Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18893

18893 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-4444 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registration — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-420 5.3 Medium2024-05-10
CVE-2024-4434 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-89 9.8 Critical2024-05-10
CVE-2024-3547 Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Reflected Cross-Site Scripting — Unlimited Elements For ElementorCWE-79 6.1 Medium2024-05-10
CVE-2024-4280 White Label CMS <= 2.7.3 - Missing Authorization to Plugin Settings Reset — White Label CMSCWE-862 5.3 Medium2024-05-10
CVE-2024-4038 Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro <= 5.3.1 - Unauthenticated Arbitrary Shortcode Execution — Back In Stock Notifier for WooCommerce | WooCommerce Waitlist ProCWE-94 6.5 Medium2024-05-09
CVE-2024-4104 ADFO – Custom data in admin dashboard <= 1.9.0 - Reflected Cross-Site Scripting — ADFO – Custom data in admin dashboardCWE-79 6.1 Medium2024-05-09
CVE-2024-4463 Squelch Tabs and Accordions Shortcodes <= 0.4.7 - Cross-Site Request Forgery — Squelch Tabs and Accordions ShortcodesCWE-352 4.3 Medium2024-05-09
CVE-2024-4082 Joli FAQ SEO – WordPress FAQ Plugin <= 1.3.2 - Cross-Site Request Forgery — Joli FAQ SEO – WordPress FAQ PluginCWE-352 4.3 Medium2024-05-09
CVE-2024-3070 Last Viewed Posts by WPBeginner <= 1.0.0 - Unauthenticated PHP Object Injection — Last Viewed Posts by WPBeginnerCWE-502 9.8 Critical2024-05-09
CVE-2024-3806 Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts — PortoCWE-98 9.8 Critical2024-05-09
CVE-2024-1230 SimpleShop <= 2.10.0 - Cross-Site Request Forgery — SimpleShopCWE-284 4.3 Medium2024-05-09
CVE-2024-4103 ADFO – Custom data in admin dashboard <= 1.9.0 - Cross-Site Request Forgery — ADFO – Custom data in admin dashboardCWE-352 4.3 Medium2024-05-09
CVE-2024-4441 XML Sitemap & Google News <= 5.4.8 - Unauthenticated Local File Inclusion — XML Sitemap & Google NewsCWE-98 8.1 High2024-05-09
CVE-2024-3915 Swift Framework <= 2.7.31 - Missing Authorization to Unauthenticated Arbitrary Content Update — Swift FrameworkCWE-862 5.3 Medium2024-05-09
CVE-2024-4314 hostel <= 1.1.5.3 - Cross-Site Request Forgery — HostelCWE-352 4.3 Medium2024-05-09
CVE-2024-4312 Soccer Engine – Soccer Plugin for WordPress <= 1.12 - Cross-Site Request Forgery — Soccer Engine – Soccer Plugin for WordPressCWE-352 4.3 Medium2024-05-09
CVE-2024-4041 Yoast SEO <= 22.5 - Reflected Cross-Site Scripting — Yoast SEO – Advanced SEO with real-time guidance and built-in AICWE-79 6.1 Medium2024-05-09
CVE-2024-1229 SimpleShop <= 2.10.2 - Missing Authorization — SimpleShopCWE-862 5.3 Medium2024-05-09
CVE-2023-6327 ShopLentor (formerly WooLentor) <= 2.8.7 - Missing Authorization via purchased_new_products — ShopLentor – All-in-One WooCommerce Growth & Store Enhancement PluginCWE-862 5.3 Medium2024-05-09
CVE-2024-4150 Simple Basic Contact Form <= 20221201 - Reflected Cross-Site Scripting — Simple Basic Contact FormCWE-79 6.1 Medium2024-05-09
CVE-2024-32739 CyberPower PowerPanel Enterprise SQL Injection — CyberPower PowerPanel Enterprise 7.5 High2024-05-09
CVE-2024-32738 CyberPower PowerPanel Enterprise SQL Injection — CyberPower PowerPanel Enterprise 7.5 High2024-05-09
CVE-2024-32737 CyberPower PowerPanel Enterprise SQL Injection — CyberPower PowerPanel Enterprise 7.5 High2024-05-09
CVE-2024-32736 CyberPower PowerPanel Enterprise SQL Injection — CyberPower PowerPanel Enterprise 7.5 High2024-05-09
CVE-2024-32735 CyberPower PowerPanel Enterprise Missing Authentication — CyberPower PowerPanel Enterprise 9.8 Critical2024-05-09
CVE-2024-3016 NEC Platforms DT900 Series 安全漏洞 — ITK-6DGS-1(BK) TELCWE-912 6.5 -2024-05-09
CVE-2024-32049 BIG-IP Next Central Manager vulnerability — BIG-IP Next Central ManagerCWE-300 7.4 High2024-05-08
CVE-2024-4135 WP Latest Posts <= 5.0.7 - Authenticated (Subscriber+) Arbitrary Shortcode Execution — WP Latest PostsCWE-94 5.4 Medium2024-05-08
CVE-2024-4393 Social Connect <= 1.2 - Authentication Bypass — Social ConnectCWE-288 9.8 Critical2024-05-08
CVE-2023-7240 Broken Access Control leading to SSRF in NetIQ Identity Console — NetIQ Identity ConsoleCWE-20 5.8 Medium2024-05-07

Vulnerabilities classified as access:pre-auth represent 18893 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.