Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18893

18893 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-4319 Advanced Contact form 7 DB <= 2.0.2 - Missing Authorization to Unauthenticated Information Disclosure — Advanced Contact form 7 DBCWE-862 5.3 Medium2024-06-11
CVE-2024-36360 awkblog 安全漏洞 — awkblog 9.8AICriticalAI2024-06-11
CVE-2023-7264 Build App Online <= 1.0.22 - Account Takeover via Weak Password Reset Mechanism — Build App OnlineCWE-640 8.1 High2024-06-11
CVE-2024-28164 Information Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures) — SAP NetWeaver AS JavaCWE-200 5.3 Medium2024-06-11
CVE-2024-34686 Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI) — SAP CRM WebClient UICWE-79 6.1 Medium2024-06-11
CVE-2024-22279 GoRouter Denial of Service Attack — Routing ReleaseCWE-444 5.9 Medium2024-06-10
CVE-2024-36407 SuiteCRM unauthenticated user password reset on php7 — SuiteCRMCWE-640 3.7 Low2024-06-10
CVE-2024-35307 Argument Injection Leading to Remote Code Execution in Realtime Graph Extension — Pandora FMSCWE-88 9.8 -2024-06-10
CVE-2024-37393 SecurEnvoy MFA 安全漏洞 — n/a 9.1 -2024-06-10
CVE-2024-5654 CF7 Google Sheets Connector <= 5.0.9 - Missing Authorization to Limited Site Configuration Update — GSheetConnector for CF7 – Connect Contact Form 7 to Google Sheets and Send Form Submissions in Real TimeCWE-862 6.5 Medium2024-06-08
CVE-2024-5613 Formula <= 0.5.1 - Reflected Cross-Site Scripting via quality_customizer_notify_dismiss_action — FormulaCWE-79 6.1 Medium2024-06-08
CVE-2024-5638 Formula <= 0.5.1 - Reflected Cross-Site Scripting via ti_customizer_notify_dismiss_recommended_plugins — FormulaCWE-79 6.1 Medium2024-06-08
CVE-2024-5382 Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to MA Template Creation or Modification — Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template KitsCWE-862 6.5 Medium2024-06-07
CVE-2024-5599 FileOrganizer <= 1.0.7 - Sensitive Information Exposure via Directory Listing — FileOrganizer – WordPress File ManagerCWE-922 7.5 High2024-06-07
CVE-2024-5542 Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via Navigation Menu Widget — Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template KitsCWE-79 7.2 High2024-06-07
CVE-2023-5424 WS Form LITE <= 1.9.217 - Unauthenticated CSV Injection — WS Form LITE – Drag & Drop Contact Form BuilderCWE-1236 4.7 Medium2024-06-07
CVE-2024-4620 ArForms < 6.6 - Unauthenticated RCE — ARForms - Premium WordPress Form Builder Plugin 9.8 -2024-06-07
CVE-2024-30163 Invision Community 安全漏洞 — n/a 9.8 -2024-06-07
CVE-2024-5130 Incorrect Authorization in lunary-ai/lunary — lunary-ai/lunaryCWE-862 5.3AIMediumAI2024-06-06
CVE-2024-5552 ReDoS in kubeflow/kubeflow — kubeflow/kubeflowCWE-1333 7.5AIHighAI2024-06-06
CVE-2024-3033 Improper Authorization in mintplex-labs/anything-llm — mintplex-labs/anything-llmCWE-863 8.2AIHighAI2024-06-06
CVE-2024-35178 Jupyter server on Windows discloses Windows user password hash — jupyter_serverCWE-200 7.5 High2024-06-06
CVE-2024-37152 Unauthenticated Access to sensitive settings in Argo CD — argo-cdCWE-287 5.3 Medium2024-06-06
CVE-2024-5684 ID Charger Connect & Pro - JWT-Null-Algorithm — ID Charger Connect & ProCWE-345 6.3 Medium2024-06-06
CVE-2024-0972 BuddyPress Members Only <= 3.4.8 - Improper Access Control to Sensitive Information Exposure via REST API — BuddyPress Members OnlyCWE-284 5.3 Medium2024-06-06
CVE-2024-5153 Startklar Elementor Addons <= 1.7.15 - Unauthenticated Path Traversal to Arbitrary Directory Deletion — Startklar Elementor AddonsCWE-22 9.1 Critical2024-06-06
CVE-2024-1175 WP-Recall – Registration, Profile, Commerce & More <= 16.26.6 - Unauthenticated Payment Deletion via delete_payment — WP-Recall – Registration, Profile, Commerce & MoreCWE-862 5.3 Medium2024-06-06
CVE-2024-5615 Open Graph <= 1.11.2 - Unauthenticated Sensitive Information Exposure — Open GraphCWE-200 5.3 Medium2024-06-06
CVE-2024-4194 Album and Image Gallery plus Lightbox <= 2.0 - Unauthenticated Arbitrary Shortcode Execution — Album and Image Gallery Plus LightboxCWE-94 6.5 Medium2024-06-06
CVE-2023-6956 EasyAzon – Amazon Associates Affiliate Plugin <= 5.1.0 - Reflected Cross-Site Scripting via easyazon-cloaking-locale — EasyAzon – Amazon Associates Affiliate PluginCWE-79 6.1 Medium2024-06-06

Vulnerabilities classified as access:pre-auth represent 18893 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.