Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18893

18893 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-30387 Junos OS: ACX5448 & ACX710: Due to interface flaps the PFE process can crash — Junos OSCWE-820 6.5 Medium2024-04-12
CVE-2024-30388 Junos OS: QFX5000 Series and EX Series: Specific malformed LACP packets will cause flaps — Junos OS 6.5 Medium2024-04-12
CVE-2024-30392 Junos OS: MX Series with SPC3 and MS-MPC/-MIC: When URL filtering is enabled and a specific URL request is received a flowd crash occurs — Junos OSCWE-121 7.5 High2024-04-12
CVE-2024-30394 Junos OS and Junos OS Evolved: A specific EVPN type-5 route causes rpd crash — Junos OSCWE-121 7.5 High2024-04-12
CVE-2024-30395 Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash — Junos OSCWE-1287 7.5 High2024-04-12
CVE-2024-21618 Junos OS and Junos OS Evolved: When LLDP is enabled and a malformed LLDP packet is received, l2cpd crashes — Junos OSCWE-788 6.5 Medium2024-04-12
CVE-2024-21605 Junos OS: SRX 300 Series: Specific link local traffic causes a control plane overload — Junos OSCWE-668 6.5 Medium2024-04-12
CVE-2024-21598 Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash — Junos OSCWE-1286 7.5 High2024-04-12
CVE-2024-21593 Junos OS: MX Series with MPC10, MPC11, LC9600, and MX304: A specific MPLS packet will cause a PFE crash — Junos OSCWE-703 6.5 Medium2024-04-12
CVE-2024-21590 Junos OS Evolved: Packets which are not destined to the device can reach the RE — Junos OS EvolvedCWE-20 5.3 Medium2024-04-12
CVE-2024-31264 WordPress Post Views Counter plugin <= 1.4.4 - Cross Site Request Forgery (CSRF) vulnerability — Post Views CounterCWE-352 4.3 Medium2024-04-12
CVE-2024-3400 PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect — PAN-OSCWE-77 10.0 Critical2024-04-12
CVE-2024-0881 Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access — Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel 5.3AIMediumAI2024-04-11
CVE-2024-2966 Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.5.6 - Sensitive Information Exposure via element_pack_ajax_search — Element Pack – Widgets, Templates & Addons for ElementorCWE-200 5.3 Medium2024-04-11
CVE-2023-6811 Language Translate Widget for WordPress – ConveyThis <= 223 - Unauthenticated Stored Cross-Site Scripting via api_key — Translate WordPress Websites Globally with ConveyThis TranslateCWE-79 7.2 High2024-04-11
CVE-2024-2217 Improper Access Control in gaizhenbiao/chuanhuchatgpt — gaizhenbiao/chuanhuchatgptCWE-284 9.1AICriticalAI2024-04-10
CVE-2024-1511 Path Traversal Vulnerability in parisneo/lollms-webui — parisneo/lollms-webuiCWE-22 8.8AIHighAI2024-04-10
CVE-2024-0218 DoS on IDS parsing of malformed Radius packets in Guardian before 23.4.1 — GuardianCWE-1286 7.5 High2024-04-10
CVE-2024-2730 Predictable Page Indexing Might Lead to Sensitive Data Exposure in Mautic — MauticCWE-425 5.3 Medium2024-04-10
CVE-2024-1780 BizCalendar Web <= 1.1.0.25 - Reflected Cross-Site Scripting via 'tab' — BizCalendar WebCWE-79 6.1 Medium2024-04-10
CVE-2024-3235 Essential Grid <= 3.1.1 - Unauthenticated Private Post Disclosure — Essential Grid Gallery WordPress PluginCWE-862 5.3 Medium2024-04-10
CVE-2023-40148 PingFederate Server Side Request Forgery vulnerability — PingFederateCWE-918 6.5 Medium2024-04-10
CVE-2024-29296 Portainer 安全漏洞 — n/a 5.3AIMediumAI2024-04-10
CVE-2022-4965 Invitation Code Content Restriction Plugin from CreativeMinds <= 1.5.4 - Reflected Cross-Site Scripting — Invitation Code Content Restriction Plugin from CreativeMindsCWE-79 6.1 Medium2024-04-09
CVE-2024-1412 Memberpress <= 1.11.24 - Reflected Cross-Site Scripting via message and error — MemberpressCWE-79 6.1 Medium2024-04-09
CVE-2024-2093 VK All in One Expansion Unit <= 9.95.0.1 - Information Exposure — VK All in One Expansion UnitCWE-200 6.5 Medium2024-04-09
CVE-2024-3213 Relevanssi – A Better Search <= 4.22.1 - Missing Authorization to Unauthenticated Count Option Update — Relevanssi PremiumCWE-862 5.3 Medium2024-04-09
CVE-2024-1984 Graphene <= 2.9.2 - Missing Authorization — GrapheneCWE-862 5.3 Medium2024-04-09
CVE-2024-1812 Everest Forms <= 2.0.7 - Unauthenticated Server-Side Request Forgery via font_url — Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form BuilderCWE-918 7.2 High2024-04-09
CVE-2024-1587 Newsmatic <= 1.3.4 - Unauthenticated Information Exposure via newsmatic_filter_posts_load_tab_content — NewsmaticCWE-862 5.3 Medium2024-04-09

Vulnerabilities classified as access:pre-auth represent 18893 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.