Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18893

18893 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-39536 Junos OS and Junos OS Evolved: Flaps of BFD sessions with authentication cause a ppmd memory leak — Junos OSCWE-401 5.3 Medium2024-07-11
CVE-2024-39535 Junos OS Evolved: ACX 7000 Series: When specific traffic is received in a VPLS scenario evo-pfemand crashes — Junos OS EvolvedCWE-754 6.5 Medium2024-07-11
CVE-2024-39533 Junos OS: QFX5000 Series and EX4600 Series: Output firewall filter is not applied if certain match criteria are used — Junos OSCWE-447 5.8 Medium2024-07-11
CVE-2024-39531 Junos OS Evolved: ACX 7000 Series: Protocol specific DDoS configuration affects other protocols — Junos OS EvolvedCWE-229 7.5 High2024-07-11
CVE-2024-39530 Junos OS: Attempting to access specific sensors on platforms not supporting these will lead to a chassisd crash — Junos OSCWE-754 7.5 High2024-07-11
CVE-2024-39529 Junos OS: SRX Series: If DNS traceoptions are configured in a DGA or tunnel detection scenario specific DNS traffic leads to a PFE crash — Junos OSCWE-134 7.5 High2024-07-11
CVE-2024-39519 Junos OS Evolved: ACX 7000 Series: Multicast traffic is looped in a multihoming EVPN MPLS scenario — Junos OS EvolvedCWE-754 6.5 Medium2024-07-11
CVE-2024-39317 Wagtail regular expression denial-of-service via search query parsing — wagtailCWE-1333 6.5 Medium2024-07-11
CVE-2024-6624 JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation — JSON API UserCWE-269 9.8 Critical2024-07-11
CVE-2024-6397 InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.44 - Authentication Bypass to Admin — InstaWP Connect – 1-click WP Staging & MigrationCWE-288 9.8 Critical2024-07-11
CVE-2024-0619 Payflex Payment Gateway <= 2.5.0 - Missing Authorization to Order Status Update — Payflex Payment GatewayCWE-862 5.3 Medium2024-07-11
CVE-2024-6554 Branda – White Label WordPress, Custom Login Page Customizer <= 3.4.18 - Unauthenticated Full Path Disclosure — Branda – White Label & Branding, Free Login Page CustomizerCWE-200 5.3 Medium2024-07-11
CVE-2024-6210 Duplicator <= 1.5.9 - Full Path Disclosure — Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & MoreCWE-200 5.3 Medium2024-07-11
CVE-2024-36435 Supermicro BMC 安全漏洞 — n/a 9.8 Critical2024-07-11
CVE-2024-6447 FULL <= 3.1.12 - Unauthenticated Stored Cross-Site Scripting via License Plan Parameter — FULL – ClienteCWE-79 7.2 High2024-07-10
CVE-2024-39517 Junos OS and Junos OS Evolved: Upon processing specific L2 traffic, rpd can hang in devices with EVPN/VXLAN configured — Junos OSCWE-754 6.5 Medium2024-07-10
CVE-2024-39514 Junos OS and Junos OS Evolved: Receiving specific traffic on devices with EVPN-VPWS with IGMP-snooping enabled will cause the rpd to crash — Junos OSCWE-703 6.5 Medium2024-07-10
CVE-2024-39565 Junos OS: J-Web: An unauthenticated, network-based attacker can perform XPATH injection attack against a device. — Junos OSCWE-643 8.8 High2024-07-10
CVE-2024-39562 Junos OS Evolved: A high rate of SSH connections causes a Denial of Service — Junos OS EvolvedCWE-772 7.5 High2024-07-10
CVE-2024-39559 Junos OS Evolved: Receipt of a specific TCP packet may result in a system crash (vmcore) on dual RE systems with NSR enabled — Junos OS EvolvedCWE-754 5.9 Medium2024-07-10
CVE-2024-39558 Junos OS and Junos OS Evolved: Receipt of specific PIM packet causes rpd crash when PIM is configured along with MoFRR — Junos OSCWE-252 6.5 Medium2024-07-10
CVE-2024-39557 Junos OS Evolved: MAC table changes cause a memory leak — Junos OS EvolvedCWE-400 6.5 Medium2024-07-10
CVE-2024-39554 Junos OS and Junos OS Evolved: BGP multipath incremental calculation is resulting in an rpd crash — Junos OSCWE-362 5.9 Medium2024-07-10
CVE-2024-38353 CodiMD - Missing Image Access Controls and Unauthorized Image Access — codimdCWE-338 5.3 Medium2024-07-10
CVE-2024-5492 Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites — NetScaler ADC 6.1AIMediumAI2024-07-10
CVE-2024-5217 Incomplete Input Validation in GlideExpression Script — Now PlatformCWE-184 9.8 Critical2024-07-10
CVE-2024-4879 Jelly Template Injection Vulnerability in ServiceNow UI Macros — Now PlatformCWE-1287 9.8 Critical2024-07-10
CVE-2024-6556 SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer <= 3.10.8 - Unauthenticated Full Path Disclosure — SmartCrawl SEO checker, analyzer & optimizerCWE-200 5.3 Medium2024-07-10
CVE-2024-6422 Pepperl+Fuchs: OIT Products can be manipulated via unintended Telnet access — OIT1500-F113-B12-CBCWE-306 9.8 Critical2024-07-10
CVE-2024-6421 Pepperl+Fuchs: Incorrectly configured FTP-Server in OIT Products — OIT1500-F113-B12-CBCWE-552 7.5 High2024-07-10

Vulnerabilities classified as access:pre-auth represent 18893 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.