Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18946

18946 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-1698 NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection — NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification BarCWE-89 9.8 Critical2024-02-27
CVE-2023-7033 Mitsubishi Electric MELSEC iQ-F series 安全漏洞 — MELSEC iQ-R series CPU module R00CPUCWE-410 5.3 Medium2024-02-27
CVE-2024-1810 Archivist – Custom Archive Templates <= 1.7.5 - Reflected Cross-Site Scripting — Archivist – Custom Archive TemplatesCWE-79 6.1 Medium2024-02-24
CVE-2024-1360 Colibri WP <= 1.0.94 - Cross-Site Request Forgery to Limited Plugin Installation — Colibri WPCWE-352 4.3 Medium2024-02-23
CVE-2024-1361 Colibri Page Builder <= 1.0.253 - Cross-Site Request Fogery via extend_builder — Colibri Page BuilderCWE-352 4.3 Medium2024-02-23
CVE-2024-1362 Colibri Page Builder <= 1.0.253 - Cross-Site Request Fogery via cp_shortcode_refresh — Colibri Page BuilderCWE-352 4.3 Medium2024-02-23
CVE-2024-1778 Admin side data storage for Contact Form 7 <= 1.1.1 - Missing Authorization to Unauthenticated Bookmark Status Alteration — Admin side data storage for Contact Form 7CWE-862 4.3 Medium2024-02-23
CVE-2024-1777 Admin side data storage for Contact Form 7 <= 1.1.1 - Cross-Site Request Forgery — Admin side data storage for Contact Form 7CWE-352 4.3 Medium2024-02-23
CVE-2024-1779 Admin side data storage for Contact Form 7 plugin <= 1.1.1 - Missing Authorization to Unauthenticated Read Status Update — Admin side data storage for Contact Form 7CWE-862 5.3 Medium2024-02-23
CVE-2024-1104 Temporary denial of service during a brute force attack — Webserv2CWE-307 7.5 High2024-02-22
CVE-2024-0903 User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.0.13 - Unauthenticated Stored Cross-Site Scripting — UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in SecondsCWE-79 5.4 Medium2024-02-22
CVE-2024-1212 LoadMaster Pre-Authenticated OS Command Injection — LoadMasterCWE-78 10.0 Critical2024-02-21
CVE-2024-20325 Cisco Unified Intelligence Center 安全漏洞 — Cisco Unified Intelligence CenterCWE-284 5.1 Medium2024-02-21
CVE-2024-0593 Simple Job Board <= 2.10.8 - Missing Authorization to Unauthenticated Information Disclosure — Simple Job BoardCWE-862 5.3 Medium2024-02-21
CVE-2024-1562 WooCommerce Google Sheet Connector <= 1.3.11 - Missing Authorization — GSheetConnector for WooCommerce – Send your Orders and Products to Google Sheet in Real-TimeCWE-862 5.3 Medium2024-02-21
CVE-2024-1501 Database Reset <= 3.22 - Cross-Site Request Forgery to WP Reset Plugin Installation — Database ResetCWE-352 4.7 Medium2024-02-21
CVE-2024-1108 Plugin Groups <= 2.0.6 - Missing Authorization to Unauthenticated Denial of Service — Plugin GroupsCWE-862 6.5 Medium2024-02-21
CVE-2023-37177 PMB SQL注入漏洞 — n/a 9.8AICriticalAI2024-02-21
CVE-2023-51828 PMB SQL注入漏洞 — n/a 9.8AICriticalAI2024-02-21
CVE-2023-52153 PMB SQL注入漏洞 — n/a 9.8AICriticalAI2024-02-21
CVE-2024-22220 Terminalfour 安全漏洞 — n/a 6.1AIMediumAI2024-02-21
CVE-2024-23830 MantisBT Host Header Injection vulnerability — mantisbtCWE-74 8.3 High2024-02-20
CVE-2024-1294 Sunshine Photo Cart: Free Client Galleries for Photographers <= 3.0.24 - Unauthenticated Sensitive Information Exposure via Invoice — Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for PhotographersCWE-284 5.3 Medium2024-02-20
CVE-2024-0516 Royal Elementor Addons and Templates <= 1.3.87 - Missing Authorization via wpr_update_form_action_meta — Royal Addons for Elementor – Addons and Templates Kit for ElementorCWE-352 5.3 Medium2024-02-20
CVE-2024-0821 Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce <= 3.2.8 - Reflected Cross-Site Scripting — Cost of Goods: Product Cost & Profit Calculator for WooCommerceCWE-79 6.1 Medium2024-02-20
CVE-2024-1389 Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.11.1 - Missing Authorization via pms_stripe_connect_handle_authorization_return — Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content RestrictionCWE-862 5.3 Medium2024-02-20
CVE-2024-1336 ImageRecycle pdf & image compression <= 3.1.13 - Cross-Site Request Forgery to Settings Update in optimizeAllOn — ImageRecycle pdf & image compressionCWE-352 4.3 Medium2024-02-20
CVE-2024-0590 Microsoft Clarity <= 0.9.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Microsoft ClarityCWE-352 6.1 Medium2024-02-20
CVE-2024-0512 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_wishlist — Royal Addons for Elementor – Addons and Templates Kit for ElementorCWE-352 4.3 Medium2024-02-20
CVE-2024-1335 ImageRecycle pdf & image compression <= 3.1.13 - Cross-Site Request Forgery to Settings Update in disableOptimization — ImageRecycle pdf & image compressionCWE-352 4.3 Medium2024-02-20

Vulnerabilities classified as access:pre-auth represent 18946 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.