Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22423

22423 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-27942 Siemens RUGGEDCOM CROSSBOW 访问控制错误漏洞 — RUGGEDCOM CROSSBOWCWE-306 7.5 High2024-05-14
CVE-2024-27939 Siemens RUGGEDCOM CROSSBOW 安全漏洞 — RUGGEDCOM CROSSBOWCWE-862 9.8 Critical2024-05-14
CVE-2024-28134 PHOENIX CONTACT: MitM attack gains privileges of the current logged in user in CHARX Series — CHARX SEC-3000CWE-319 7.0 High2024-05-14
CVE-2024-25969 Dell PowerScale OneFS 安全漏洞 — PowerScale OneFSCWE-770 6.2 Medium2024-05-14
CVE-2024-25966 Dell PowerScale OneFS 安全漏洞 — PowerScale OneFSCWE-241 5.3 Medium2024-05-14
CVE-2024-25968 Dell PowerScale OneFS 加密问题漏洞 — PowerScale OneFSCWE-327 5.9 Medium2024-05-14
CVE-2024-4144 Simple Basic Contact Form <= 20240502 - Unauthenticated Arbitrary Shortcode Execution — Simple Basic Contact FormCWE-94 6.5 Medium2024-05-14
CVE-2024-33006 File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform — SAP NetWeaver Application Server ABAP and ABAP PlatformCWE-434 9.6 Critical2024-05-14
CVE-2024-32733 Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform — SAP NetWeaver Application Server ABAP and ABAP Platform CWE-79 6.1 Medium2024-05-14
CVE-2024-0870 YITH WooCommerce Gift Cards <= 4.12.0 - Missing Authorization to Unauthenticated WooCommerce Settings Update — YITH WooCommerce Gift CardsCWE-285 5.3 Medium2024-05-14
CVE-2023-6812 WP Compress – Image Optimizer [All-In-One] <= 6.20.01 - Open Redirect via css — WP Compress – Instant Performance & Speed OptimizationCWE-601 4.3 Medium2024-05-14
CVE-2024-34697 Freescout vulnerable to Stored HTML Injection in Editing Received Emails — freescoutCWE-74 7.6 High2024-05-13
CVE-2024-29895 Cacti command injection in cmd_realtime.php — cactiCWE-77 10.0 Critical2024-05-13
CVE-2024-34749 Phormer 安全漏洞 — Phormer 6.1 -2024-05-13
CVE-2024-4560 Kognetiks Chatbot for WordPress <= 1.9.9 - Unauthenticated Arbitrary File Upload via chatbot_chatgpt_upload_file_to_assistant Function — Kognetiks Chatbot for WordPressCWE-434 9.8 Critical2024-05-11
CVE-2024-4213 Shopping Cart & eCommerce Store <= 5.6.4 - Sensitive Information Exposure — Shopping Cart & eCommerce StoreCWE-922 5.3 Medium2024-05-10
CVE-2024-4413 Hotel Booking Lite <= 4.11.1 - Unauthenticated PHP Object Injection — MotoPress Hotel BookingCWE-502 9.8 Critical2024-05-10
CVE-2024-34199 TinyWeb 安全漏洞 — n/a 7.5 -2024-05-10
CVE-2024-34070 Froxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromise — FroxlorCWE-79 9.7 Critical2024-05-10
CVE-2024-4039 Orders Tracking for WooCommerce <= 1.2.10 - Unauthenticated Arbitrary Shortcode Execution — Orders Tracking for WooCommerceCWE-94 6.5 Medium2024-05-10
CVE-2024-4444 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registration — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-420 5.3 Medium2024-05-10
CVE-2024-4434 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-89 9.8 Critical2024-05-10
CVE-2024-3547 Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Reflected Cross-Site Scripting — Unlimited Elements For ElementorCWE-79 6.1 Medium2024-05-10
CVE-2024-4280 White Label CMS <= 2.7.3 - Missing Authorization to Plugin Settings Reset — White Label CMSCWE-862 5.3 Medium2024-05-10
CVE-2024-4038 Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro <= 5.3.1 - Unauthenticated Arbitrary Shortcode Execution — Back In Stock Notifier for WooCommerce | WooCommerce Waitlist ProCWE-94 6.5 Medium2024-05-09
CVE-2024-4104 ADFO – Custom data in admin dashboard <= 1.9.0 - Reflected Cross-Site Scripting — ADFO – Custom data in admin dashboardCWE-79 6.1 Medium2024-05-09
CVE-2024-4463 Squelch Tabs and Accordions Shortcodes <= 0.4.7 - Cross-Site Request Forgery — Squelch Tabs and Accordions ShortcodesCWE-352 4.3 Medium2024-05-09
CVE-2024-4082 Joli FAQ SEO – WordPress FAQ Plugin <= 1.3.2 - Cross-Site Request Forgery — Joli FAQ SEO – WordPress FAQ PluginCWE-352 4.3 Medium2024-05-09
CVE-2024-3070 Last Viewed Posts by WPBeginner <= 1.0.0 - Unauthenticated PHP Object Injection — Last Viewed Posts by WPBeginnerCWE-502 9.8 Critical2024-05-09
CVE-2024-3806 Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts — PortoCWE-98 9.8 Critical2024-05-09

Vulnerabilities classified as access:pre-auth represent 22423 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.