Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18965

18965 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-21595 Junos OS: EX4100, EX4400, EX4600, QFX5000 Series: A high rate of specific ICMP traffic will cause the PFE to hang — Junos OSCWE-1286 7.5 High2024-01-12
CVE-2024-21591 Junos OS: SRX Series and EX Series: Security Vulnerability in J-web allows a preAuth Remote Code Execution — Junos OSCWE-787 9.8 Critical2024-01-12
CVE-2024-21589 Paragon Active Assurance Control Center: Information disclosure vulnerability — Paragon Active AssuranceCWE-284 7.4 High2024-01-12
CVE-2024-21585 Junos OS and Junos OS Evolved: BGP session flaps on NSR-enabled devices can cause rpd crash — Junos OSCWE-755 5.9 Medium2024-01-12
CVE-2023-36842 Junos OS: jdhcpd will hang on receiving a specific DHCP packet — Junos OSCWE-703 6.5 Medium2024-01-12
CVE-2023-48166 Atos Unify OpenScape 安全漏洞 — n/a 7.5 -2024-01-12
CVE-2023-6242 EventON - WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Cross-Site Request Forgery via evo_eventpost_update_meta — EventON – Events CalendarCWE-352 6.5 Medium2024-01-11
CVE-2023-6244 EventON - WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.8 (Free) - Cross-Site Request Forgery via save_virtual_event_settings — EventON – Events CalendarCWE-352 6.5 Medium2024-01-11
CVE-2023-6582 ElementsKit Lite <= 3.0.3 - Unauthenticated Sensitive Information Exposure — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for ElementorCWE-284 5.3 Medium2024-01-11
CVE-2023-6875 POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile AppCWE-639 9.8 Critical2024-01-11
CVE-2023-4247 GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin deactivation — GiveWP – Donation Plugin and Fundraising PlatformCWE-352 5.4 Medium2024-01-11
CVE-2023-4246 GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin installation — GiveWP – Donation Plugin and Fundraising PlatformCWE-352 4.3 Medium2024-01-11
CVE-2023-6751 Hostinger <= 1.9.7 - Missing Authorization to Maintenance Mode Activation — Hostinger ToolsCWE-862 7.3 High2024-01-11
CVE-2023-6638 GTG Product Feed for Shopping <= 1.2.4 - Missing Authorization to Unauthenticated Plugin Settings Update — GG Woo Feed for WooCommerce Shopping Feed on Google and Other ChannelsCWE-862 6.5 Medium2024-01-11
CVE-2023-6737 Enable Media Replace <= 4.1.4 - Reflected Cross-Site Scripting — Enable Media ReplaceCWE-79 4.7 Medium2024-01-11
CVE-2023-7048 My Sticky Bar <= 2.6.6 - Cross-Site Request Forgery to Sensitive Information Exposure — My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu)CWE-352 3.1 Low2024-01-11
CVE-2023-6316 MW WP Form <= 5.0.1 - Unauthenticated Arbitrary File Upload — MW WP FormCWE-434 9.8 Critical2024-01-11
CVE-2023-6220 Piotnet Forms <= 1.0.28 - Unauthenticated Arbitrary File Upload — Piotnet FormsCWE-434 8.1 High2024-01-11
CVE-2023-6828 ARForms <= 1.5.8 - Unauthenticated Stored Cross-Site Scripting via arf_http_referrer_url — Contact Form, Survey, Quiz & Popup Form Builder – ARFormsCWE-79 7.2 High2024-01-11
CVE-2023-6567 LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-89 9.8 Critical2024-01-11
CVE-2023-6637 CAOS | Host Google Analytics Locally <= 4.7.14 - Missing Authorization to Unauthenticated Plugin Settings Update — CAOS | Host Google Analytics LocallyCWE-862 6.5 Medium2024-01-11
CVE-2023-6855 Paid Memberships Pro <= 2.12.5 - Missing Authorization via API — Paid Memberships Pro – Content Restriction, User Registration, & Paid SubscriptionsCWE-862 5.3 Medium2024-01-11
CVE-2023-6882 Simple Membership <= 4.3.8 - Reflected Cross-Site Scripting Vulnerability via environment_mode — Simple MembershipCWE-79 6.1 Medium2024-01-11
CVE-2023-4248 GiveWP <= 2.33.3 - Cross-Site Request Forgery to Stripe Integration Deletion — GiveWP – Donation Plugin and Fundraising PlatformCWE-352 5.4 Medium2024-01-11
CVE-2023-6634 LearnPress <= 4.2.5.7 - Command Injection — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-88 8.1 High2024-01-11
CVE-2023-6266 Backup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive Information Exposure — BackupBliss – Backup & Migration with Free Cloud StorageCWE-200 7.5 High2024-01-11
CVE-2023-6496 Manage Notification E-mails <= 1.8.5 - Missing Authorization — Manage Notification E-mailsCWE-285 5.3 Medium2024-01-11
CVE-2023-6632 Happy Addons for Elementor <= 3.9.1.1 - Reflected Cross-Site Scripting — Happy Addons for Elementor ProCWE-79 6.1 Medium2024-01-11
CVE-2023-6699 WP Compress – Image Optimizer [All-In-One] <= 6.10.33 - Unauthenticated Directory Traversal via css — WP Compress – Instant Performance & Speed OptimizationCWE-24 9.1 Critical2024-01-11
CVE-2023-6520 WP 2FA – Two-factor authentication for WordPress <= 2.5.0 - Cross-Site Request Forgery — WP 2FA – Two-factor authentication for WordPressCWE-352 4.3 Medium2024-01-11

Vulnerabilities classified as access:pre-auth represent 18965 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.