Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22121

22121 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-10958 WP Photo Album Plus <= 8.8.08.007 - Unauthenticated Arbitrary Shortcode Execution via getshortcodedrenderedfenodelay — WP Photo Album PlusCWE-94 7.3 High2024-11-10
CVE-2024-10265 Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.30 - Reflected Cross-Site Scripting via add_query_arg Parameter — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form BuilderCWE-79 6.1 Medium2024-11-10
CVE-2024-10837 SysBasics Customize My Account for WooCommerce <= 2.7.29 - Reflected Cross-Site Scripting via tab Parameter — SysBasics Customize My Account for WooCommerceCWE-79 6.1 Medium2024-11-09
CVE-2024-10261 Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.0 - Unauthenticated Arbitrary Shortcode Execution — Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content RestrictionCWE-94 7.3 High2024-11-09
CVE-2024-10640 The FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.2 - Unauthenticated Arbitrary Shortcode Execution — FOX – Currency Switcher Professional for WooCommerceCWE-94 7.3 High2024-11-09
CVE-2024-10508 RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery — RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User LoginCWE-230 9.8 Critical2024-11-09
CVE-2024-10801 WordPress User Extra Fields <= 16.5 - Unauthenticated Arbitrary File Upload — WordPress User Extra FieldsCWE-434 9.8 Critical2024-11-09
CVE-2024-10547 WP Membership <= 1.6.2 - Unauthenticated Arbitrary File Upload — WP MembershipCWE-434 9.8 Critical2024-11-09
CVE-2024-10871 Category Ajax Filter <= 2.8.2 - Unauthenticated Local File Inclusion — Category AJAX Filter – Advanced Filter for Posts & Custom Post TypesCWE-98 9.8 Critical2024-11-09
CVE-2024-10876 Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.3 - Reflected Cross-Site Scripting — Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & MoreCWE-79 6.1 Medium2024-11-09
CVE-2024-10683 Contact Form 7 - PayPal & Stripe Add-on <= 2.3.1 - Reflected Cross-Site Scripting — Contact Form 7 – PayPal & Stripe Add-onCWE-79 6.1 Medium2024-11-09
CVE-2024-8756 Quform - WordPress Form Builder <= 2.20.0 - Unauthenticated Sensitive Information Exposure — Quform - WordPress Form BuilderCWE-200 5.3 Medium2024-11-09
CVE-2024-10470 WPLMS Learning Management System for WordPress <= 4.962 - Unauthenticated Arbitrary File Read and Deletion — WPLMS Learning Management System for WordPress, WordPress LMSCWE-22 9.8 Critical2024-11-09
CVE-2024-10627 WooCommerce Support Ticket System <= 17.7 - Unauthenticated Arbitrary File Upload — WooCommerce Support Ticket SystemCWE-434 9.8 Critical2024-11-09
CVE-2024-10625 WooCommerce Support Ticket System <= 17.7 - Unauthenticated Arbitrary File Deletion — WooCommerce Support Ticket SystemCWE-22 9.8 Critical2024-11-09
CVE-2024-9226 Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages <= 1.7.6 - Reflected Cross-Site Scripting — Landing Page Cat – Coming Soon & Maintenance PagesCWE-79 6.1 Medium2024-11-09
CVE-2024-10294 CE21 Suite <= 2.2.0 - Missing Authorization to Unauthenticated Plugin Settings Change — CE21 SuiteCWE-862 6.5 Medium2024-11-09
CVE-2024-10285 CE21 Suite <= 2.2.0 - JWT Token Disclosure — CE21 SuiteCWE-200 9.8 Critical2024-11-09
CVE-2024-10284 CE21 Suite <= 2.2.0 - Authentication Bypass — CE21 SuiteCWE-288 9.8 Critical2024-11-09
CVE-2024-10586 Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation — Debug ToolCWE-862 9.8 Critical2024-11-09
CVE-2024-10588 Debug Tool <= 2.2 - Missing Authorization to Information Exposure — Debug ToolCWE-862 4.3 Medium2024-11-09
CVE-2024-9262 User Meta – User Profile Builder and User management plugin <= 3.1.1 - Insecure Direct Object Reference to Sensitive Information Exposure — User Meta – User Profile Builder and User management pluginCWE-639 6.5 Medium2024-11-09
CVE-2024-45764 Dell Enterprise SONiC OS 安全漏洞 — Enterprise SONiC OSCWE-304 9.0 Critical2024-11-08
CVE-2024-50589 Unprotected FHIR API — ElefantCWE-306 5.7 -2024-11-08
CVE-2024-50588 Unprotected Exposed Firebird Database with default credentials — ElefantCWE-1393 8.8 -2024-11-08
CVE-2024-7982 Registrations for The Events Calendar < 2.12.4 - Unauthenticated Stored XSS — Registrations for the Events Calendar 6.1 -2024-11-08
CVE-2023-27195 Trimble TM4Web 权限许可和访问控制问题漏洞 — n/a 9.8AICriticalAI2024-11-08
CVE-2019-20457 Brother MFC-J491DW 安全漏洞 — n/a 9.8AICriticalAI2024-11-07
CVE-2020-11926 Luvion Grand Elite 3 Connect 安全漏洞 — n/a 9.8AICriticalAI2024-11-07
CVE-2024-48950 Logpoint 安全漏洞 — n/a 8.1AIHighAI2024-11-07

Vulnerabilities classified as access:pre-auth represent 22121 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.