Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18942

18942 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-1503 Tutor LMS – eLearning and online course solution <= 2.6.1 - Cross-Site Request Forgery to Plugin Deactivation and Data Erase — Tutor LMS – eLearning and online course solutionCWE-352 4.3 Medium2024-03-12
CVE-2023-7072 Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint — Post GridCWE-202 7.5 High2024-03-12
CVE-2024-0386 weForms <= 1.6.21 - Unauthenticated Stored Cross-Site Scripting via Referer — weForms – Easy Drag & Drop Contact Form Builder For WordPressCWE-79 7.2 High2024-03-12
CVE-2024-2107 Blossom Spa <= 1.3.3 - Sensitive Information Exposure — Blossom SpaCWE-862 5.8 Medium2024-03-12
CVE-2024-2395 Bulgarisation for WooCommerce <= 3.0.14 - Cross-Site Request Forgery — Bulgarisation for WooCommerceCWE-862 7.3 High2024-03-12
CVE-2022-34321 Apache Pulsar: Improper Authentication for Pulsar Proxy Statistics Endpoint — Apache PulsarCWE-306 8.2 High2024-03-12
CVE-2024-1410 Unbounded storage of information related to connection ID retirement, in quiche — quicheCWE-400 3.7 Low2024-03-12
CVE-2024-22041 Siemens 多款产品缓冲区错误漏洞 — Cerberus PRO EN Engineering ToolCWE-119 7.5 High2024-03-12
CVE-2024-22040 Siemens 多款产品缓冲区错误漏洞 — Cerberus PRO EN Engineering ToolCWE-125 7.5 High2024-03-12
CVE-2024-22039 Siemens 多款产品安全漏洞 — Cerberus PRO EN Engineering ToolCWE-120 10.0 Critical2024-03-12
CVE-2023-4629 LadiApp <= 4.4 - Cross-Site Request Forgery via save_config() — LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…CWE-352 4.3 Medium2024-03-12
CVE-2023-4729 LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 - Cross-Site Request Forgery via publish_lp() — LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…CWE-352 4.3 Medium2024-03-12
CVE-2023-4731 LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 - Cross-Site Request Forgery via init_endpoint — LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…CWE-352 4.3 Medium2024-03-12
CVE-2023-4628 LadiApp <= 4.4 - Cross-Site Request Forgery via ladiflow_save_hook() — LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…CWE-352 4.3 Medium2024-03-12
CVE-2024-0906 f(x) Private Site <= 1.2.1 - Sensitive Information Exposure — f(x) Private SiteCWE-200 5.3 Medium2024-03-12
CVE-2024-26288 PHOENIX CONTACT: Lack of SSL support in CHARX Series — CHARX SEC-3000CWE-319 8.7 High2024-03-12
CVE-2024-26005 PHOENIX CONTACT: Privilege gain through incomplete cleanup in CHARX Series — CHARX SEC-3000CWE-459 4.8 Medium2024-03-12
CVE-2024-26004 PHOENIX CONTACT: DoS of a control agent due to access of a uninitialized pointer in CHARX Series — CHARX SEC-3000CWE-824 7.5 High2024-03-12
CVE-2024-26003 PHOENIX CONTACT: DoS of the control agent in CHARX Series — CHARX SEC-3000CWE-125 7.5 High2024-03-12
CVE-2024-26001 PHOENIX CONTACT: Out of bounds write only memory access — CHARX SEC-3000CWE-787 7.4 High2024-03-12
CVE-2024-26000 PHOENIX CONTACT: Out of bounds read only memory access — CHARX SEC-3000CWE-125 5.9 Medium2024-03-12
CVE-2024-25999 PHOENIX CONTACT: Privilege escalation in the OCPP agent service — CHARX SEC-3000CWE-20 8.4 High2024-03-12
CVE-2024-25998 PHOENIX CONTACT: Command injection in the OCPP Service — CHARX SEC-3000CWE-77 7.3 High2024-03-12
CVE-2024-25997 PHOENIX CONTACT: Log injection in CHARX Series — CHARX SEC-3000CWE-20 5.3 Medium2024-03-12
CVE-2024-25996 PHOENIX CONTACT: Remote code execution due to an origin validation error in CHARX Series — CHARX SEC-3000CWE-346 5.3 Medium2024-03-12
CVE-2024-25995 PHOENIX CONTACT: Remote code execution in CHARX Series — CHARX SEC-3000CWE-20 9.8 Critical2024-03-12
CVE-2024-25994 PHOENIX CONTACT: Unintended script file upload in CHARX Series — CHARX SEC-3000CWE-434 5.3 Medium2024-03-12
CVE-2024-25331 D-Link DIR-822 和DIR-822-CA 安全漏洞 — n/a 9.8AICriticalAI2024-03-12
CVE-2023-6444 Seriously Simple Podcasting < 3.0.0 - Unauthenticated Administrator Email Disclosure — Seriously Simple Podcasting 5.3AIMediumAI2024-03-11
CVE-2024-1320 EventPrime – Events Calendar, Bookings and Tickets <= 3.4.3 - Unauthenticated Stored Cross-Site Scripting — EventPrime – Events Calendar, Bookings and TicketsCWE-79 6.5 Medium2024-03-09

Vulnerabilities classified as access:pre-auth represent 18942 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.