Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22463

22463 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-36421 GHSL-2023-234: Flowise Cors Misconfiguration in packages/server/src/index.ts — FlowiseCWE-346 7.5 High2024-07-01
CVE-2024-36401 Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver — geoserverCWE-95 9.8 Critical2024-07-01
CVE-2024-6425 Incorrect Provision of Specified Functionality vulnerability in MESbook — MESbookCWE-684 9.1 Critical2024-07-01
CVE-2024-6424 Server-Side Request Forgery vulnerability in MESbook — MESbookCWE-918 9.3 Critical2024-07-01
CVE-2024-6387 Openssh: regresshion - race condition in ssh allows rce/dos CWE-364 8.1 High2024-07-01
CVE-2024-37763 Machform 安全漏洞 — n/a 6.1AIMediumAI2024-07-01
CVE-2023-4017 Goya <= 1.0.8.7 - Unauthenticated Reflected Cross-Site Scripting via Multiple Parameters — GoyaCWE-79 6.1 Medium2024-06-29
CVE-2024-5598 Advanced File Manager <= 5.2.4 - Sensitive Information Exposure via Directory Listing — Advanced File Manager – Ultimate File Manager for WordPress And Document Library SolutionCWE-922 7.5 High2024-06-29
CVE-2024-5889 Events Manager <= 6.4.8 - Reflected Cross-Site Scripting — Events Manager – Calendar, Bookings, Tickets, and more!CWE-79 6.1 Medium2024-06-29
CVE-2024-6265 UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sort_by' — UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WPCWE-89 9.8 Critical2024-06-29
CVE-2024-6405 Floating Social Buttons <= 1.5 - Cross-Site Request Forgery — Floating Social ButtonsCWE-352 6.1 Medium2024-06-29
CVE-2024-38528 Unlimited number of NTS-KE connections can crash ntpd-rs server — ntpd-rsCWE-770 7.5 High2024-06-28
CVE-2024-2795 SEO SIMPLE PACK <= 3.2.1 - Information Exposure — SEO SIMPLE PACKCWE-200 5.3 Medium2024-06-28
CVE-2024-6288 Conversios.io - All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce <= 7.1.0 - Reflected Cross-Site Scripting — Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-ChannelsCWE-79 4.7 Medium2024-06-28
CVE-2024-6071 PTC Creo Elements/Direct License Server Missing Authorization — Creo Elements/Direct LicenseCWE-862 10.0 Critical2024-06-27
CVE-2024-6127 BC Security Empire Path Traversal RCE — EmpireCWE-22 9.8 Critical2024-06-27
CVE-2024-6085 Path Traversal in parisneo/lollms — parisneo/lollmsCWE-22 9.1AICriticalAI2024-06-27
CVE-2024-3043 Zigbee co-ordinator realignment packet may lead to denial of service — Ember ZNet SDKCWE-829 7.5 High2024-06-27
CVE-2024-31883 IBM Security Verify Access denial of service — Security Verify AccessCWE-703 5.3 Medium2024-06-27
CVE-2024-36072 Netwrix CoSoSys Endpoint Protector 安全漏洞 — n/a 9.8AICriticalAI2024-06-27
CVE-2024-1839 Intrado 911 Emergency Gateway 安全漏洞 — 911 Emergency Gateway (EGW)CWE-89 10.0 Critical2024-06-26
CVE-2024-29175 Dell PowerProtect Data Domain 安全漏洞 — PowerProtect DDCWE-327 5.9 Medium2024-06-26
CVE-2024-23766 HMS Networks Anybus X-Gateway AB7832-F3 安全漏洞 — n/a 7.5AIHighAI2024-06-26
CVE-2024-23767 HMS Networks Anybus X-Gateway AB7832-F3 安全漏洞 — n/a 7.5AIHighAI2024-06-26
CVE-2024-4869 WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.2.0 - Unauthenticated Stored Cross-Site Scripting via Client-IP header — Cookie Banner for GDPR / CCPA – WPLP Cookie ConsentCWE-79 7.2 High2024-06-25
CVE-2024-5019 WhatsUp Gold LoadCSSUsingBasePath Directory Traversal Information Disclosure Vulnerability — WhatsUp GoldCWE-22 5.3 Medium2024-06-25
CVE-2024-5018 WhatsUp Gold LoadUsingBasePath Directory Traversal Information Disclosure Vulnerability — WhatsUp GoldCWE-22 5.3 Medium2024-06-25
CVE-2024-5017 WhatsUp Gold AppProfileImport path traversal vulnerability — WhatsUp GoldCWE-22 6.5 Medium2024-06-25
CVE-2024-5013 WhatsUp Gold InstallController Denial-of-Service Vulnerability — WhatsUp GoldCWE-400 7.5 High2024-06-25
CVE-2024-5012 WhatsUp Gold Missing Authentication GetWindowsCredential Information Disclosure Vulnerability — WhatsUp GoldCWE-287 8.6 High2024-06-25

Vulnerabilities classified as access:pre-auth represent 22463 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.