Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18893

18893 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-28747 ifm: Use of Hard-coded Credentials — Smart PLC AC14xx FirmwareCWE-798 9.8 Critical2024-07-09
CVE-2024-5488 SEOPress < 7.9 - Unauthenticated Object Injection — SEOPress 9.8AICriticalAI2024-07-09
CVE-2024-5441 Modern Events Calendar <= 7.11.0 - Authenticated (Subscriber+) Arbitrary File Upload — Modern Events CalendarCWE-434 8.8 High2024-07-09
CVE-2024-6171 Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - IP Address Spoofing to Antispam Bypass — Unlimited Elements For ElementorCWE-348 5.3 Medium2024-07-09
CVE-2024-37173 [Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI) — SAP CRM WebClient UICWE-79 6.1 Medium2024-07-09
CVE-2024-6365 Product Table by WBW <= 2.0.1 - Unauthenticated Remote Code Execution — Product Table for WooCommerce by WBWCWE-94 9.8 Critical2024-07-09
CVE-2023-50805 SAMSUNG Mobile Processor和Wearable Processor安全漏洞 — n/a 8.1 High2024-07-09
CVE-2023-50807 SAMSUNG Wearable Processor 安全漏洞 — n/a 8.1 High2024-07-09
CVE-2024-23562 HCL Domino is susceptible to an information disclosure vulnerability — Domino Server 5.3 Medium2024-07-08
CVE-2024-5753 Local File Read (LFI) by Prompt Injection via Postgres SQL in vanna-ai/vanna — vanna-ai/vannaCWE-89 9.1AICriticalAI2024-07-05
CVE-2024-38346 Apache CloudStack: Unauthenticated cluster service port leads to remote execution — Apache CloudStackCWE-94 10.0 -2024-07-05
CVE-2024-39864 Apache CloudStack: Integration API service uses dynamic port when disabled — Apache CloudStackCWE-665 9.1 -2024-07-05
CVE-2024-5943 Nested Pages <= 3.2.7 - Cross-Site Request Forgery to Local File Inclusion — Nested PagesCWE-352 8.8 High2024-07-04
CVE-2024-1573 Mitsubishi Electric MC Works64 授权问题漏洞 — GENESIS64CWE-306 5.9 Medium2024-07-04
CVE-2024-31223 Fides Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL — fidesCWE-497 5.3 Medium2024-07-03
CVE-2024-6427 Uncontrolled Resource Consumption vulnerability in MESbook — MESbookCWE-400 7.5 High2024-07-03
CVE-2024-4543 Snippet Shortcodes <= 4.1.4 - Cross-Site Request Forgery — Snippet ShortcodesCWE-352 4.3 Medium2024-07-03
CVE-2024-6099 LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User Registration — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-420 5.3 Medium2024-07-02
CVE-2024-6088 LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration Bypass — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-862 5.3 Medium2024-07-02
CVE-2024-4836 LFI in sites managed by Edito CMS — Edito CMSCWE-552 7.5 High2024-07-02
CVE-2023-41918 Missing Authentication for Critical Function in Kiloview P1/P2 devices — P1/P2CWE-306 10.0 Critical2024-07-02
CVE-2024-5544 Media Library Assistant <= 3.17 - Reflected Cross-Site Scripting — Media Library AssistantCWE-79 6.1 Medium2024-07-02
CVE-2024-5545 Motors – Car Dealer, Classifieds & Listing <= 1.4.9 - Missing Authorization — Motors – Car Dealership & Classified Listings PluginCWE-862 5.3 Medium2024-07-02
CVE-2024-6172 Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.25 - Unauthenticated SQL Injection via unsubscribe — Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPressCWE-89 9.8 Critical2024-07-02
CVE-2024-39891 Twilio Authy API 安全漏洞 — n/a 5.3 Medium2024-07-02
CVE-2024-37146 GHSL-2023-248: Flowise xss in /api/v1/credentials/id — FlowiseCWE-79 6.1 Medium2024-07-01
CVE-2024-37145 GHSL-2023-247: Flowise xss in /api/v1/chatflows-streaming/id — FlowiseCWE-79 6.1 Medium2024-07-01
CVE-2024-36423 GHSL-2023-246: Flowise xss in /api/v1/public-chatflows/id — FlowiseCWE-79 6.1 Medium2024-07-01
CVE-2024-21586 Junos OS: SRX Series and NFX Series: Specific valid traffic leads to a PFE crash — Junos OSCWE-754 7.5 High2024-07-01
CVE-2024-36422 GHSL-2023-245: Flowise xss in api/v1/chatflows/id — FlowiseCWE-79 6.1 Medium2024-07-01

Vulnerabilities classified as access:pre-auth represent 18893 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.