Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 21541

21541 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-10913 Clone <= 2.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialized_replace' — CloneCWE-502 8.8 High2024-11-20
CVE-2024-10520 WP Project Manager <= 2.6.14 - Missing Authorization to Project Milestone and Task Creation/Deletion — Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time TrackerCWE-862 5.3 Medium2024-11-20
CVE-2024-11494 Zyxel P-6101C 授权问题漏洞 — P-6101C firmwareCWE-287 7.5 High2024-11-20
CVE-2024-47865 Rakuten Turbo 5G 安全漏洞 — Rakuten Turbo 5GCWE-306 5.3 Medium2024-11-20
CVE-2024-52033 Rakuten Turbo 5G 安全漏洞 — Rakuten Turbo 5GCWE-497 5.3 Medium2024-11-20
CVE-2024-9239 Booster for WooCommerce <= 7.2.3 - Reflected Cross-Site Scripting — Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ ToolsCWE-79 6.1 Medium2024-11-20
CVE-2024-10899 WooCommerce Product Table Lite <= 3.8.6 - Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting — Product Table and List Builder for WooCommerce LiteCWE-94 7.3 High2024-11-20
CVE-2024-8726 MailChimp Forms by MailMunch <= 3.2.3 - Reflected Cross-Site Scripting — MailChimp Forms by MailMunchCWE-79 6.1 Medium2024-11-20
CVE-2024-11277 404 Solution <= 2.35.19 - Reflected Cross-Site Scripting — 404 SolutionCWE-79 6.1 Medium2024-11-20
CVE-2024-9653 Restaurant Menu – Food Ordering System – Table Reservation <= 2.4.2 - Reflected Cross-Site Scripting — Restaurant Menu – Food Ordering System – Table ReservationCWE-79 6.1 Medium2024-11-20
CVE-2024-11278 GD bbPress Attachments <= 4.7.2 - Reflected Cross-Site Scripting — GD bbPress AttachmentsCWE-79 6.1 Medium2024-11-20
CVE-2024-11400 HUSKY – Products Filter for WooCommerce <= 1.3.6.3 - Reflected Cross-Site Scripting via really_curr_tax Parameter — HUSKY – Products Filter Professional for WooCommerceCWE-79 6.1 Medium2024-11-19
CVE-2024-45422 Zoom Apps - Improper Input Validation — Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms ControllersCWE-20 6.5 Medium2024-11-19
CVE-2024-45419 Zoom Apps - Improper Input Validation — Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms ControllersCWE-252 8.1 High2024-11-19
CVE-2024-21697 Atlassian Sourcetree 安全漏洞 — Sourcetree for Mac 8.8AIHighAI2024-11-19
CVE-2024-42450 Versa Director 安全漏洞 — Director 9.8AICriticalAI2024-11-19
CVE-2024-9777 Ashe <= 2.243 - Reflected Cross-Site Scripting via add_query_arg Parameter — AsheCWE-79 6.1 Medium2024-11-19
CVE-2024-9830 Bard <= 2.216 - Reflected Cross-Site Scripting via add_query_arg Parameter — BardCWE-79 6.1 Medium2024-11-19
CVE-2024-11036 GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.1.5 - Unauthenticated Arbitrary Shortcode Execution via gamipress_get_user_earnings — GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressCWE-94 7.3 High2024-11-19
CVE-2024-11038 WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup <= 1.7.5 - Unauthenticated Arbitrary Shortcode Execution via wpb_pcf_fire_contact_form — WPB Popup for Contact Form 7 – Showing Contact Form 7 Popup on Button ClickCWE-94 7.3 High2024-11-19
CVE-2024-10388 WordPress GDPR <= 2.0.2 - Unauthenticated Stored Cross-Site Scripting — WordPress GDPRCWE-79 7.2 High2024-11-19
CVE-2024-11069 WordPress GDPR <= 2.0.2 - Missing Authorization to Unauthenticated Arbitrary User Deletion — WordPress GDPRCWE-862 6.5 Medium2024-11-19
CVE-2024-21287 Oracle Agile PLM Framework 安全漏洞 — Oracle Agile PLM Framework 7.5 High2024-11-18
CVE-2024-10486 Google for WooCommerce <= 2.8.6 - Information Disclosure via Publicly Accessible PHP Info File — Google for WooCommerceCWE-862 5.3 Medium2024-11-18
CVE-2024-43416 GLPI vulnerable to enumeration of users' email addresses by unauthenticated user — glpiCWE-200 7.5 High2024-11-18
CVE-2020-26062 Cisco Integrated Management Controller Username Enumeration Vulnerability — Cisco Unified Computing System (Managed)CWE-203 5.3 Medium2024-11-18
CVE-2020-27124 Cisco Adaptive Security Appliance Software SSL/TLS Denial of Service Vulnerability — Cisco Adaptive Security Appliance (ASA) SoftwareCWE-457 8.6 High2024-11-18
CVE-2020-3431 Cisco Small Business RV Series Routers Cross-Site Scripting Vulnerability — Cisco Small Business RV Series Router FirmwareCWE-79 6.1 Medium2024-11-18
CVE-2020-26073 Cisco SD-WAN vManage Directory Traversal Vulnerability — Cisco Catalyst SD-WAN ManagerCWE-35 7.5 High2024-11-18
CVE-2020-3532 Cisco Unified Communications Products Cross-Site Scripting Vulnerability — Cisco Unity ConnectionCWE-79 6.1 -2024-11-18

Vulnerabilities classified as access:pre-auth represent 21541 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.