Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22348

22348 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-5871 WooCommerce - Social Login <= 2.6.2 - Unauthenticated PHP Object Injection — WooCommerce - Social LoginCWE-502 9.8 Critical2024-06-15
CVE-2024-5671 Trellix IPS Manager 代码问题漏洞 — Intrusion Prevention System (IPS) ManagerCWE-502 9.8 Critical2024-06-14
CVE-2024-2472 LatePoint Plugin <= 4.9.9 - Missing Authorization and Sensitive Information Exposure via IDOR — LatePoint PluginCWE-639 9.1 Critical2024-06-14
CVE-2024-3912 ASUS Router - Upload arbitrary firmware — DSL-N17UCWE-434 9.8 Critical2024-06-14
CVE-2024-5577 Where I Was, Where I Will Be <= 1.1.1 - Unauthenticated Remote File Inclusion — Where I Was, Where I Will BeCWE-98 9.8 Critical2024-06-14
CVE-2024-31163 ASUS Download Master - Buffer Overflow — Download MasterCWE-121 7.2 High2024-06-14
CVE-2024-31162 ASUS Download Master - OS Command Injection — Download MasterCWE-78 7.2 High2024-06-14
CVE-2024-3966 Pray For Me <= 1.0.4 - Unauthenticated Stored XSS — Pray For Me 6.1AIMediumAI2024-06-14
CVE-2024-5551 WP STAGING PRO - Backup Duplicator & Migration <= 5.6.0 - Cross-Site Request Forgery to Limited Local File Inclusion — WP STAGING Pro WordPress Backup PluginCWE-352 7.5 High2024-06-14
CVE-2024-4936 Canto <= 3.0.8 - Unauthenticated Remote File Inclusion — CantoCWE-98 9.8 Critical2024-06-14
CVE-2024-1094 Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling Plugin <= 1.0.21 - Missing Authorization to Limited Privilege Escalation — Timetics – Appointment Booking & SchedulingCWE-862 7.3 High2024-06-14
CVE-2024-27169 Lack of authentication — Toshiba Tec e-Studio multi-function peripheral (MFP)CWE-306 8.4 High2024-06-14
CVE-2023-6492 Simple Sitemap <= 3.5.13 - Cross-Site Request Forgery via admin_notices — Simple Sitemap – Create a Responsive HTML SitemapCWE-352 4.3 Medium2024-06-14
CVE-2024-0892 Schema App Structured Data <= 2.2.0 - Cross-Site Request Forgery — Schema App Structured DataCWE-352 4.3 Medium2024-06-14
CVE-2024-3080 ASUS Router - Improper Authentication — ZenWiFi XT8CWE-287 9.8 Critical2024-06-14
CVE-2024-27144 Pre-authenticated Remote Code Execution — Toshiba Tec e-Studio multi-function peripheral (MFP)CWE-22 9.8 Critical2024-06-14
CVE-2024-27141 Pre-authenticated Time-Based Blind XXE injection — Toshiba Tec e-Studio multi-function peripheral (MFP)CWE-776 5.9 Medium2024-06-14
CVE-2024-33374 LB-LINK BL-W1210M 安全漏洞 — n/a 8.8AIHighAI2024-06-14
CVE-2024-5949 Deep Sea Electronics DSE855 Multipart Boundary Infinite Loop Denial-of-Service Vulnerability — DSE855CWE-835 6.5AIMediumAI2024-06-13
CVE-2024-37131 Dell Secure Connect Gateway 安全漏洞 — Secure Connect Gateway (SCG) Policy ManagerCWE-942 7.5 High2024-06-13
CVE-2024-30472 Dell ThinOS 信息泄露漏洞 — Wyse 5070 Thin ClientCWE-200 7.5 High2024-06-13
CVE-2024-4371 CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More <= 4.4.1 - Unauthenticated PHP Object Injection — CoDesigner – All in One Elementor WooCommerce BuilderCWE-502 9.0 Critical2024-06-13
CVE-2024-0979 Dashboard Widgets Suite <= 3.4.3 - Reflected Cross-Site Scripting — Dashboard Widgets SuiteCWE-79 6.1 Medium2024-06-13
CVE-2024-3552 Web Directory Free < 1.7.0 - Unauthenticated SQL Injection — Web Directory Free 9.8AICriticalAI2024-06-13
CVE-2024-2098 Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary — Download ManagerCWE-289 7.5 High2024-06-13
CVE-2024-3922 Dokan Pro <= 3.10.3 - Unauthenticated SQL Injection — Dokan ProCWE-89 10.0 Critical2024-06-13
CVE-2023-35858 Modern Campus Omni CMS 安全漏洞 — n/a 5.3AIMediumAI2024-06-13
CVE-2023-35860 Modern Campus Omni CMS 安全漏洞 — n/a 7.5AIHighAI2024-06-13
CVE-2024-28964 Dell Common Event Enabler 代码问题漏洞 — Common Event EnablerCWE-502 7.8 High2024-06-12
CVE-2024-34065 @strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass — strapiCWE-294 7.1 High2024-06-12

Vulnerabilities classified as access:pre-auth represent 22348 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.