Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18946

18946 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-0514 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_compare — Royal Addons for Elementor – Addons and Templates Kit for ElementorCWE-352 4.3 Medium2024-02-20
CVE-2024-1322 Directorist <= 7.8.4 - Missing Authorization to Unauthenticated Settings Change — Directorist: AI-Powered Business Directory, Listings & Classified AdsCWE-862 5.3 Medium2024-02-20
CVE-2024-0515 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_compare — Royal Addons for Elementor – Addons and Templates Kit for ElementorCWE-352 4.3 Medium2024-02-20
CVE-2024-0978 My Private Site <= 3.0.14 - Improper Access Control to Sensitive Information Exposure via REST API — My Private SiteCWE-284 5.3 Medium2024-02-20
CVE-2024-1472 WP Maintenance <= 6.1.6 - Information Exposure — WP MaintenanceCWE-284 5.3 Medium2024-02-20
CVE-2024-1338 ImageRecycle pdf & image compression <= 3.1.13 - Cross-Site Request Forgery to Settings Update in stopOptimizeAll — ImageRecycle pdf & image compressionCWE-352 4.3 Medium2024-02-20
CVE-2024-1519 Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.4 - Unauthenticated Stored Cross-Site Scripting — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePressCWE-79 6.5 Medium2024-02-20
CVE-2024-1492 WPify Woo Czech <= 4.0.8 - Missing Authorization — WPify Woo CzechCWE-284 5.3 Medium2024-02-20
CVE-2024-1475 Coming Soon Maintenance Mode <= 1.0.5 - Information Exposure — Coming Soon Maintenance ModeCWE-284 5.3 Medium2024-02-20
CVE-2024-1044 Customer Reviews for WooCommerce <= 5.38.10 - Improper Authorization via submit_review — Customer Reviews for WooCommerceCWE-284 5.3 Medium2024-02-20
CVE-2024-0513 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_wishlist — Royal Addons for Elementor – Addons and Templates Kit for ElementorCWE-352 4.3 Medium2024-02-20
CVE-2024-0620 PPWP – Password Protect Pages <= 1.8.9 - Protection Mechanism Bypass — PPWP – Password Protect PagesCWE-200 5.3 Medium2024-02-20
CVE-2023-6565 InfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information Exposure — InfiniteWP ClientCWE-922 5.9 Medium2024-02-20
CVE-2023-6923 Matomo <= 4.15.3 - Reflected Cross-Site Scripting via idsite — Matomo Analytics – Powerful, Privacy-First Insights for WordPressCWE-79 6.1 Medium2024-02-20
CVE-2024-0379 Custom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.1 - Cross-Site Request Forgery to Plugin Options Update — Custom Twitter Feeds – A Tweets Widget or X Feed WidgetCWE-352 4.3 Medium2024-02-20
CVE-2024-1339 ImageRecycle pdf & image compression <= 3.1.13 - Cross-Site Request Forgery to Plugin Data Removal in reinitialize — ImageRecycle pdf & image compressionCWE-352 4.3 Medium2024-02-20
CVE-2024-0616 Passster – Password Protect Pages and Content <= 4.2.6.2 - Missing Authorization to Sensitive Information Exposure — Passster – Password Protect Pages and ContentCWE-200 5.3 Medium2024-02-20
CVE-2024-1334 ImageRecycle pdf & image compression <= 3.1.13 - Cross-Site Request Forgery to Settings Update in enableOptimization — ImageRecycle pdf & image compressionCWE-352 4.3 Medium2024-02-20
CVE-2023-38562 Weston Embedded uC-TCP-IP 资源管理错误漏洞 — uC-TCP-IPCWE-415 8.7 High2024-02-20
CVE-2024-1559 Link Library <= 7.6 - Unauthenticated Stored Cross-Site Scripting — Link LibraryCWE-79 6.5 Medium2024-02-20
CVE-2024-25626 Yocto Project Security Advisory - BitBake/Toaster — pokyCWE-78 8.8 High2024-02-19
CVE-2024-0610 Piraeus Bank WooCommerce Payment Gateway <= 1.6.5.1 - Unauthenticated SQL Injection — Piraeus Bank WooCommerce Payment GatewayCWE-89 9.8 Critical2024-02-17
CVE-2024-1512 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection — MasterStudy LMS WordPress Plugin – for Online Courses and EducationCWE-89 9.8 Critical2024-02-17
CVE-2024-20986 Oracle Fusion Middleware 安全漏洞 — WebLogic Server 6.1 Medium2024-02-17
CVE-2024-20951 Oracle E-Business Suite 安全漏洞 — Customer Interaction History 6.1 Medium2024-02-17
CVE-2024-20956 Oracle Supply Chain Products Suite 安全漏洞 — Agile Product Lifecycle Management for Process 7.3 High2024-02-17
CVE-2024-20949 Oracle E-Business Suite 安全漏洞 — Customer Interaction History 6.1 Medium2024-02-17
CVE-2024-20941 Oracle E-Business Suite 安全漏洞 — Installed Base 6.1 Medium2024-02-17
CVE-2024-20935 Oracle E-Business Suite 安全漏洞 — Installed Base 6.1 Medium2024-02-17
CVE-2024-20931 Oracle Fusion Middleware 的 WebLogic Server 安全漏洞 — WebLogic Server 7.5 High2024-02-17

Vulnerabilities classified as access:pre-auth represent 18946 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.