Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18893

18893 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-20261 Cisco Firepower Threat Defense 安全漏洞 — Cisco Firepower Threat Defense SoftwareCWE-284 5.8 Medium2024-05-22
CVE-2024-20363 Cisco 多款产品安全漏洞 — Cisco Firepower Threat Defense SoftwareCWE-290 5.8 Medium2024-05-22
CVE-2024-3495 Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection — Country State City Dropdown CF7CWE-89 9.8 Critical2024-05-22
CVE-2024-5147 WPZOOM Addons for Elementor (Templates, Widgets) <= 1.1.37 - Unauthenticated Local File Inclusion — WPZOOM Addons for Elementor – Starter Templates & WidgetsCWE-22 9.8 Critical2024-05-22
CVE-2024-2119 LuckyWP Table of Contents <= 2.1.5 - Reflected Cross-Site Scripting — LuckyWP Table of ContentsCWE-79 6.1 Medium2024-05-22
CVE-2024-1762 NextScripts: Social Networks Auto-Poster <= 4.4.3 - Unauthenticated Stored Cross-Site Scripting via User Agent — NextScripts: Social Networks Auto-PosterCWE-79 6.1 Medium2024-05-22
CVE-2024-3927 Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.3 - Form Submission Admin Email Bypass — Element Pack – Widgets, Templates & Addons for ElementorCWE-424 5.3 Medium2024-05-22
CVE-2024-1446 NextScripts: Social Networks Auto-Poster <= 4.4.3 - Cross-Site Request Forgery to Arbitrary Post Deletion — NextScripts: Social Networks Auto-PosterCWE-352 5.4 Medium2024-05-22
CVE-2024-4443 Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter — Business Directory Plugin – Easy Listing Directories for WordPressCWE-89 9.8 Critical2024-05-22
CVE-2024-4971 LearnPress – WordPress LMS Plugin <= 4.2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-79 6.4 Medium2024-05-22
CVE-2024-31340 TP-LINK Tapo 安全漏洞 — TP-Link Tether 5.9AIMediumAI2024-05-22
CVE-2024-3519 Media Library Assistant <= 3.15 - Reflected Cross-Site Scripting via lang — Media Library AssistantCWE-87 6.1 Medium2024-05-21
CVE-2024-31847 Italtel Embrace 安全漏洞 — n/a 6.1AIMediumAI2024-05-21
CVE-2024-31845 Italtel Embrace 安全漏洞 — n/a 6.5AIMediumAI2024-05-21
CVE-2024-31844 Italtel Embrace 安全漏洞 — n/a 5.3AIMediumAI2024-05-21
CVE-2024-3268 YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress <= 3.3.6 - Missing Authorization to Arbitrary Post/Page Creation — Video Gallery – YouTube Gallery & Responsive Video PlaylistCWE-862 5.3 Medium2024-05-21
CVE-2024-4442 Salon booking system <= 9.9 - Unauthenticated Arbitrary File Deletion — Salon Booking System – Free VersionCWE-22 9.1 Critical2024-05-21
CVE-2024-35061 NASA AIT-Core 安全漏洞 — n/a 7.4AIHighAI2024-05-21
CVE-2024-36081 Westermo EDW-100 安全漏洞 — n/a 9.8 Critical2024-05-19
CVE-2024-28064 Accellion Kiteworks 安全漏洞 — n/a 9.8 -2024-05-18
CVE-2024-2782 Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form BuilderCWE-862 7.5 High2024-05-18
CVE-2024-2771 Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form BuilderCWE-862 9.8 Critical2024-05-18
CVE-2024-3231 Popup4Phone <= 1.3.2 - Unauthenticated Stored XSS — Popup4Phone 6.1 -2024-05-17
CVE-2024-3551 Penci Soledad Data Migrator <= 1.3.0 - Unauthenticated Local File Inclusion — Penci Soledad Data MigratorCWE-98 9.8 Critical2024-05-17
CVE-2021-33146 Intel Ethernet Adapters 和 Intel Ethernet Controller I225 Manageability firmware 安全漏洞 — Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware 5.3 Medium2024-05-16
CVE-2021-33141 Intel Ethernet Adapters 和 Intel Ethernet Controller I225 Manageability firmware 安全漏洞 — Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware 8.6 High2024-05-16
CVE-2023-38417 Intel PROSet/Wireless WiFi Software 安全漏洞 — Intel(R) PROSet/Wireless WiFi software 4.3 Medium2024-05-16
CVE-2023-40536 Intel PROSet/Wireless WiFi Software 安全漏洞 — Intel(R) PROSet/Wireless WiFi software for Windows 4.3 Medium2024-05-16
CVE-2023-47210 Intel PROSet/Wireless WiFi Software 安全漏洞 — Intel(R) PROSet/Wireless WiFi software for linux 4.7 Medium2024-05-16
CVE-2023-38654 Intel PROSet/Wireless WiFi Software 安全漏洞 — some Intel(R) PROSet/Wireless WiFi software for Windows 8.2 High2024-05-16

Vulnerabilities classified as access:pre-auth represent 18893 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.