medium2024-08-17
CVE-2023-4507 Admission AppManager <= 1.0.0 - Reflected Cross-Site Scripting — Admission AppManagerCWE-79 6.1 Medium2024-08-17
CVE-2023-4024 Radio Player <= 2.0.73 - Missing Authorization to Player Deletion — Radio Player – Live Shoutcast, Icecast and Any Audio Stream PlayerCWE-862 5.3 Medium2024-08-17
CVE-2023-4027 Radio Player <= 2.0.73 - Missing Authorization to Settings Update — Radio Player – Live Shoutcast, Icecast and Any Audio Stream PlayerCWE-862 5.3 Medium2024-08-17
CVE-2022-1751 Skitter Slideshow <= 2.5.2 - Unauthenticated Server-Side Request Forgery — Skitter SlideshowCWE-918 7.2 High2024-08-17
CVE-2024-6459 News Element Elementor Blog Magazine < 1.0.6 - Unauthenticated LFI — News Element Elementor Blog Magazine 9.8AICriticalAI2024-08-17
CVE-2024-6500 InPost for WooCommerce <= 1.4.0 and InPost PL <= 1.4.4 - Missing Authorization to Unauthenticated Arbitrary File Read and Delete — InPost for WooCommerceCWE-862 10.0 Critical2024-08-17
CVE-2024-6004 Lenovo printers 安全漏洞 — PrintersCWE-770 6.5 Medium2024-08-16
CVE-2024-5210 Lenovo printers 安全漏洞 — PrintersCWE-770 6.5 Medium2024-08-16
CVE-2024-5209 Lenovo printers 安全漏洞 — PrintersCWE-770 6.5 Medium2024-08-16
CVE-2024-4782 Lenovo printers 安全漏洞 — PrintersCWE-770 6.5 Medium2024-08-16
CVE-2024-4781 Lenovo printers 安全漏洞 — PrintersCWE-770 6.5 Medium2024-08-16
CVE-2024-7501 Download Plugins and Themes from Dashboard <= 1.8.7 - Cross-Site Request Forgery — Download Plugins and Themes in ZIP from DashboardCWE-352 4.2 Medium2024-08-16
CVE-2024-7301 WordPress File Upload <= 4.24.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload — Iptanus File UploadCWE-79 7.2 High2024-08-16
CVE-2024-7422 Theme My Login <= 7.1.7 - Cross-Site Request Forgery to Settings Update — Theme My LoginCWE-352 4.3 Medium2024-08-16
CVE-2024-7630 Relevanssi <= 4.22.2 (Free) and <= 2.25.1 (Premium) - Unauthenticated Information Exposure — Relevanssi PremiumCWE-200 5.3 Medium2024-08-16
CVE-2024-25633 In eLabFTW, if administrators can create users, users can too — elabftwCWE-266 5.4 Medium2024-08-15
CVE-2024-6347 Unauthorized access to ECU functionality — AltimaCWE-285 5.1AIMediumAI2024-08-15
CVE-2024-7411 Newsletters <= 4.9.9 - Unauthenticated Full Path Disclosure — NewslettersCWE-200 5.3 Medium2024-08-15
CVE-2024-7628 MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.2 - Authentication Bypass to Account Takeover — MStore API – Create Native Android & iOS Apps On The CloudCWE-288 8.1 High2024-08-15
CVE-2024-7420 Insert PHP Code Snippet <= 1.3.6 - Cross-Site Request Forgery to Code Snippet Activate/Deactivate/Deletion — Insert PHP Code SnippetCWE-352 5.8 Medium2024-08-15

Vulnerabilities classified as access:pre-auth represent 18893 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.