Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22137

22137 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-6557 SchedulePress <= 5.1.3 - Unauthenticated Full Path Disclosure — SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post PublisherCWE-200 5.3 Medium2024-07-16
CVE-2024-40627 OpaMiddleware does not filter HTTP OPTIONS requests — fastapi-opaCWE-204 5.8 Medium2024-07-15
CVE-2024-38492 Symantec Privileged Access Manager Remote Command Execution vulnerability — Symantec Privileged Access Management 9.8 -2024-07-15
CVE-2024-38491 Symantec Privileged Access Manager SQL Injection vulnerability — Symantec Privileged Access Management 7.5 -2024-07-15
CVE-2024-36456 Symantec Privileged Access Manager Remote Command Execution vulnerability — Symantec Privileged Access Management 9.8 -2024-07-15
CVE-2024-36455 Symantec Privileged Access Manager Remote Command Execution vulnerability — Symantec Privileged Access Management 9.8 -2024-07-15
CVE-2024-6741 Openfind Mail2000 - HttpOnly flag bypass — Mail2000 V7.0CWE-693 5.8 Medium2024-07-15
CVE-2024-6740 Openfind Mail2000 - Stored XSS — Mail2000 V7.0CWE-79 6.1 Medium2024-07-15
CVE-2024-6744 Cellopoint Secure Email Gateway 安全漏洞 — Secure Email GatewayCWE-121 9.8 Critical2024-07-15
CVE-2024-6743 AguardNet Space Management System - SQL injection — Space Management SystemCWE-89 9.8 Critical2024-07-15
CVE-2024-6289 WPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure — WPS Hide Login 6.1 -2024-07-15
CVE-2024-6738 WisdomGarden Tronclass - Broken Access Control — TronclassCWE-284 5.3 Medium2024-07-15
CVE-2024-5450 Bug Library < 2.1.1 - Unauthenticated RCE — Bug Library 9.8AICriticalAI2024-07-13
CVE-2024-5079 WP eMember < 10.6.7 - Unauthenticated Stored XSS via Member Registration — wp-eMember 6.1AIMediumAI2024-07-13
CVE-2024-6574 Laposta <= 1.12 - Unauthenticated Full Path Disclosure — LapostaCWE-200 5.3 Medium2024-07-13
CVE-2024-5902 UserFeedback Lite <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Name Parameter — UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in SecondsCWE-79 7.2 High2024-07-12
CVE-2024-6328 MStore API – Create Native Android & iOS Apps On The Cloud <= 4.14.7 - Authentication Bypass — MStore API – Create Native Android & iOS Apps On The CloudCWE-288 9.8 Critical2024-07-12
CVE-2024-6588 PowerPress Podcasting plugin by Blubrry <= 11.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via media_url Parameter — PowerPress Podcasting plugin by BlubrryCWE-79 6.4 Medium2024-07-12
CVE-2024-6555 WP Popups – WordPress Popup builder <= 2.2.0.1 - Unauthenticated Full Path Disclosure — WP Popups – WordPress Popup builderCWE-200 5.3 Medium2024-07-12
CVE-2024-1375 Event post <= 5.9.10 - Cross-Site Request Forgery — Event postCWE-352 4.3 Medium2024-07-12
CVE-2024-40110 Poultry Farm Management System 安全漏洞 — n/a 9.8AICriticalAI2024-07-12
CVE-2024-39553 Junos OS Evolved: Receipt of arbitrary data when sampling service is enabled, leads to partial Denial of Service (DoS). — Junos OS EvolvedCWE-668 6.5 Medium2024-07-11
CVE-2024-39552 Junos OS and Junos OS Evolved: Malformed BGP UPDATE causes RPD crash — Junos OSCWE-755 7.5 High2024-07-11
CVE-2024-39551 Junos OS: SRX Series and MX Series with SPC3 and MS-MPC/MIC: Receipt of specific packets in H.323 ALG causes traffic drop — Junos OSCWE-400 7.5 High2024-07-11
CVE-2024-39550 Junos OS: MX Series with SPC3 line card: Port flaps causes rtlogd memory leak leading to Denial of Service — Junos OSCWE-401 6.5 Medium2024-07-11
CVE-2024-39548 Junos OS Evolved: Receipt of specific packets in the aftmand process will lead to a memory leak — Junos OS EvolvedCWE-400 7.5 High2024-07-11
CVE-2024-39545 Junos OS: SRX Series, MX Series with SPC3 and NFX350: When VPN tunnels parameters are not configured in specific way the iked process will crash — Junos OSCWE-754 7.5 High2024-07-11
CVE-2024-39543 Junos OS and Junos OS Evolved: Receipt of a large RPKI-RTR PDU packet can cause rpd to crash — Junos OSCWE-120 6.5 Medium2024-07-11
CVE-2024-39542 Junos OS and Junos OS Evolved: A malformed CFM packet or specific transit traffic leads to FPC crash — Junos OS 7.5 High2024-07-11
CVE-2024-39541 Junos OS and Junos OS Evolved: Inconsistent information in the TE database can lead to an rpd crash — Junos OSCWE-755 6.5 Medium2024-07-11

Vulnerabilities classified as access:pre-auth represent 22137 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.