Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18893

18893 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-7589 OpenSSH pre-authentication async signal safety issue — FreeBSD 9.8AICriticalAI2024-08-11
CVE-2024-7574 Christmasify! <= 1.5.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Christmasify!CWE-352 6.1 Medium2024-08-10
CVE-2024-7649 Opal Membership <= 1.2.4 - Unauthenticated Stored Cross-Site Scripting — Opal MembershipCWE-79 6.1 Medium2024-08-10
CVE-2024-7503 WooCommerce - Social Login <= 2.7.5 - Authentication Bypass to Account Takeover — WooCommerce - Social LoginCWE-288 9.8 Critical2024-08-10
CVE-2024-42468 Path traversal (CometVisu) — openhab-webuiCWE-22 5.3 Medium2024-08-09
CVE-2024-42467 CometVisu Backend for openHAB affected by SSRF/XSS — openhab-webuiCWE-918 10.0 Critical2024-08-09
CVE-2024-42470 CometVisu Backend for openHAB has a sensitive information disclosure vulnerability — openhab-webuiCWE-862 6.5 Medium2024-08-09
CVE-2024-6562 affiliate-toolkit <= 3.5.5 - Unauthenticated Full Path Dislcosure — affiliate-toolkit – Multi-Network Affiliate & Amazon Product DisplayCWE-200 5.3 Medium2024-08-09
CVE-2024-7410 My Custom CSS PHP & ADS <= 3.3 - Unauthenticated Full Path Disclosure — My Custom CSS PHP & ADSCWE-200 5.3 Medium2024-08-09
CVE-2024-7412 No Update Nag <= 1.4.12 - Unauthenticated Full Path Disclosure — No Update NagCWE-200 5.3 Medium2024-08-09
CVE-2024-7414 PDF Builder for WPForms <= 1.2.116 - Unauthenticated Full Path Disclosure — PDF Builder for WPFormsCWE-200 5.3 Medium2024-08-09
CVE-2024-7416 Reveal Template <= 3.7 - Unauthenticated Full Path Disclosure — Reveal TemplateCWE-200 5.3 Medium2024-08-09
CVE-2024-7382 Linkify Text <= 1.9.1 - Unauthenticated Full Path Disclosure — Linkify TextCWE-200 5.3 Medium2024-08-09
CVE-2024-7413 Obfuscate Email <= 3.8.1 - Unauthenticated Full Path Disclosure — Obfuscate EmailCWE-200 5.3 Medium2024-08-09
CVE-2024-40480 Online Exam System 安全漏洞 — n/a 9.8AICriticalAI2024-08-09
CVE-2024-41570 Havoc 安全漏洞 — n/a 5.3AIMediumAI2024-08-09
CVE-2024-42001 Vonets WiFi Bridges Forced Browsing — VAR1200-HCWE-425 8.6 High2024-08-08
CVE-2024-39791 Vonets WiFi Bridges Stack-based Buffer Overflow — VAR1200-HCWE-121 10.0 Critical2024-08-08
CVE-2024-39815 Vonets WiFi Bridges Improper Check or Handling of Exceptional Conditions — VAR1200-HCWE-703 9.1 Critical2024-08-08
CVE-2024-41936 Vonets WiFi Bridges Path Traversal — VAR1200-HCWE-22 7.5 High2024-08-08
CVE-2024-29082 Vonets WiFi Bridges Improper Access Control — VAR1200-HCWE-284 8.6 High2024-08-08
CVE-2024-41161 Vonets WiFi Bridges Use of Hard-coded Credentials — VAR1200-HCWE-798 7.5 High2024-08-08
CVE-2024-6552 Booking for Appointments and Events Calendar – Amelia <= 1.2 - Unauthenticated Full Path Disclosure — Booking for Appointments and Events Calendar – AmeliaCWE-200 5.3 Medium2024-08-08
CVE-2024-6254 Brizy – Page Builder <= 2.5.1 - Cross-Site Request Forgery — Brizy – Page BuilderCWE-20 4.3 Medium2024-08-08
CVE-2024-7492 MainWP Child Reports <= 2.2 - Cross-Site Request Forgery to Arbitrary Options Update — MainWP Child ReportsCWE-352 8.8 High2024-08-08
CVE-2024-7350 Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress 1.1.6 - 1.1.7 - Authentication Bypass to Account Takeover — Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPressCWE-288 9.8 Critical2024-08-08
CVE-2024-6893 Journyx Unauthenticated XML External Entities Injection — Journyx (jtime)CWE-611 9.8AICriticalAI2024-08-07
CVE-2024-20451 Cisco Small Business SPA300 Series IP Phones和Cisco Small Business SPA500 Series IP Phones 安全漏洞 — Cisco Small Business IP PhonesCWE-120 7.5 High2024-08-07
CVE-2024-20454 Cisco Small Business SPA500 Series IP Phones和Cisco Small Business 安全漏洞 — Cisco Small Business IP PhonesCWE-120 9.8 Critical2024-08-07
CVE-2024-20450 Cisco Small Business SPA300 Series IP Phones和Cisco Small Business SPA500 Series IP Phones 安全漏洞 — Cisco Small Business IP PhonesCWE-120 9.8 Critical2024-08-07

Vulnerabilities classified as access:pre-auth represent 18893 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.