Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18965

18965 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2023-46787 Online Matrimonial Project v1.0 - Multiple Unauthenticated SQL Injections (SQLi) — Online Matrimonial ProjectCWE-89 9.8 Critical2023-11-07
CVE-2023-46785 Online Matrimonial Project v1.0 - Multiple Unauthenticated SQL Injections (SQLi) — Online Matrimonial ProjectCWE-89 9.8 Critical2023-11-07
CVE-2023-46679 Online Job Portal v1.0 - Multiple Unauthenticated SQL Injections (SQLi) — Online Job PortalCWE-89 9.8 Critical2023-11-07
CVE-2023-46677 Online Job Portal v1.0 - Multiple Unauthenticated SQL Injections (SQLi) — Online Job PortalCWE-89 9.8 Critical2023-11-07
CVE-2023-5982 UpdraftPlus <= 1.23.10 - Cross-Site Request Forgery to Google Drive Storage Update — UpdraftPlus: WP Backup & Migration PluginCWE-352 5.4 Medium2023-11-07
CVE-2023-5818 Amazonify <= 0.8.1 - Cross-Site Request Forgery to Amazon Tracking ID Update — AmazonifyCWE-352 4.3 Medium2023-11-07
CVE-2023-5532 ImageMapper <= 1.2.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting via imgmap_save_area_title — ImageMapperCWE-352 6.1 Medium2023-11-07
CVE-2023-5975 ImageMapper <= 1.2.6 - Cross-Site Request Forgery to Plugin Settings Change via ajax — ImageMapperCWE-352 4.3 Medium2023-11-07
CVE-2023-38547 Veeam ONE 安全漏洞 — One 9.8 -2023-11-07
CVE-2023-43984 PrestaShop Advanced Export Products Orders Cron CSV Excel 安全漏洞 — n/a 7.5 -2023-11-07
CVE-2023-5601 WooCommerce Ninja Forms Product Add-ons < 1.7.1 - Unauthenticated Arbitrary File Upload — WooCommerce Ninja Forms Product Add-ons 9.8 -2023-11-06
CVE-2023-4930 Front End PM < 11.4.3 - Sensitive Data Exposure via Directory Listing — Front End PM 7.5 -2023-11-06
CVE-2023-5454 Templately < 2.2.6 - Arbitrary post trashing via Missing Authorization — Templately 7.5 -2023-11-06
CVE-2023-5771 HTML injection in AdminUI through email subject — Proofpoint Enterprise ProtectionCWE-79 6.1 Medium2023-11-06
CVE-2023-46731 Remote code execution through the section parameter in Administration as guest in XWiki Platform — xwiki-platformCWE-94 10.0 Critical2023-11-06
CVE-2023-4699 Arbitrary Command Execution Vulnerability in Mitsubishi Electric proprietary protocol communication of multiple FA products — MELSEC-F Series FX3U-16MT/ESCWE-306 10.0 Critical2023-11-06
CVE-2023-4625 Denial-of-Service(DoS) Vulnerability in Web server function on MELSEC Series CPU module — MELSEC iQ-F Series FX5U-32MT/ESCWE-307 5.3 Medium2023-11-06
CVE-2023-46381 LOYTEC LINX-212 安全漏洞 — n/a 9.8 -2023-11-04
CVE-2023-5946 WordPress Plugin Digirisk 跨站脚本漏洞 — Digirisk 6.1 Medium2023-11-03
CVE-2023-5945 WordPress Plugin video carousel slider with lightbox 跨站请求伪造漏洞 — video carousel slider with lightbox 4.3 Medium2023-11-03
CVE-2023-3277 MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation — MStore API – Create Native Android & iOS Apps On The CloudCWE-288 9.8 Critical2023-11-03
CVE-2023-4591 Inclusion of Functionality from Untrusted Control Sphere in WPN-XM Serverstack — ServerstackCWE-829 7.5 High2023-11-03
CVE-2023-41356 WisdomGarden Tronclass ilearn - Path Traversal — Tronclass ilearnCWE-22 6.5 Medium2023-11-03
CVE-2023-41344 NCSIST ManageEngine MDM - Path Traversal — MDMCWE-22 7.5 High2023-11-03
CVE-2023-41355 Chunghwa Telecom NOKIA G-040W-Q - Improper Input Validation — NOKIA G-040W-QCWE-940 9.8 Critical2023-11-03
CVE-2023-41354 Chunghwa Telecom NOKIA G-040W-Q - Exposure of Sensitive Information — NOKIA G-040W-QCWE-200 4.0 Medium2023-11-03
CVE-2023-41351 Chunghwa Telecom NOKIA G-040W-Q - Broken Access Control — NOKIA G-040W-QCWE-288 9.8 Critical2023-11-03
CVE-2023-41350 Chunghwa Telecom NOKIA G-040W-Q - Excessive Authentication Attempts — NOKIA G-040W-QCWE-307 7.5 High2023-11-03
CVE-2023-46817 phpFox 安全漏洞 — n/a 9.8 -2023-11-03
CVE-2023-5846 Use of Password Hash With Insufficient Computational Effort in Franklin Fueling System TS-550 — TS-550CWE-916 8.3 High2023-11-02

Vulnerabilities classified as access:pre-auth represent 18965 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.