Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22137

22137 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-5344 The Plus Addons for Elementor Page Builder <= 5.5.6 - Reflected Cross-Site Scripting via WP Login and Register Widget — The Plus Addons for Elementor Page Builder ProCWE-79 6.1 Medium2024-06-21
CVE-2024-38874 TYPO3 安全漏洞 — n/a 5.4 Medium2024-06-21
CVE-2023-49111 Reflected Cross-Site-Scripting in Kiuwan SAST — SASTCWE-79 6.1 -2024-06-20
CVE-2024-4098 Shariff Wrapper <= 4.6.13 - Unauthenticated Local File Inclusion — Shariff WrapperCWE-22 9.8 Critical2024-06-20
CVE-2024-5522 HTML5 Video Player < 2.5.27 - Unauthenticated SQLi — HTML5 Video Player 9.8AICriticalAI2024-06-20
CVE-2024-3597 Export WP Page to Static HTML/CSS <= 2.2.2 - Open Redirect — Export WordPress Pages to Static HTML & PDF — Static Site ExportCWE-601 7.1 High2024-06-20
CVE-2024-3605 WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection — WP Hotel BookingCWE-89 10.0 Critical2024-06-20
CVE-2024-5432 Lifeline Donation <= 1.2.6 - Authentication Bypass — Lifeline DonationCWE-288 9.8 Critical2024-06-20
CVE-2024-0789 WP Maintenance <= 6.1.9.2 - IP Spoofing to Maintenance Mode Bypass — WP MaintenanceCWE-348 5.3 Medium2024-06-19
CVE-2024-1407 Paid Memberships Pro <= 2.12.10 - Cross-Site Request Forgery to Membership Modification — Paid Memberships Pro – Content Restriction, User Registration, & Paid SubscriptionsCWE-352 5.4 Medium2024-06-19
CVE-2024-5343 Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.19 - Cross-Site Request Forgery to Post Creation and Limited Data Loss — Robo Gallery – Photo & Image SliderCWE-352 8.8 High2024-06-19
CVE-2024-3229 Salon Booking System <= 10.2 - Unauthenticated Arbitrary File Upload — Salon Booking System – Free VersionCWE-434 9.8 Critical2024-06-19
CVE-2024-4541 Custom Product List Table <= 3.0.0 - Cross-Site Request Forgery — Custom Product List TableCWE-352 4.3 Medium2024-06-19
CVE-2024-4663 OSM Map Widget for Elementor <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter — OSM Map Widget for ElementorCWE-79 6.4 Medium2024-06-19
CVE-2024-5021 WordPress Picture / Portfolio / Media Gallery <= 3.0.1 - Unauthenticated Server-Side Request Forgery — WordPress Picture / Portfolio / Media GalleryCWE-918 9.3 Critical2024-06-19
CVE-2024-4787 Cost Calculator Builder PRO <= 3.1.75 - Unauthenticated Arbitrary Email Sending — Cost Calculator Builder PROCWE-20 5.8 Medium2024-06-19
CVE-2024-6125 Login with phone number <= 1.7.34 - Insecure Password Reset Mechanism — OTP Login With Phone Number, OTP VerificationCWE-640 8.1 High2024-06-19
CVE-2024-21685 Atlassian JIRA Data Center 安全漏洞 — Jira Core Data Center 4.3AIMediumAI2024-06-18
CVE-2024-34024 Fujitsu ID Link Manager和Fujitsu TIME CREATOR 安全漏洞 — FUJITSU Business Application ID Link Manager II 5.3AIMediumAI2024-06-18
CVE-2024-33620 Fujitsu ID Link Manager和Fujitsu TIME CREATOR 安全漏洞 — FUJITSU Business Application ID Link Manager II 7.5AIHighAI2024-06-18
CVE-2024-1634 Scheduling Plugin – Online Booking for WordPress <= 3.5.10 - Missing Authorization to Unauthenticated Service Disconnection — Scheduling Plugin – Online Booking for WordPressCWE-862 6.5 Medium2024-06-18
CVE-2024-5541 Ibtana - WordPress Website Builder <= 1.2.3.3 - Unauthenticated reCAPTCHA Settings Update — Ibtana – WordPress Website BuilderCWE-862 5.3 Medium2024-06-18
CVE-2024-6048 Openfind MailGates and MailAudit - OS Command Injection — MailGates 5.0CWE-78 9.8 Critical2024-06-17
CVE-2024-6047 GeoVision EOL device - OS Command Injection — GV_DSP_LPR_V2CWE-78 9.8 Critical2024-06-17
CVE-2024-6045 D-Link router - Hidden Backdoor — G403CWE-912 8.8 High2024-06-17
CVE-2024-6044 D-Link router - Arbitrary File Reading — G403CWE-22 6.5 Medium2024-06-17
CVE-2024-34833 Payroll Management System 安全漏洞 — n/a 9.8AICriticalAI2024-06-17
CVE-2024-4258 Video Gallery – YouTube Playlist, Channel Gallery by YotuWP <= 1.3.13 - Unauthenticated Local File Inclusion — Video Gallery – YouTube Playlist, Channel Gallery by YotuWPCWE-98 9.8 Critical2024-06-15
CVE-2024-5868 WooCommerce - Social Login <= 2.6.2 - Email Verification due to Insufficient Randomness — WooCommerce - Social LoginCWE-330 6.5 Medium2024-06-15
CVE-2024-5871 WooCommerce - Social Login <= 2.6.2 - Unauthenticated PHP Object Injection — WooCommerce - Social LoginCWE-502 9.8 Critical2024-06-15

Vulnerabilities classified as access:pre-auth represent 22137 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.