Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22518

22518 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-1071 WordPress Plugin Ultimate Member 安全漏洞 — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 9.8 Critical2024-03-13
CVE-2024-2123 Ultimate Member <= 2.8.3 - Unauthenticated Stored Cross-Site Scripting — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership PluginCWE-79 7.2 High2024-03-13
CVE-2018-25090 Wago: Improper Neutralization of Input During Web Page Generation in multiple devices — Controller BACnet/IPCWE-79 5.4 Medium2024-03-13
CVE-2015-10130 WordPress Plugin Team Circle Image Slider With Lightbox 安全漏洞 — Team Circle Image Slider With Lightbox 5.3 Medium2024-03-13
CVE-2024-1214 Easy Social Feed <= 6.5.4 - Cross-Site Request Forgery — Easy Social Feed – Social Photos Gallery and Post Feed for WordPressCWE-352 4.3 Medium2024-03-12
CVE-2024-1213 Easy Social Feed <= 6.5.4 - Cross-Site Request Forgery — Easy Social Feed – Social Photos Gallery and Post Feed for WordPressCWE-352 5.4 Medium2024-03-12
CVE-2024-1503 Tutor LMS – eLearning and online course solution <= 2.6.1 - Cross-Site Request Forgery to Plugin Deactivation and Data Erase — Tutor LMS – eLearning and online course solutionCWE-352 4.3 Medium2024-03-12
CVE-2023-7072 Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint — Post GridCWE-202 7.5 High2024-03-12
CVE-2024-0386 weForms <= 1.6.21 - Unauthenticated Stored Cross-Site Scripting via Referer — weForms – Easy Drag & Drop Contact Form Builder For WordPressCWE-79 7.2 High2024-03-12
CVE-2024-2107 Blossom Spa <= 1.3.3 - Sensitive Information Exposure — Blossom SpaCWE-862 5.8 Medium2024-03-12
CVE-2024-2395 Bulgarisation for WooCommerce <= 3.0.14 - Cross-Site Request Forgery — Bulgarisation for WooCommerceCWE-862 7.3 High2024-03-12
CVE-2022-34321 Apache Pulsar: Improper Authentication for Pulsar Proxy Statistics Endpoint — Apache PulsarCWE-306 8.2 High2024-03-12
CVE-2024-1410 Unbounded storage of information related to connection ID retirement, in quiche — quicheCWE-400 3.7 Low2024-03-12
CVE-2024-22041 Siemens 多款产品缓冲区错误漏洞 — Cerberus PRO EN Engineering ToolCWE-119 7.5 High2024-03-12
CVE-2024-22040 Siemens 多款产品缓冲区错误漏洞 — Cerberus PRO EN Engineering ToolCWE-125 7.5 High2024-03-12
CVE-2024-22039 Siemens 多款产品安全漏洞 — Cerberus PRO EN Engineering ToolCWE-120 10.0 Critical2024-03-12
CVE-2023-4629 LadiApp <= 4.4 - Cross-Site Request Forgery via save_config() — LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…CWE-352 4.3 Medium2024-03-12
CVE-2023-4729 LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 - Cross-Site Request Forgery via publish_lp() — LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…CWE-352 4.3 Medium2024-03-12
CVE-2023-4731 LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 - Cross-Site Request Forgery via init_endpoint — LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…CWE-352 4.3 Medium2024-03-12
CVE-2023-4628 LadiApp <= 4.4 - Cross-Site Request Forgery via ladiflow_save_hook() — LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…CWE-352 4.3 Medium2024-03-12
CVE-2024-0906 f(x) Private Site <= 1.2.1 - Sensitive Information Exposure — f(x) Private SiteCWE-200 5.3 Medium2024-03-12
CVE-2024-26288 PHOENIX CONTACT: Lack of SSL support in CHARX Series — CHARX SEC-3000CWE-319 8.7 High2024-03-12
CVE-2024-26005 PHOENIX CONTACT: Privilege gain through incomplete cleanup in CHARX Series — CHARX SEC-3000CWE-459 4.8 Medium2024-03-12
CVE-2024-26004 PHOENIX CONTACT: DoS of a control agent due to access of a uninitialized pointer in CHARX Series — CHARX SEC-3000CWE-824 7.5 High2024-03-12
CVE-2024-26003 PHOENIX CONTACT: DoS of the control agent in CHARX Series — CHARX SEC-3000CWE-125 7.5 High2024-03-12
CVE-2024-26001 PHOENIX CONTACT: Out of bounds write only memory access — CHARX SEC-3000CWE-787 7.4 High2024-03-12
CVE-2024-26000 PHOENIX CONTACT: Out of bounds read only memory access — CHARX SEC-3000CWE-125 5.9 Medium2024-03-12
CVE-2024-25999 PHOENIX CONTACT: Privilege escalation in the OCPP agent service — CHARX SEC-3000CWE-20 8.4 High2024-03-12
CVE-2024-25998 PHOENIX CONTACT: Command injection in the OCPP Service — CHARX SEC-3000CWE-77 7.3 High2024-03-12
CVE-2024-25997 PHOENIX CONTACT: Log injection in CHARX Series — CHARX SEC-3000CWE-20 5.3 Medium2024-03-12

Vulnerabilities classified as access:pre-auth represent 22518 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.