Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18893

18893 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-36421 GHSL-2023-234: Flowise Cors Misconfiguration in packages/server/src/index.ts — FlowiseCWE-346 7.5 High2024-07-01
CVE-2024-36401 Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver — geoserverCWE-95 9.8 Critical2024-07-01
CVE-2024-6425 Incorrect Provision of Specified Functionality vulnerability in MESbook — MESbookCWE-684 9.1 Critical2024-07-01
CVE-2024-6424 Server-Side Request Forgery vulnerability in MESbook — MESbookCWE-918 9.3 Critical2024-07-01
CVE-2024-6387 Openssh: regresshion - race condition in ssh allows rce/dos CWE-364 8.1 High2024-07-01
CVE-2024-37763 Machform 安全漏洞 — n/a 6.1AIMediumAI2024-07-01
CVE-2023-4017 Goya <= 1.0.8.7 - Unauthenticated Reflected Cross-Site Scripting via Multiple Parameters — GoyaCWE-79 6.1 Medium2024-06-29
CVE-2024-5598 Advanced File Manager <= 5.2.4 - Sensitive Information Exposure via Directory Listing — Advanced File Manager – Ultimate File Manager for WordPress And Document Library SolutionCWE-922 7.5 High2024-06-29
CVE-2024-5889 Events Manager <= 6.4.8 - Reflected Cross-Site Scripting — Events Manager – Calendar, Bookings, Tickets, and more!CWE-79 6.1 Medium2024-06-29
CVE-2024-6265 UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sort_by' — UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WPCWE-89 9.8 Critical2024-06-29
CVE-2024-6405 Floating Social Buttons <= 1.5 - Cross-Site Request Forgery — Floating Social ButtonsCWE-352 6.1 Medium2024-06-29
CVE-2024-38528 Unlimited number of NTS-KE connections can crash ntpd-rs server — ntpd-rsCWE-770 7.5 High2024-06-28
CVE-2024-2795 SEO SIMPLE PACK <= 3.2.1 - Information Exposure — SEO SIMPLE PACKCWE-200 5.3 Medium2024-06-28
CVE-2024-6288 Conversios.io - All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce <= 7.1.0 - Reflected Cross-Site Scripting — Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-ChannelsCWE-79 4.7 Medium2024-06-28
CVE-2024-6071 PTC Creo Elements/Direct License Server Missing Authorization — Creo Elements/Direct LicenseCWE-862 10.0 Critical2024-06-27
CVE-2024-6127 BC Security Empire Path Traversal RCE — EmpireCWE-22 9.8 Critical2024-06-27
CVE-2024-6085 Path Traversal in parisneo/lollms — parisneo/lollmsCWE-22 9.1AICriticalAI2024-06-27
CVE-2024-3043 Zigbee co-ordinator realignment packet may lead to denial of service — Ember ZNet SDKCWE-829 7.5 High2024-06-27
CVE-2024-31883 IBM Security Verify Access denial of service — Security Verify AccessCWE-703 5.3 Medium2024-06-27
CVE-2024-36072 Netwrix CoSoSys Endpoint Protector 安全漏洞 — n/a 9.8AICriticalAI2024-06-27
CVE-2024-1839 Intrado 911 Emergency Gateway 安全漏洞 — 911 Emergency Gateway (EGW)CWE-89 10.0 Critical2024-06-26
CVE-2024-29175 Dell PowerProtect Data Domain 安全漏洞 — PowerProtect DDCWE-327 5.9 Medium2024-06-26
CVE-2024-23766 HMS Networks Anybus X-Gateway AB7832-F3 安全漏洞 — n/a 7.5AIHighAI2024-06-26
CVE-2024-23767 HMS Networks Anybus X-Gateway AB7832-F3 安全漏洞 — n/a 7.5AIHighAI2024-06-26
CVE-2024-4869 WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.2.0 - Unauthenticated Stored Cross-Site Scripting via Client-IP header — Cookie Banner for GDPR / CCPA – WPLP Cookie ConsentCWE-79 7.2 High2024-06-25
CVE-2024-5019 WhatsUp Gold LoadCSSUsingBasePath Directory Traversal Information Disclosure Vulnerability — WhatsUp GoldCWE-22 5.3 Medium2024-06-25
CVE-2024-5018 WhatsUp Gold LoadUsingBasePath Directory Traversal Information Disclosure Vulnerability — WhatsUp GoldCWE-22 5.3 Medium2024-06-25
CVE-2024-5017 WhatsUp Gold AppProfileImport path traversal vulnerability — WhatsUp GoldCWE-22 6.5 Medium2024-06-25
CVE-2024-5013 WhatsUp Gold InstallController Denial-of-Service Vulnerability — WhatsUp GoldCWE-400 7.5 High2024-06-25
CVE-2024-5012 WhatsUp Gold Missing Authentication GetWindowsCredential Information Disclosure Vulnerability — WhatsUp GoldCWE-287 8.6 High2024-06-25

Vulnerabilities classified as access:pre-auth represent 18893 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.