Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22137

22137 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-8522 LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields' — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-89 10.0 Critical2024-09-12
CVE-2024-8529 LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields' — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-89 10.0 Critical2024-09-12
CVE-2024-8622 amCharts: Charts and Maps <= 1.4.4 - Reflected Cross-Site Scripting via Cross-Site Request Forgery — amCharts: Charts and MapsCWE-79 6.1 Medium2024-09-12
CVE-2024-6019 Music Request Manager <= 1.3 - Unauthenticated Stored XSS — Music Request Manager 6.1AIMediumAI2024-09-12
CVE-2024-29847 Ivanti Endpoint Manager 代码问题漏洞 — EPM 9.8 -2024-09-12
CVE-2024-37397 Ivanti Endpoint Manager 安全漏洞 — EPM 7.5AIHighAI2024-09-12
CVE-2024-20304 Cisco IOS XR Software Packet Memory Exhaustion Vulnerability — Cisco IOS XR SoftwareCWE-401 8.6 High2024-09-11
CVE-2024-20406 Cisco IOS XR Software Intermediate System-to-Intermediate System Denial of Service Vulnerability — Cisco IOS XR SoftwareCWE-20 7.4 High2024-09-11
CVE-2024-20317 Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerability — Cisco IOS XR SoftwareCWE-684 7.4 High2024-09-11
CVE-2024-20390 Cisco IOS XR Software Dedicated XML Agent TCP Denial of Service Vulnerability — Cisco IOS XR SoftwareCWE-940 5.3 Medium2024-09-11
CVE-2024-27112 SQL Injection in SOPlanning before 1.52.02 — SO PlanningCWE-89 9.8AICriticalAI2024-09-11
CVE-2024-27114 Remote Code Execution through File Upload in SOPlanning before 1.52.02 — SO PlanningCWE-367 8.1AIHighAI2024-09-11
CVE-2024-27115 Remote Code Execution through File Upload in SOPlanning before 1.52.02 — SO PlanningCWE-434 9.8AICriticalAI2024-09-11
CVE-2024-27113 Insecure Direct Object Reference to export Database in SOPlanning before 1.52.02 — SO PlanningCWE-200 6.2AIMediumAI2024-09-11
CVE-2024-8277 WooCommerce Photo Reviews Premium <= 1.3.13.2 - Authentication Bypass to Account Takeover and Privilege Escalation — WooCommerce Photo Reviews PremiumCWE-288 9.8 Critical2024-09-11
CVE-2024-7727 HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.32 - Missing Authorization in multiple functions via h5vp_ajax_handler — HTML5 Video Player – Embed and Play Videos in Custom PlayerCWE-862 5.3 Medium2024-09-11
CVE-2024-8321 Ivanti EPM 安全漏洞 — Endpoint ManagerCWE-306 5.8 Medium2024-09-10
CVE-2024-8320 Ivanti EPM 安全漏洞 — Endpoint ManagerCWE-306 5.3 Medium2024-09-10
CVE-2024-8191 Ivanti EPM 安全漏洞 — Endpoint ManagerCWE-89 7.8 High2024-09-10
CVE-2024-8232 iniNet Solutions SpiderControl SCADA Web Server Unrestricted Upload of File with Dangerous Type — SpiderControl SCADA Web ServerCWE-434 7.5 High2024-09-10
CVE-2024-8504 VICIdial Authenticated Remote Code Execution — VICIdialCWE-78 8.8AIHighAI2024-09-10
CVE-2024-8503 VICIdial Unauthenticated SQL Injection — VICIdialCWE-89 7.5AIHighAI2024-09-10
CVE-2024-45409 The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector — ruby-samlCWE-347 10.0 Critical2024-09-10
CVE-2024-45596 Directus's session is cached for OpenID and OAuth2 if `redirect` is not used — directusCWE-524 7.4 High2024-09-10
CVE-2024-42423 Dell ThinOS 安全漏洞 — Wyse Proprietary OS (Modern ThinOS)CWE-863 6.1 Medium2024-09-10
CVE-2022-45856 Fortinet FortiClient 信任管理问题漏洞 — FortiClientiOSCWE-295 4.6 Medium2024-09-10
CVE-2024-31489 Fortinet FortiClient 信任管理问题漏洞 — FortiClientMacCWE-295 6.4 Medium2024-09-10
CVE-2024-35282 Fortinet FortiClient 安全漏洞 — FortiClientiOSCWE-316 3.9 Medium2024-09-10
CVE-2024-33508 Fortinet FortiClientEMS 命令注入漏洞 — FortiClientEMSCWE-77 6.9 High2024-09-10
CVE-2024-8369 EventPrime <= 4.0.4.3 - Missing Authorization to Unauthenticated Private or Password-Protected Events Disclosure — EventPrime – Events Calendar, Bookings and TicketsCWE-862 5.3 Medium2024-09-10

Vulnerabilities classified as access:pre-auth represent 22137 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.