Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22137

22137 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-6893 Journyx Unauthenticated XML External Entities Injection — Journyx (jtime)CWE-611 9.8AICriticalAI2024-08-07
CVE-2024-20451 Cisco Small Business SPA300 Series IP Phones和Cisco Small Business SPA500 Series IP Phones 安全漏洞 — Cisco Small Business IP PhonesCWE-120 7.5 High2024-08-07
CVE-2024-20454 Cisco Small Business SPA500 Series IP Phones和Cisco Small Business 安全漏洞 — Cisco Small Business IP PhonesCWE-120 9.8 Critical2024-08-07
CVE-2024-20450 Cisco Small Business SPA300 Series IP Phones和Cisco Small Business SPA500 Series IP Phones 安全漏洞 — Cisco Small Business IP PhonesCWE-120 9.8 Critical2024-08-07
CVE-2024-6494 WordPress File Upload < 4.24.8 - Unauthenticated Stored XSS — WordPress File Upload 6.1AIMediumAI2024-08-07
CVE-2024-41243 Kashipara Responsive School Management System 安全漏洞 — n/a 5.3AIMediumAI2024-08-07
CVE-2024-41244 Kashipara Responsive School Management System 安全漏洞 — n/a 5.3AIMediumAI2024-08-07
CVE-2024-41245 Kashipara Responsive School Management System 安全漏洞 — n/a 5.3AIMediumAI2024-08-07
CVE-2024-41246 Kashipara Responsive School Management System 安全漏洞 — n/a 5.3AIMediumAI2024-08-07
CVE-2024-41247 Kashipara Responsive School Management System 安全漏洞 — n/a 5.3AIMediumAI2024-08-07
CVE-2024-41248 Kashipara Responsive School Management System 安全漏洞 — n/a 5.3AIMediumAI2024-08-07
CVE-2024-41249 Kashipara Responsive School Management System 安全漏洞 — n/a 5.3AIMediumAI2024-08-07
CVE-2024-41250 Kashipara Responsive School Management System 安全漏洞 — n/a 5.3AIMediumAI2024-08-07
CVE-2024-41251 Kashipara Responsive School Management System 安全漏洞 — n/a 6.5AIMediumAI2024-08-07
CVE-2024-41252 Kashipara Responsive School Management System 安全漏洞 — n/a 6.5AIMediumAI2024-08-07
CVE-2024-38166 Microsoft Dynamics 365 Cross-site Scripting Vulnerability — Dynamics CRM Service Portal Web ResourceCWE-79 8.2 High2024-08-06
CVE-2024-42400 Unauthenticated Denial-of-Service (DoS) Vulnerabilities in the Soft AP Daemon Service Accessed by the PAPI Protocol — HPE Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10 5.3 Medium2024-08-06
CVE-2024-42399 Unauthenticated Denial-of-Service (DoS) Vulnerabilities in the Soft AP Daemon Service Accessed by the PAPI Protocol — HPE Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10 5.3 Medium2024-08-06
CVE-2024-42398 Unauthenticated Denial-of-Service (DoS) Vulnerabilities in the Soft AP Daemon Service Accessed by the PAPI Protocol — HPE Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10 5.3 Medium2024-08-06
CVE-2024-42393 Unauthenticated Stack-Based Buffer Overflow Remote Command Execution (RCE) in the Soft AP Daemon Service Accessed by the PAPI Protocol — Hpe Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10 9.8 Critical2024-08-06
CVE-2024-42394 Unauthenticated Stack-Based Buffer Overflow Remote Command Execution (RCE) in the Soft AP Daemon Service Accessed by the PAPI Protocol — HPE Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10 9.8 Critical2024-08-06
CVE-2024-42395 Unauthenticated Stack-Based Buffer Overflow Remote Command Execution (RCE) in the AP Certificate Management Service Accessed by the PAPI Protocol — HPE Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10 9.8 Critical2024-08-06
CVE-2024-42396 Unauthenticated Denial-of-Service (DoS) Vulnerabilities in the AP Certificate Management Service Accessed by the PAPI Protocol — HPE Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10 5.3 Medium2024-08-06
CVE-2024-42397 Unauthenticated Denial-of-Service (DoS) Vulnerabilities in the AP Certificate Management Service Accessed by the PAPI Protocol — HPE Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10 5.3 Medium2024-08-06
CVE-2024-28962 Dell Update和Dell Alienware Update 安全漏洞 — Dell Update (DU)CWE-610 6.5 Medium2024-08-06
CVE-2024-6782 Calibre Remote Code Execution — CalibreCWE-863 9.8 Critical2024-08-06
CVE-2024-6781 Calibre Arbitrary File Read — CalibreCWE-22 7.5 High2024-08-06
CVE-2024-7485 Traffic Manager <= 1.4.5 - Unauthenticated Stored Cross-Site Scripting — Traffic ManagerCWE-79 7.2 High2024-08-06
CVE-2024-39227 GL.iNet多款产品 安全漏洞 — n/a 9.1AICriticalAI2024-08-06
CVE-2024-40101 Microweber 安全漏洞 — n/a 6.1AIMediumAI2024-08-06

Vulnerabilities classified as access:pre-auth represent 22137 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.