Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22564

22564 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-1504 SecuPress Free — WordPress Security <= 2.2.5.1 - Cross-Site Request Forgery to Banned IP Address — SecuPress with Simple SSL – Simple and Performant SecurityCWE-352 4.3 Medium2024-04-02
CVE-2024-25187 71cms 安全漏洞 — n/a 7.5AIHighAI2024-04-02
CVE-2023-41724 Ivanti Sentry 安全漏洞 — Sentry 8.8AIHighAI2024-03-31
CVE-2024-25944 Dell OpenManage Enterprise 安全漏洞 — Dell OpenManage Enterprise CWE-23 5.7 Medium2024-03-29
CVE-2024-2848 Responsive <= 5.0.2 - Missing Authorization to HTML Injection — ResponsiveCWE-862 7.5 High2024-03-29
CVE-2024-2409 MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action — MasterStudy LMS WordPress Plugin – for Online Courses and EducationCWE-266 9.8 Critical2024-03-29
CVE-2024-2411 MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal — MasterStudy LMS WordPress Plugin – for Online Courses and EducationCWE-98 9.8 Critical2024-03-29
CVE-2024-2964 Pocket News Generator <= 0.2.0 - Cross-Site Request Forgery to Settings Update — Pocket News GeneratorCWE-352 5.4 Medium2024-03-29
CVE-2024-0609 WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Unauthenticated Stored Cross-Site Scripting — ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM SupportCWE-79 7.2 High2024-03-29
CVE-2024-2116 Christmas Greetings <= 1.2.5 - Reflected Cross-Site Scripting — Christmas GreetingsCWE-79 6.1 Medium2024-03-29
CVE-2024-2113 Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.8.0 - Cross-Site Request Forgery to Publicly Accessible Form Submission Export — Ninja Forms – The Contact Form Builder That Grows With YouCWE-352 4.3 Medium2024-03-29
CVE-2024-2970 News Wall <= 1.1.0 - Cross-Site Request Forgery to Plugin Settings Update — News WallCWE-352 4.3 Medium2024-03-29
CVE-2024-2969 WP-Eggdrop <= 0.1 - Cross-Site Request Forgery to Settings Update — WP-EggdropCWE-352 5.4 Medium2024-03-29
CVE-2024-2844 Easy Appointments <= 3.11.18 - Insufficient Authorization — Easy AppointmentsCWE-862 4.3 Medium2024-03-29
CVE-2023-49231 Stilog Visual Planning 8 安全漏洞 — n/a 9.1AICriticalAI2024-03-29
CVE-2023-49232 Stilog Visual Planning 安全漏洞 — n/a 9.8AICriticalAI2024-03-29
CVE-2024-25954 Dell PowerScale OneFS 代码问题漏洞 — PowerScale OneFSCWE-613 5.3 Medium2024-03-28
CVE-2024-25963 Dell PowerScale OneFS 加密问题漏洞 — PowerScale OneFSCWE-327 5.9 Medium2024-03-28
CVE-2024-2110 Events Manager <= 6.4.7.1 - Cross-Site Request Forgery — Events Manager – Calendar, Bookings, Tickets, and more!CWE-352 4.3 Medium2024-03-28
CVE-2024-20307 多款Cisco产品安全漏洞 — IOSCWE-121 6.8 Medium2024-03-27
CVE-2024-20308 多款Cisco产品安全漏洞 — IOS 8.6 High2024-03-27
CVE-2024-20271 Cisco Access Point 安全漏洞 — Cisco Aironet Access Point SoftwareCWE-20 8.6 High2024-03-27
CVE-2024-20265 Cisco Access Point 安全漏洞 — Cisco IOS XE SoftwareCWE-501 5.9 Medium2024-03-27
CVE-2024-20303 Cisco IOS XE Software 安全漏洞 — Cisco IOS XE SoftwareCWE-459 7.4 High2024-03-27
CVE-2024-20314 Cisco IOS XE Software 安全漏洞 — Cisco IOS XE SoftwareCWE-783 8.6 High2024-03-27
CVE-2024-20312 Cisco IOS 和 IOS XE Software 安全漏洞 — IOSCWE-476 7.4 High2024-03-27
CVE-2024-20259 Cisco IOS XE Software 安全漏洞 — Cisco IOS XE SoftwareCWE-122 8.6 High2024-03-27
CVE-2024-20276 Cisco Catalyst 安全漏洞 — IOSCWE-248 7.4 High2024-03-27
CVE-2024-20311 Cisco IOS 和 IOS XE Software 安全漏洞 — IOSCWE-674 8.6 High2024-03-27
CVE-2024-20316 Cisco IOS XE Software 安全漏洞 — Cisco IOS XE SoftwareCWE-390 5.8 Medium2024-03-27

Vulnerabilities classified as access:pre-auth represent 22564 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.