Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18946

18946 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-20321 Cisco NX-OS Software 安全漏洞 — Cisco NX-OS SoftwareCWE-400 8.6 High2024-02-28
CVE-2024-1719 Easy PayPal & Stripe Buy Now Button <= 1.8.3 & Contact Form 7 – PayPal & Stripe Add-on <= 2.1 - Cross-Site Request Forgery to Settings Update — Easy PayPal & Stripe Buy Now ButtonCWE-352 4.3 Medium2024-02-28
CVE-2024-1860 Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan <= 4.51 - Missing Authorization to Unauthenticated IP Address Whitelist — Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker ScanCWE-862 6.5 Medium2024-02-28
CVE-2024-1476 Under Construction / Maintenance Mode from Acurax <= 2.6 - Information Exposure — Under Construction / Maintenance Mode from AcuraxCWE-284 5.3 Medium2024-02-28
CVE-2024-0767 Envo's Elementor Templates & Widgets for WooCommerce <= 1.4.4 - Cross-Site Request Forgery via ajax_plugin_activation — Envo's Templates & Widgets for Elementor and WooCommerceCWE-352 4.3 Medium2024-02-28
CVE-2024-1136 Coming Soon Page & Maintenance Mode <= 2.2.1 - Maintenance Mode Bypass — Coming Soon Page & Maintenance ModeCWE-862 5.3 Medium2024-02-28
CVE-2024-1368 Page Duplicator <= 0.1.1 - Missing Authorization to Unauthenticated Post/Page Duplication — Page DuplicatorCWE-862 5.3 Medium2024-02-28
CVE-2024-1516 WP eCommerce <= 3.15.1 - Missing Authorization to Unauthenticated Arbitrary Post Creation — WP eCommerceCWE-862 5.3 Medium2024-02-28
CVE-2024-1954 Oliver POS – A WooCommerce Point of Sale (POS) <= 2.4.1.8 - Cross-Site Request Forgery — Oliver POS – A WooCommerce Point of Sale (POS)CWE-352 6.3 Medium2024-02-28
CVE-2024-0431 Gestpay for WooCommerce <= 20221130 - Cross-Site Request Forgery (CSRF) via ajax_set_default_card — Ecommerce FabrickCWE-352 4.3 Medium2024-02-28
CVE-2024-1566 Redirects <= 1.2.1 - Missing Authorization via save — RedirectsCWE-862 6.5 Medium2024-02-28
CVE-2024-0432 Gestpay for WooCommerce <= 20221130 - Cross-Site Request Forgery (CSRF) via ajax_delete_card — Ecommerce FabrickCWE-352 4.3 Medium2024-02-28
CVE-2024-0768 Envo's Elementor Templates & Widgets for WooCommerce <= 1.4.4 - Cross-Site Request Forgery via ajax_theme_activation — Envo's Templates & Widgets for Elementor and WooCommerceCWE-352 4.3 Medium2024-02-28
CVE-2024-0682 Page Restrict <= 2.5.5 - Protection Mechanism Bypass — Page RestrictCWE-693 5.3 Medium2024-02-28
CVE-2024-0433 Gestpay for WooCommerce <= 20221130 - Cross-Site Request Forgery (CSRF) via ajax_unset_default_card — Ecommerce FabrickCWE-352 4.3 Medium2024-02-28
CVE-2024-0680 WP Private Content Plus <= 3.6 - Protection Mechanism Bypass — WP Private Content PlusCWE-693 5.3 Medium2024-02-28
CVE-2024-0975 WordPress Access Control <= 4.0.13 - Improper Access Control to Sensitive Information Exposure via REST API — WordPress Access ControlCWE-284 5.3 Medium2024-02-28
CVE-2024-1514 WP eCommerce <= 3.15.1 - Unauthenticated SQL Injection — WP eCommerceCWE-89 9.8 Critical2024-02-28
CVE-2024-1943 Yuki <= 1.3.14 - Cross-Site Request Forgery to Theme Setting Reset — YukiCWE-352 4.3 Medium2024-02-28
CVE-2023-43769 Couchbase Server 安全漏洞 — n/a 9.8 -2024-02-28
CVE-2024-25830 Field Logic DataCube3 安全漏洞 — n/a 9.8 -2024-02-28
CVE-2024-25833 Field Logic DataCube3 安全漏洞 — n/a 9.8 -2024-02-28
CVE-2024-1722 Keycloak-core: dos via account lockout CWE-645 3.7 Low2024-02-27
CVE-2024-27905 Apache Aurora: padding oracle can allow construction an authentication cookie — Apache AuroraCWE-200 9.8 -2024-02-27
CVE-2024-1910 Categorify <= 1.0.7.4 - Cross-Site Request Forgery via categorifyAjaxClearCategory — Categorify – WordPress Media Library Category & File ManagerCWE-352 4.3 Medium2024-02-27
CVE-2024-1906 Categorify <= 1.0.7.4 - Cross-Site Request Forgery via categorifyAjaxAddCategory — Categorify – WordPress Media Library Category & File ManagerCWE-352 4.3 Medium2024-02-27
CVE-2024-1912 Categorify <= 1.0.7.4 - Cross-Site Request Forgery via categorifyAjaxUpdateFolderPosition — Categorify – WordPress Media Library Category & File ManagerCWE-352 4.3 Medium2024-02-27
CVE-2024-1909 Categorify <= 1.0.7.4 - Cross-Site Request Forgery via categorifyAjaxRenameCategory — Categorify – WordPress Media Library Category & File ManagerCWE-352 4.3 Medium2024-02-27
CVE-2024-1907 Categorify <= 1.0.7.4 - Cross-Site Request Forgery via categorifyAjaxDeleteCategory — Categorify – WordPress Media Library Category & File ManagerCWE-352 4.3 Medium2024-02-27
CVE-2023-6585 JobSearch WP Job Board < 2.3.4 - Arbitrary File Upload to RCE — WP JobSearch 9.8 -2024-02-27

Vulnerabilities classified as access:pre-auth represent 18946 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.