Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22463

22463 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-4444 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registration — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-420 5.3 Medium2024-05-10
CVE-2024-4434 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-89 9.8 Critical2024-05-10
CVE-2024-3547 Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Reflected Cross-Site Scripting — Unlimited Elements For ElementorCWE-79 6.1 Medium2024-05-10
CVE-2024-4280 White Label CMS <= 2.7.3 - Missing Authorization to Plugin Settings Reset — White Label CMSCWE-862 5.3 Medium2024-05-10
CVE-2024-4038 Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro <= 5.3.1 - Unauthenticated Arbitrary Shortcode Execution — Back In Stock Notifier for WooCommerce | WooCommerce Waitlist ProCWE-94 6.5 Medium2024-05-09
CVE-2024-4104 ADFO – Custom data in admin dashboard <= 1.9.0 - Reflected Cross-Site Scripting — ADFO – Custom data in admin dashboardCWE-79 6.1 Medium2024-05-09
CVE-2024-4463 Squelch Tabs and Accordions Shortcodes <= 0.4.7 - Cross-Site Request Forgery — Squelch Tabs and Accordions ShortcodesCWE-352 4.3 Medium2024-05-09
CVE-2024-4082 Joli FAQ SEO – WordPress FAQ Plugin <= 1.3.2 - Cross-Site Request Forgery — Joli FAQ SEO – WordPress FAQ PluginCWE-352 4.3 Medium2024-05-09
CVE-2024-3070 Last Viewed Posts by WPBeginner <= 1.0.0 - Unauthenticated PHP Object Injection — Last Viewed Posts by WPBeginnerCWE-502 9.8 Critical2024-05-09
CVE-2024-3806 Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts — PortoCWE-98 9.8 Critical2024-05-09
CVE-2024-1230 SimpleShop <= 2.10.0 - Cross-Site Request Forgery — SimpleShopCWE-284 4.3 Medium2024-05-09
CVE-2024-4103 ADFO – Custom data in admin dashboard <= 1.9.0 - Cross-Site Request Forgery — ADFO – Custom data in admin dashboardCWE-352 4.3 Medium2024-05-09
CVE-2024-4441 XML Sitemap & Google News <= 5.4.8 - Unauthenticated Local File Inclusion — XML Sitemap & Google NewsCWE-98 8.1 High2024-05-09
CVE-2024-3915 Swift Framework <= 2.7.31 - Missing Authorization to Unauthenticated Arbitrary Content Update — Swift FrameworkCWE-862 5.3 Medium2024-05-09
CVE-2024-4314 hostel <= 1.1.5.3 - Cross-Site Request Forgery — HostelCWE-352 4.3 Medium2024-05-09
CVE-2024-4312 Soccer Engine – Soccer Plugin for WordPress <= 1.12 - Cross-Site Request Forgery — Soccer Engine – Soccer Plugin for WordPressCWE-352 4.3 Medium2024-05-09
CVE-2024-4041 Yoast SEO <= 22.5 - Reflected Cross-Site Scripting — Yoast SEO – Advanced SEO with real-time guidance and built-in AICWE-79 6.1 Medium2024-05-09
CVE-2024-1229 SimpleShop <= 2.10.2 - Missing Authorization — SimpleShopCWE-862 5.3 Medium2024-05-09
CVE-2023-6327 ShopLentor (formerly WooLentor) <= 2.8.7 - Missing Authorization via purchased_new_products — ShopLentor – All-in-One WooCommerce Growth & Store Enhancement PluginCWE-862 5.3 Medium2024-05-09
CVE-2024-4150 Simple Basic Contact Form <= 20221201 - Reflected Cross-Site Scripting — Simple Basic Contact FormCWE-79 6.1 Medium2024-05-09
CVE-2024-32739 CyberPower PowerPanel Enterprise SQL Injection — CyberPower PowerPanel Enterprise 7.5 High2024-05-09
CVE-2024-32738 CyberPower PowerPanel Enterprise SQL Injection — CyberPower PowerPanel Enterprise 7.5 High2024-05-09
CVE-2024-32737 CyberPower PowerPanel Enterprise SQL Injection — CyberPower PowerPanel Enterprise 7.5 High2024-05-09
CVE-2024-32736 CyberPower PowerPanel Enterprise SQL Injection — CyberPower PowerPanel Enterprise 7.5 High2024-05-09
CVE-2024-32735 CyberPower PowerPanel Enterprise Missing Authentication — CyberPower PowerPanel Enterprise 9.8 Critical2024-05-09
CVE-2024-3016 NEC Platforms DT900 Series 安全漏洞 — ITK-6DGS-1(BK) TELCWE-912 6.5 -2024-05-09
CVE-2024-32049 BIG-IP Next Central Manager vulnerability — BIG-IP Next Central ManagerCWE-300 7.4 High2024-05-08
CVE-2024-4135 WP Latest Posts <= 5.0.7 - Authenticated (Subscriber+) Arbitrary Shortcode Execution — WP Latest PostsCWE-94 5.4 Medium2024-05-08
CVE-2024-4393 Social Connect <= 1.2 - Authentication Bypass — Social ConnectCWE-288 9.8 Critical2024-05-08
CVE-2023-7240 Broken Access Control leading to SSRF in NetIQ Identity Console — NetIQ Identity ConsoleCWE-20 5.8 Medium2024-05-07

Vulnerabilities classified as access:pre-auth represent 22463 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.