Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22098

22098 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-2551 PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet — Cloud NGFWCWE-476 7.5AIHighAI2024-11-14
CVE-2024-9472 PAN-OS: Firewall Denial of Service (DoS) Using Specially Crafted Traffic — Cloud NGFWCWE-476 7.5AIHighAI2024-11-14
CVE-2024-9186 Automation By Autonami < 3.3.0 - Unauthenticated SQLi — Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit 9.8AICriticalAI2024-11-14
CVE-2024-28028 Intel Neural Compressor 安全漏洞 — Intel(R) Neural Compressor software 7.5 High2024-11-13
CVE-2024-33624 Intel PROSet/Wireless WiFi Software driver 输入验证错误漏洞 — Intel(R) PROSet/Wireless WiFi software for Windows 4.3 Medium2024-11-13
CVE-2024-32048 Intel Distribution of OpenVINO(TM) Toolkit 输入验证错误漏洞 — Intel(R) Distribution of OpenVINO(TM) Model Server software 6.5 Medium2024-11-13
CVE-2024-28049 Intel PROSet/Wireless Software和Intel Killer 安全漏洞 — Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi wireless products 5.7 Medium2024-11-13
CVE-2024-24984 Intel Wireless Bluetooth 输入验证错误漏洞 — Intel(R) Wireless Bluetooth(R) products for Windows 6.5 Medium2024-11-13
CVE-2024-23198 Intel PROSet/Wireless Software和Intel Killer 输入验证错误漏洞 — Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi products 6.6 Medium2024-11-13
CVE-2024-11028 MultiManager WP – Manage All Your WordPress Sites Easily <= 1.0.5 - Authentication Bypass via User Impersonation — MultiManager WP – Manage All Your WordPress Sites EasilyCWE-288 9.8 Critical2024-11-13
CVE-2024-10877 AFI – The Easiest Integration Plugin <= 1.92.0 - Reflected Cross-Site Scripting — AFI – The Easiest Integration PluginCWE-79 6.1 Medium2024-11-13
CVE-2024-11150 WordPress User Extra Fields <= 16.6 - Unauthenticated Arbitrary File Deletion — WordPress User Extra FieldsCWE-22 9.8 Critical2024-11-13
CVE-2024-10816 LUNA RADIO PLAYER <= 6.24.01.24 - Unauthenticated Arbitrary File Read — LUNA RADIO PLAYERCWE-22 7.5 High2024-11-13
CVE-2024-10174 WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.13 - Insecure Direct Object Reference to Unauthenticated Authorization Bypass — Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time TrackerCWE-639 7.3 High2024-11-13
CVE-2024-10820 WooCommerce Upload Files <= 84.3 - Unauthenticated Arbitrary File Upload — WooCommerce Upload FilesCWE-434 9.8 Critical2024-11-13
CVE-2024-10828 Advanced Order Export For WooCommerce <= 3.5.5 - Unauthenticated PHP Object Injection via Order Details — Advanced Order Export For WooCommerceCWE-502 8.1 High2024-11-13
CVE-2024-10802 Hash Elements <= 1.4.7 - Missing Authorization to Unauthenticated Draft Post Title Exposure — Hash ElementsCWE-862 5.3 Medium2024-11-13
CVE-2024-11143 Kognetiks Chatbot for WordPress <= 2.1.8 - Cross-Site Request Forgery to Authenticated (Subscriber+) Assistant Modification — Kognetiks Chatbot for WordPressCWE-352 4.3 Medium2024-11-13
CVE-2024-10684 Kognetiks Chatbot for WordPress <= 2.1.7 - Reflected Cross-Site Scripting — Kognetiks Chatbot for WordPressCWE-79 6.1 Medium2024-11-13
CVE-2024-10593 WPForms – Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion — WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & MoreCWE-352 4.3 Medium2024-11-13
CVE-2024-10882 Product Delivery Date for WooCommerce - Lite <= 2.8.0 - Reflected Cross-Site Scripting — Product Delivery Date for WooCommerce – LiteCWE-79 6.1 Medium2024-11-13
CVE-2024-8874 AJAX Login and Registration modal popup + inline form <= 2.24 - Reflected Cross-Site Scripting — AJAX Login and Registration modal popup + inline formCWE-79 6.1 Medium2024-11-13
CVE-2024-9614 Constant Contact Forms by MailMunch <= 2.1.2 - Reflected Cross-Site Scripting — Constant Contact Forms by MailMunchCWE-79 6.1 Medium2024-11-13
CVE-2024-10850 Razorpay Payment Button for Elementor <= 1.2.5 - Reflected Cross-Site Scripting — Razorpay Payment Button Elementor PluginCWE-79 6.1 Medium2024-11-13
CVE-2024-10577 Fat Rat Collect <= 2.7.3 - Reflected Cross-Site Scripting — 胖鼠采集(Fat Rat Collect)CWE-79 6.1 Medium2024-11-13
CVE-2024-10851 Razorpay Payment Button <= 2.4.6 - Reflected Cross-Site Scripting — Razorpay Payment Button PluginCWE-79 6.1 Medium2024-11-13
CVE-2024-9578 Hide Links <= 1.4.2 - Unauthenticated Shortcode Execution — Hide LinksCWE-862 5.3 Medium2024-11-13
CVE-2024-37400 Ivanti Connect Secure 安全漏洞 — Connect Secure 7.5AIHighAI2024-11-13
CVE-2024-34787 Ivanti Endpoint Manager 安全漏洞 — EPM 7.8AIHighAI2024-11-13
CVE-2024-38649 Ivanti Connect Secure 安全漏洞 — Connect Secure 7.5AIHighAI2024-11-13

Vulnerabilities classified as access:pre-auth represent 22098 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.