Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22530

22530 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-20254 Cisco Expressway Series 跨站请求伪造漏洞 — Cisco TelePresence Video Communication Server (VCS) ExpresswayCWE-352 9.6 Critical2024-02-07
CVE-2024-20252 Cisco Expressway Series 跨站请求伪造漏洞 — Cisco TelePresence Video Communication Server (VCS) ExpresswayCWE-352 9.6 Critical2024-02-07
CVE-2024-24811 Products.SQLAlchemyDA vulnerable to unauthenticated arbitrary SQL query execution — Products.SQLAlchemyDACWE-89 9.8 Critical2024-02-07
CVE-2024-1109 Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Unauthenticated Data Export — Podlove Podcast PublisherCWE-862 5.3 Medium2024-02-07
CVE-2024-1110 Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Settings Import — Podlove Podcast PublisherCWE-862 5.3 Medium2024-02-07
CVE-2024-1079 Quiz Maker <= 6.5.2.4 - Missing Authorization to Unauthenticated Quiz Data Retrieval — Quiz MakerCWE-862 5.3 Medium2024-02-07
CVE-2024-1037 All-In-One Security (AIOS) – Security and Firewall <= 5.2.5 - Reflected Cross-Site Scripting — All-In-One Security (AIOS) – Security and FirewallCWE-79 6.1 Medium2024-02-07
CVE-2024-23304 Cybozu KUNAI 安全漏洞 — Cybozu KUNAI for Android 7.5 -2024-02-06
CVE-2023-46359 eCharge Hardy Barth eCharge Ladestation 安全漏洞 — n/a 9.8 -2024-02-06
CVE-2023-6557 The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure — The Events CalendarCWE-862 5.3 Medium2024-02-05
CVE-2024-0701 UserPro <= 5.1.6 - Disabled Membership Registration Bypass — UserPro - Community and User Profile WordPress PluginCWE-602 5.3 Medium2024-02-05
CVE-2024-0969 ARMember <= 4.0.24 - Improper Access Control to Sensitive Information Exposure via REST API — ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signupCWE-284 5.3 Medium2024-02-05
CVE-2024-0373 Views for WPForms <= 3.2.2 - Cross-Site Request Forgery via save_view — Views for WPForms – Display & Edit WPForms Entries on your site frontendCWE-284 4.3 Medium2024-02-05
CVE-2023-6963 Getwid – Gutenberg Blocks <= 2.0.4 - Captcha Bypass — Getwid – Gutenberg BlocksCWE-804 5.3 Medium2024-02-05
CVE-2024-0428 Index Now <= 2.6.3 - Cross-Site Request Forgery via reset_form — CrawlWP SEO – Instant Search Engine Indexing & SEO Performance MonitorCWE-352 7.1 High2024-02-05
CVE-2023-4637 WPvivid <= 0.9.94 - Missing Authorization — WPvivid — Backup, Migration & StagingCWE-862 4.3 Medium2024-02-05
CVE-2024-0660 Formidable Forms <= 6.7.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form BuilderCWE-352 6.1 Medium2024-02-05
CVE-2024-0709 WordPress plugin Cryptocurrency Widgets 安全漏洞 — Cryptocurrency Widgets – Price Ticker & Coins List 9.8 Critical2024-02-05
CVE-2024-1208 LearnDash LMS <= 4.10.2 - Sensitive Information Exposure via API — LearnDash LMSCWE-200 5.3 Medium2024-02-05
CVE-2023-6933 Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection — Better Search ReplaceCWE-502 8.8 High2024-02-05
CVE-2024-1121 Advanced Forms for ACF <= 1.9.3.2 - Missing Authorization to Unauthenticated Form Settings Export — Advanced Forms for ACFCWE-862 5.3 Medium2024-02-05
CVE-2024-1072 Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.15.21 - Missing Authorization via seedprod_lite_new_lpage — Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance ModeCWE-862 8.2 High2024-02-05
CVE-2024-1075 Minimal Coming Soon – Coming Soon Page <= 2.37 - Unauthenticated Maintenance Mode Bypass — Minimal Coming Soon – Coming Soon PageCWE-639 3.7 Low2024-02-05
CVE-2024-0678 Order Delivery Date for WP e-Commerce <= 1.2 - Unauthenticated Stored Cross-Site Scripting — Order Delivery Date for WP e-CommerceCWE-79 6.5 Medium2024-02-05
CVE-2024-1209 LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignments — LearnDash LMSCWE-200 5.3 Medium2024-02-05
CVE-2024-0509 WP 404 Auto Redirect to Similar Post <= 1.0.3 - Reflected Cross-Site Scripting via request — WP 404 Auto Redirect to Similar PostCWE-79 6.1 Medium2024-02-05
CVE-2024-0790 WOLF – WordPress Posts Bulk Editor and Manager Professional <= 1.0.8.1 - Cross-Site Request Forgery — WOLF – WordPress Posts Bulk Editor and Manager ProfessionalCWE-352 5.4 Medium2024-02-05
CVE-2024-1177 WP Club Manager – WordPress Sports Club Plugin <= 2.2.10 - Missing Authorization to Unauthenticated Event Permalink Update — WP Club Manager – WordPress Sports Club PluginCWE-862 5.3 Medium2024-02-05
CVE-2024-1210 LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via API — LearnDash LMSCWE-200 5.3 Medium2024-02-05
CVE-2023-7014 Author Box, Guest Author and Co-Authors for Your Posts – Molongui <= 4.7.4 - Information Exposure via ma_debug — Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPressCWE-359 5.3 Medium2024-02-05

Vulnerabilities classified as access:pre-auth represent 22530 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.