Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22495

22495 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-27521 TOTOLINK A3300R 安全漏洞 — n/a 9.8AICriticalAI2024-03-26
CVE-2024-28108 phpMyFAQ Stored HTML Injection at contentLink — phpMyFAQCWE-79 4.7 Medium2024-03-25
CVE-2024-25964 Dell PowerScale OneFS 安全漏洞 — PowerScale OneFSCWE-385 5.3 Medium2024-03-25
CVE-2024-29009 WordPress plugin easy-popup-show 安全漏洞 — easy-popup-show 8.8AIHighAI2024-03-25
CVE-2024-21865 KDDI HGW BL1500HM 安全漏洞 — HGW BL1500HMCWE-1391 8.8AIHighAI2024-03-25
CVE-2024-29071 KDDI HGW BL1500HM 安全漏洞 — HGW BL1500HMCWE-1391 6.5AIMediumAI2024-03-25
CVE-2024-28041 KDDI HGW BL1500HM 安全漏洞 — HGW BL1500HM 8.8AIHighAI2024-03-25
CVE-2024-2326 Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin <= 3.6.3 - Cross-Site Request Forgery to Plugin Settings Update — PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments PluginCWE-352 4.3 Medium2024-03-23
CVE-2024-0957 WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.4.1 - Unauthenticated Stored Cross-Site Scripting — WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping LabelsCWE-79 6.1 Medium2024-03-22
CVE-2024-29272 VvvebJs 安全漏洞 — n/a 9.8 -2024-03-22
CVE-2024-29275 SeaCMS 安全漏洞 — n/a 9.8 -2024-03-22
CVE-2024-29385 D-Link DIR-845L 安全漏洞 — n/a 9.8 -2024-03-22
CVE-2024-29732 SQL Injection vulnerability on SCAN_VISIO eDocument Suite Web Viewer from Abast — SCAN_VISIO eDocument Suite Web ViewerCWE-89 9.8 Critical2024-03-21
CVE-2024-1538 File Manager <= 7.2.4 - Cross-Site Request Forgery to Local JS File Inclusion — File ManagerCWE-352 8.8 High2024-03-21
CVE-2023-48901 Autoexpress 安全漏洞 — n/a 9.8AICriticalAI2024-03-21
CVE-2023-48902 Autoexpress 安全漏洞 — n/a 9.8AICriticalAI2024-03-21
CVE-2023-48903 AutoExpress 安全漏洞 — n/a 6.1AIMediumAI2024-03-21
CVE-2024-28179 Jupyter Server Proxy's Websocket Proxying does not require authentication — jupyter-server-proxyCWE-306 9.1 Critical2024-03-20
CVE-2024-1711 Create by Mediavine <= 1.9.4 - Unauthenticated SQL Injection via 'id' — CreateCWE-89 9.8 Critical2024-03-20
CVE-2024-1379 Website Article Monetization By MageNet <= 1.0.11 - Unauthenticated Stored Cross-Site Scripting — Website Article Monetization By MageNetCWE-79 6.1 Medium2024-03-20
CVE-2024-1325 Live Sales Notification for Woocommerce – Woomotiv <= 3.4.3 - Cross-Site Request Forgery via ajax_cancel_review — Live Sales Notification for Woocommerce – WoomotivCWE-352 4.3 Medium2024-03-20
CVE-2024-1119 Order Tip for WooCommerce <= 1.3.1 - Missing Authorization to Unauthenticated Data Export — Order Tip for WooCommerceCWE-862 5.3 Medium2024-03-20
CVE-2024-1181 Coming Soon, Under Construction & Maintenance Mode By Dazzler <= 2.1.2 - Maintenance Mode Bypass — Coming Soon, Under Construction & Maintenance Mode By DazzlerCWE-862 5.3 Medium2024-03-20
CVE-2024-1473 Coming Soon & Maintenance Mode by Colorlib <= 1.0.99 - Information Exposure — Coming Soon & Maintenance Mode by ColorlibCWE-284 5.3 Medium2024-03-20
CVE-2024-0337 Travelpayouts <= 1.1.15 - Open Redirect — Travelpayouts: All Travel Brands in One Place 6.1AIMediumAI2024-03-20
CVE-2024-1785 Contests by Rewards Fuel <= 2.0.62 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Contests by Rewards FuelCWE-352 5.4 Medium2024-03-20
CVE-2024-2387 Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 - SQL Injection to Reflected Cross-Site Scripting via integration_id — AFI – The Easiest Integration PluginCWE-89 6.1 Medium2024-03-20
CVE-2024-22080 Elspec G5 digital fault recorder 安全漏洞 — n/a 9.8AICriticalAI2024-03-20
CVE-2024-22081 Elspec G5 digital fault recorder 安全漏洞 — n/a 9.1AICriticalAI2024-03-20
CVE-2024-22082 Elspec G5 digital fault recorder 安全漏洞 — n/a 5.3AIMediumAI2024-03-20

Vulnerabilities classified as access:pre-auth represent 22495 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.