Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18893

18893 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-31163 ASUS Download Master - Buffer Overflow — Download MasterCWE-121 7.2 High2024-06-14
CVE-2024-31162 ASUS Download Master - OS Command Injection — Download MasterCWE-78 7.2 High2024-06-14
CVE-2024-3966 Pray For Me <= 1.0.4 - Unauthenticated Stored XSS — Pray For Me 6.1AIMediumAI2024-06-14
CVE-2024-5551 WP STAGING PRO - Backup Duplicator & Migration <= 5.6.0 - Cross-Site Request Forgery to Limited Local File Inclusion — WP STAGING Pro WordPress Backup PluginCWE-352 7.5 High2024-06-14
CVE-2024-4936 Canto <= 3.0.8 - Unauthenticated Remote File Inclusion — CantoCWE-98 9.8 Critical2024-06-14
CVE-2024-1094 Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling Plugin <= 1.0.21 - Missing Authorization to Limited Privilege Escalation — Timetics – Appointment Booking & SchedulingCWE-862 7.3 High2024-06-14
CVE-2024-27169 Lack of authentication — Toshiba Tec e-Studio multi-function peripheral (MFP)CWE-306 8.4 High2024-06-14
CVE-2023-6492 Simple Sitemap <= 3.5.13 - Cross-Site Request Forgery via admin_notices — Simple Sitemap – Create a Responsive HTML SitemapCWE-352 4.3 Medium2024-06-14
CVE-2024-0892 Schema App Structured Data <= 2.2.0 - Cross-Site Request Forgery — Schema App Structured DataCWE-352 4.3 Medium2024-06-14
CVE-2024-3080 ASUS Router - Improper Authentication — ZenWiFi XT8CWE-287 9.8 Critical2024-06-14
CVE-2024-27144 Pre-authenticated Remote Code Execution — Toshiba Tec e-Studio multi-function peripheral (MFP)CWE-22 9.8 Critical2024-06-14
CVE-2024-27141 Pre-authenticated Time-Based Blind XXE injection — Toshiba Tec e-Studio multi-function peripheral (MFP)CWE-776 5.9 Medium2024-06-14
CVE-2024-33374 LB-LINK BL-W1210M 安全漏洞 — n/a 8.8AIHighAI2024-06-14
CVE-2024-5949 Deep Sea Electronics DSE855 Multipart Boundary Infinite Loop Denial-of-Service Vulnerability — DSE855CWE-835 6.5AIMediumAI2024-06-13
CVE-2024-37131 Dell Secure Connect Gateway 安全漏洞 — Secure Connect Gateway (SCG) Policy ManagerCWE-942 7.5 High2024-06-13
CVE-2024-30472 Dell ThinOS 信息泄露漏洞 — Wyse 5070 Thin ClientCWE-200 7.5 High2024-06-13
CVE-2024-4371 CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More <= 4.4.1 - Unauthenticated PHP Object Injection — CoDesigner – All in One Elementor WooCommerce BuilderCWE-502 9.0 Critical2024-06-13
CVE-2024-0979 Dashboard Widgets Suite <= 3.4.3 - Reflected Cross-Site Scripting — Dashboard Widgets SuiteCWE-79 6.1 Medium2024-06-13
CVE-2024-3552 Web Directory Free < 1.7.0 - Unauthenticated SQL Injection — Web Directory Free 9.8AICriticalAI2024-06-13
CVE-2024-2098 Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary — Download ManagerCWE-289 7.5 High2024-06-13
CVE-2024-3922 Dokan Pro <= 3.10.3 - Unauthenticated SQL Injection — Dokan ProCWE-89 10.0 Critical2024-06-13
CVE-2023-35858 Modern Campus Omni CMS 安全漏洞 — n/a 5.3AIMediumAI2024-06-13
CVE-2023-35860 Modern Campus Omni CMS 安全漏洞 — n/a 7.5AIHighAI2024-06-13
CVE-2024-28964 Dell Common Event Enabler 代码问题漏洞 — Common Event EnablerCWE-502 7.8 High2024-06-12
CVE-2024-34065 @strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass — strapiCWE-294 7.1 High2024-06-12
CVE-2024-5674 Newsletter - API v1 and v2 addon for Newsletter <= 2.4.5 - Missing Authorization to Email Subscribers Management — Newsletter - API v1 and v2 addon for NewsletterCWE-862 6.5 Medium2024-06-12
CVE-2024-4898 InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation — InstaWP Connect – 1-click WP Staging & MigrationCWE-862 9.8 Critical2024-06-12
CVE-2024-5468 WordPress Header Builder Plugin – Pearl <= 1.3.7 - Missing Authorization to Unauthenticated Arbitrary Site Options Deletion — Pearl – Header BuilderCWE-862 6.5 Medium2024-06-12
CVE-2024-4266 MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 3.8.8 - Unauthenticated Sensitive Information Exposure — MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for ElementorCWE-200 5.3 Medium2024-06-11
CVE-2024-3723 Advanced Contact form 7 DB <= 2.0.2 - Sensitive Information Exposure — Advanced Contact form 7 DBCWE-922 5.3 Medium2024-06-11

Vulnerabilities classified as access:pre-auth represent 18893 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.