Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 21962

21962 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-12258 WP Service Payment Form With Authorize.net <= 2.6.3 - Reflected Cross-Site Scripting — WP Service Payment Form With Authorize.netCWE-79 6.1 Medium2024-12-12
CVE-2024-12260 Ultimate Endpoints With Rest Api <= 2.2.2 - Reflected Cross-Site Scripting — Ultimate Endpoints With Rest ApiCWE-79 6.1 Medium2024-12-12
CVE-2024-10111 OAuth Single Sign On – SSO (OAuth Client) <= 6.26.3 - Authentication Bypass — OAuth Single Sign On – SSO (OAuth Client)CWE-287 8.1 High2024-12-12
CVE-2024-12338 Website Toolbox Community <= 2.0.1 - Reflected Cross-Site Scripting via websitetoolbox_username — Website Toolbox ForumCWE-79 6.1 Medium2024-12-12
CVE-2024-11015 Sign In With Google <= 1.8.0 - Authentication Bypass in authenticate_user — Sign In With GoogleCWE-287 9.8 Critical2024-12-12
CVE-2024-11417 dejure.org Vernetzungsfunktion <= 1.97.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting — dejure.org VernetzungsfunktionCWE-352 6.1 Medium2024-12-12
CVE-2024-11419 Password for WP <= 1.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Password for WPCWE-352 6.1 Medium2024-12-12
CVE-2024-11279 Schema App Structured Data <= 2.2.4 - Reflected Cross-Site Scripting — Schema App Structured DataCWE-79 6.1 Medium2024-12-12
CVE-2024-11689 HQ Rental Software <= 1.5.29 - Cross-Site Request Forgery to Arbitrary Options Update — HQ Rental SoftwareCWE-352 8.8 High2024-12-12
CVE-2024-37401 Ivanti Connect Secure 安全漏洞 — Connect Secure 7.5 -2024-12-11
CVE-2024-37377 Ivanti Connect Secure 安全漏洞 — Connect Secure 7.5 -2024-12-11
CVE-2024-50339 GLPI vulnerable to unauthenticated session hijacking — glpiCWE-79 5.3 -2024-12-11
CVE-2024-11351 Restrict – membership, site, content and user access restrictions for WordPress <= 2.2.8 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Restrict – membership, site, content and user access restrictions for WordPressCWE-200 5.3 Medium2024-12-11
CVE-2024-12325 Waymark <= 1.4.1 - Reflected Cross-Site Scripting via 'content' — WaymarkCWE-79 6.1 Medium2024-12-11
CVE-2024-12294 Last Viewed Posts by WPBeginner <= 1.0.1 - Unauthenticated Sensitive Information Exposure — Last Viewed Posts by WPBeginnerCWE-284 5.3 Medium2024-12-11
CVE-2024-11008 Members <= 3.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Members – Membership & User Role Editor PluginCWE-200 5.3 Medium2024-12-11
CVE-2024-11737 Schneider Electric Modicon Controllers 输入验证错误漏洞 — Modicon Controllers M241 / M251CWE-20 9.8 Critical2024-12-11
CVE-2024-12283 WP Pipes <= 1.4.1 - Reflected Cross-Site Scripting via x1 Parameter — WP PipesCWE-79 6.1 Medium2024-12-11
CVE-2024-12004 WPC Order Notes for WooCommerce <= 1.5.2 - Cross-Site Request Forgery to Reflected Cross-Site Scripting — WPC Order Notes for WooCommerceCWE-352 6.1 Medium2024-12-11
CVE-2024-53290 Dell ThinOS 命令注入漏洞 — Wyse Proprietary OS (Modern ThinOS)CWE-77 8.4 High2024-12-11
CVE-2024-54048 Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe ConnectCWE-79 6.1 Medium2024-12-10
CVE-2024-54045 Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe ConnectCWE-79 6.1 Medium2024-12-10
CVE-2024-54043 Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe ConnectCWE-79 6.1 Medium2024-12-10
CVE-2024-54042 Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe ConnectCWE-79 6.1 Medium2024-12-10
CVE-2024-54044 Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe ConnectCWE-79 6.1 Medium2024-12-10
CVE-2024-54047 Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe ConnectCWE-79 6.1 Medium2024-12-10
CVE-2024-54046 Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe ConnectCWE-79 6.1 Medium2024-12-10
CVE-2024-11639 Ivanti CSA 安全漏洞 — Cloud Services ApplicationCWE-288 10.0 Critical2024-12-10
CVE-2024-12323 turboSMTP <= 4.6 - Reflected Cross-Site Scripting via 'page' — turboSMTPCWE-79 6.1 Medium2024-12-10
CVE-2024-11868 LearnPress – WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-284 5.3 Medium2024-12-10

Vulnerabilities classified as access:pre-auth represent 21962 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.