Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18893

18893 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2023-6813 Login by Auth0 <= 4.6.0 - Reflected Cross-Site Scripting via wle — Login by Auth0CWE-79 6.1 Medium2024-07-10
CVE-2024-6550 Gravity Forms: Multiple Form Instances <= 1.1.1 - Unauthenticated Full Path Disclosure — Gravity Forms: Multiple Form InstancesCWE-200 5.3 Medium2024-07-10
CVE-2024-25077 多款Renesas产品 安全漏洞 — n/a 8.1AIHighAI2024-07-10
CVE-2024-39899 PrivateBin allows shortening of URLs for other domains — PrivateBinCWE-305 5.3 Medium2024-07-09
CVE-2024-6237 389-ds-base: unauthenticated user can trigger a dos by sending a specific extended search request CWE-230 6.5 Medium2024-07-09
CVE-2023-50178 Fortinet FortiADC 信任管理问题漏洞 — FortiADCCWE-295 7.2 High2024-07-09
CVE-2024-26015 Fortinet FortiProxy 安全漏洞 — FortiProxyCWE-1389 3.1 Low2024-07-09
CVE-2024-27783 Fortinet FortiAIOps 跨站请求伪造漏洞 — FortiAIOpsCWE-352 7.2 High2024-07-09
CVE-2023-50179 Fortinet FortiADC 信任管理问题漏洞 — FortiADCCWE-295 4.7 Medium2024-07-09
CVE-2024-33509 Fortinet FortiWeb 信任管理问题漏洞 — FortiWebCWE-295 4.4 Medium2024-07-09
CVE-2024-39876 Siemens SINEMA Remote Connect Server 安全漏洞 — SINEMA Remote Connect ServerCWE-770 4.0 Medium2024-07-09
CVE-2024-39868 Siemens SINEMA Remote Connect Server 安全漏洞 — SINEMA Remote Connect ServerCWE-425 7.6 High2024-07-09
CVE-2024-39867 Siemens SINEMA Remote Connect 安全漏洞 — SINEMA Remote Connect ServerCWE-425 7.6 High2024-07-09
CVE-2024-30321 Siemens SIMATIC WinCC和SIMATIC PCS 安全漏洞 — SIMATIC PCS 7 V9.1CWE-359 5.9 Medium2024-07-09
CVE-2024-5992 Cliengo - Chatbot <= 3.0.2 - Missing Authorization to Unauthenticated Chatbot Settings Update — Cliengo – ChatbotCWE-862 6.5 Medium2024-07-09
CVE-2024-6168 Just Custom Fields <= 3.3.2 - Cross-Site Request Forgery via AJAX actions — Just Custom FieldsCWE-352 4.3 Medium2024-07-09
CVE-2024-3228 Social Sharing Plugin – Kiwi <= 2.1.7 - Information Disclosure — Social Sharing Plugin – KiwiCWE-200 5.3 Medium2024-07-09
CVE-2024-4100 Pricing Table <= 2.0.1 - Cross-Site Request Forgery via ajax() — Pricing TableCWE-352 5.3 Medium2024-07-09
CVE-2024-3608 Product Designer <= 1.0.33 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion — PickPlugins Product Designer for WooCommerceCWE-862 5.3 Medium2024-07-09
CVE-2024-5810 WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 <= 1.0.1 - Improper Authorization due to use of Hardcoded Credentials — WP2Speed Faster – Optimize PageSpeed Insights Score 90-100CWE-798 5.3 Medium2024-07-09
CVE-2024-5479 Easy Pixels by JEVNET <= 2.13 - Unauthenticated Stored Cross-Site Scripting — Easy PixelsCWE-79 7.2 High2024-07-09
CVE-2024-6320 ScrollTo Top <= 1.2.2 - Cross-Site Request Forgery to Arbitrary File Upload — ScrollTo TopCWE-352 8.8 High2024-07-09
CVE-2024-6321 ScrollTo Bottom <= 1.1.1 - Cross-Site Request Forgery to Arbitrary File Upload — ScrollTo BottomCWE-352 8.8 High2024-07-09
CVE-2024-6310 Advanced AJAX Page Loader <= 2.7.7 - Cross-Site Request Forgery to Arbitrary File Upload — Advanced AJAX Page LoaderCWE-352 8.8 High2024-07-09
CVE-2024-6313 Gutenberg Forms <= 2.2.9 - Unauthenticated Arbitrary File Upload — Gutenberg Forms – WordPress Form Builder PluginCWE-434 9.8 Critical2024-07-09
CVE-2024-6314 IQ Testimonials <= 2.2.7 - Unauthenticated Arbitrary File Upload — IQ TestimonialsCWE-434 9.8 Critical2024-07-09
CVE-2024-6309 Attachment File Icons (AF Icons) <= 1.3 - Cross-Site Request Forgery to Arbitrary File Upload — Attachment File Icons (AF Icons)CWE-352 8.8 High2024-07-09
CVE-2024-6316 Generate PDF using Contact Form 7 <= 4.1.2 - Cross-Site Request Forgery to Arbitrary File Upload — Generate PDF using Contact Form 7CWE-352 8.8 High2024-07-09
CVE-2024-6317 Generate PDF using Contact Form 7 <= 4.1.2 - Cross-Site Request Forgery to Arbitrary File Deletion — Generate PDF using Contact Form 7CWE-352 8.8 High2024-07-09
CVE-2024-6180 EventON <= 2.2.15 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting and Plugin Settings Updates — EventON – Events CalendarCWE-862 7.2 High2024-07-09

Vulnerabilities classified as access:pre-auth represent 18893 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.