Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18893

18893 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-0910 Restrict for Elementor <= 1.0.7 - Protection Mechanism Bypass — Restrict for ElementorCWE-200 5.3 Medium2024-06-06
CVE-2023-6968 The Moneytizer <= 9.6.3 - Cross-Site Request Forgery via multiple AJAX actions — The MoneytizerCWE-284 8.1 High2024-06-06
CVE-2024-36129 OpenTelemetry Collector has a Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPC — opentelemetry-collectorCWE-119 8.2 High2024-06-05
CVE-2024-20405 Cisco Finesse 安全漏洞 — Cisco Unified Contact Center EnterpriseCWE-20 4.8 Medium2024-06-05
CVE-2024-20404 Cisco Finesse 代码问题漏洞 — Cisco Unified Contact Center EnterpriseCWE-918 7.2 High2024-06-05
CVE-2024-3469 GP Premium <= 2.4.0 - Reflected Cross-Site Scripting — GP PremiumCWE-79 6.1 Medium2024-06-05
CVE-2024-5439 Blocksy <= 2.0.50 - Authenticated (Contributor+) Stored Cross-Site Scripting — BlocksyCWE-20 6.4 Medium2024-06-05
CVE-2024-2368 Mollie Forms <= 2.6.13 - Cross-Site Request Forgery to Arbitrary Post Duplication — Mollie FormsCWE-352 4.3 Medium2024-06-05
CVE-2024-2087 Brizy – Page Builder <= 2.4.43 - Unauthenticated Stored Cross-Site Scripting via Form — Brizy – Page BuilderCWE-79 7.2 High2024-06-05
CVE-2024-4295 Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash — Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPressCWE-89 9.8 Critical2024-06-05
CVE-2024-5149 BuddyForms <= 2.8.9 - Email Verification Bypass due to Insufficient Randomness — Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC)CWE-330 6.5 Medium2024-06-05
CVE-2024-5483 LearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON API — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-200 5.3 Medium2024-06-05
CVE-2024-5317 Newsletter <= 8.3.4 - Unauthenticated Stored Cross-Site Scripting via np1 — Newsletter – Send awesome emails from WordPressCWE-79 6.4 Medium2024-06-05
CVE-2024-29170 Dell PowerScale OneFS 信任管理问题漏洞 — PowerScale OneFSCWE-798 8.1 High2024-06-04
CVE-2024-5000 CODESYS: Incorrect calculation of buffer size can cause DoS on CODESYS OPC UA products — CODESYS Control for BeagleBone SLCWE-131 7.5 High2024-06-04
CVE-2024-4856 FS Product Inquiry <= 1.1.1 - Reflected XSS — FS Product Inquiry 6.1AIMediumAI2024-06-04
CVE-2024-4857 FS Product Inquiry <= 1.1.1 - Unauthenticated Stored XSS — FS Product Inquiry 6.1AIMediumAI2024-06-04
CVE-2024-4997 WPUpper Share Buttons <= 3.43 - Missing Authorization — WPUpper Share ButtonsCWE-862 5.3 Medium2024-06-04
CVE-2024-2382 Authorize.net Payment Gateway For WooCommerce <= 8.0 - Insufficient Verification of Data Authenticity to Unauthenticated Payment Bypass — Authorize.net Payment Gateway For WooCommerceCWE-345 5.3 Medium2024-06-04
CVE-2024-1718 Claudio Sanches – Checkout Cielo for WooCommerce <= 1.1.0 - Insufficient Verification of Data Authenticity to Order Payment Status Update — Claudio Sanches – Checkout Cielo for WooCommerceCWE-345 5.3 Medium2024-06-04
CVE-2024-3555 Social Link Pages: link-in-bio landing pages for your social media profiles <= 1.6.9 - Missing Authorization to Arbitrary Page Creation and Cross-Site Scripting — Social Link Pages: link-in-bio landing pages for your social media profilesCWE-862 7.2 High2024-06-04
CVE-2024-4552 Social Login Lite For WooCommerce <= 1.6.0 - Authentication Bypass — Social Login Lite For WooCommerceCWE-288 9.8 Critical2024-06-04
CVE-2024-29974 Zyxel NAS326和Zyxel NAS542 代码问题漏洞 — NAS326 firmwareCWE-434 9.8 Critical2024-06-04
CVE-2024-29973 Zyxel NAS326和Zyxel NAS542 操作系统命令注入漏洞 — NAS326 firmwareCWE-78 9.8 Critical2024-06-04
CVE-2024-29972 Zyxel NAS326和Zyxel NAS542 操作系统命令注入漏洞 — NAS326 firmwareCWE-78 9.8 Critical2024-06-04
CVE-2024-4332 Improper Authentication in Tripwire Enterprise 9.1.0 APIs — Tripwire EnterpriseCWE-303 8.1AIHighAI2024-06-03
CVE-2024-5404 ifm: moneo prone to weak password recovery mechanism — moneo appliance QVA200CWE-640 9.8 Critical2024-06-03
CVE-2024-5311 DigiWin EasyFlow .NET - SQL Injection — EasyFlow .NETCWE-89 9.8 Critical2024-06-03
CVE-2024-36042 Silverpeas 安全漏洞 — n/a 9.8AICriticalAI2024-06-03
CVE-2024-27776 MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') — DeviceHubCWE-22 9.8 Critical2024-06-02

Vulnerabilities classified as access:pre-auth represent 18893 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.