Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22423

22423 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2026-16232 Authentication Bypass in the SmartConsole Login Process Using an Application Token — Quantum Security ManagementCWE-287--2026-07-22
CVE-2026-14932 Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart — Telerik UI for ASP.NET AJAXCWE-321 6.5 Medium2026-07-22
CVE-2026-14865 XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAXCWE-776 5.3 Medium2026-07-22
CVE-2026-13185 PersistenceFramework Cookie Deserialization Vulnerability in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAXCWE-502 8.1 High2026-07-22
CVE-2026-55991 Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 — UnboundCWE-195 5.9 Medium2026-07-22
CVE-2026-55990 Packet of death for a DNSCrypt misconfigured Unbound — UnboundCWE-457 5.9 Medium2026-07-22
CVE-2025-13146 Contact Form 7 – Dynamic Text Extension <= 5.0.6 - Unauthenticated Arbitrary Shortcode Execution — Contact Form 7 – Dynamic Text ExtensionCWE-94 6.5 Medium2026-07-22
CVE-2026-65600 Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex — traefikCWE-22 7.8 High2026-07-22
CVE-2026-65597 n8n before 1.123.64 DOM-Based XSS via Unsandboxed iframe — n8nCWE-79--2026-07-22
CVE-2026-65014 n8n before 2.28.0 Authentication Bypass via test-webhook — n8nCWE-306--2026-07-22
CVE-2026-61392 Hikvision DS-2CD Series 信息泄露漏洞 — DS-2CD Series 5.3 Medium2026-07-22
CVE-2026-61390 Hikvision DS-2CD Series 缓冲区错误漏洞 — DS-2CD Series 7.7 High2026-07-22
CVE-2026-57600 Hikvision DS-2CD Series 输入验证错误漏洞 — DS-2CD Series 7.5 High2026-07-22
CVE-2026-12987 Events Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injection in Booking Registration — Events Manager--2026-07-22
CVE-2026-12968 Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload — Product Addons and Product Options With Custom Fields--2026-07-22
CVE-2026-14322 Timetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payment_method — Timetics--2026-07-22
CVE-2026-56819 Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS) — nettyCWE-400 7.5 High2026-07-21
CVE-2026-65319 Feedbin Unauthenticated Entry Content Disclosure via GET /api/v2/entries/:id/text — FeedbinCWE-306 7.5 High2026-07-21
CVE-2026-62547 Oracle workflow 安全漏洞 — Oracle Workflow 8.1 High2026-07-21
CVE-2026-62521 Oracle HRMS (US) 安全漏洞 — Oracle HRMS (US) 7.5 High2026-07-21
CVE-2026-62517 Oracle Production Scheduling 安全漏洞 — Oracle Production Scheduling 5.3 Medium2026-07-21
CVE-2026-62505 Oracle Time and Labor 安全漏洞 — Oracle Time and Labor 6.1 Medium2026-07-21
CVE-2026-62487 Oracle Contracts Integration 安全漏洞 — Oracle Contracts Integration 6.1 Medium2026-07-21
CVE-2026-62486 Oracle Contracts Integration 安全漏洞 — Oracle Contracts Integration 5.0 Medium2026-07-21
CVE-2026-62484 Oracle Contracts Integration 安全漏洞 — Oracle Contracts Integration 5.9 Medium2026-07-21
CVE-2026-62444 Oracle Contracts Integration 安全漏洞 — Oracle Contracts Integration 6.1 Medium2026-07-21
CVE-2026-62443 Oracle Contracts Integration 安全漏洞 — Oracle Contracts Integration 7.1 High2026-07-21
CVE-2026-61309 Oracle E-Business Suite 安全漏洞 — Oracle In-Memory Cost Management for Discrete Industries 7.5 High2026-07-21
CVE-2026-61271 Oracle Document Management and Collaboration 安全漏洞 — Oracle Document Management and Collaboration 7.3 High2026-07-21
CVE-2026-61267 Oracle Human Capital Management Configuration Workbench 安全漏洞 — Oracle HCM Configuration Workbench 7.3 High2026-07-21

Vulnerabilities classified as access:pre-auth represent 22423 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.