Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22551

22551 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-1064 Improper Neutralization of HTTP Headers for Scripting Syntax in Crafty Controller 4 — Crafty ControllerCWE-644 7.5 High2024-02-03
CVE-2024-0909 Anonymous Restricted Content <= 1.6.2 - Protection Mechanism Bypass — Anonymous Restricted ContentCWE-200 5.3 Medium2024-02-03
CVE-2022-34381 Dell BSAFE 安全漏洞 — Dell BSAFE Crypto-JCWE-1329 9.1 Critical2024-02-02
CVE-2024-1047 ThemeIsle SDK <= Various Versions - Missing Authorization — Menu Icons by ThemeIsleCWE-862 5.3 Medium2024-02-02
CVE-2024-1162 Orbit Fox by ThemeIsle <= 2.10.29 - Cross-Site Request Forgery — Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & MoreCWE-352 4.3 Medium2024-02-02
CVE-2024-0685 Ninja Forms Contact Form <= 3.7.1 - Unauthenticated Second Order SQL Injection — Ninja Forms – The Contact Form Builder That Grows With YouCWE-89 5.9 Medium2024-02-02
CVE-2024-22108 GTB Central Console 安全漏洞 — n/a 9.8 -2024-02-02
CVE-2023-49115 MachineSense FeverWarn Missing Authentication for Critical Function — FeverWarnCWE-306 7.5 High2024-02-01
CVE-2023-49617 MachineSense FeverWarn Missing Authentication for Critical Function — FeverWarnCWE-306 10.0 Critical2024-02-01
CVE-2023-4472 Cryptographically weak PRNG in Opinio 7.22 — OpinioCWE-335 9.8 -2024-02-01
CVE-2024-22433 Dell Data Protection Search 安全漏洞 — Data Protection SearchCWE-538 8.8 High2024-02-01
CVE-2024-24548 Payment EX 安全漏洞 — Payment EX 5.3 -2024-02-01
CVE-2024-21893 Ivanti Connect Secure 代码问题漏洞 — ICS 9.8 -2024-01-31
CVE-2023-50166 Pegasystem PEGA Platform 安全漏洞 — Pega PlatformCWE-79 6.1 Medium2024-01-31
CVE-2023-50356 Improper Certificate Validation in AREAL Topkapi Vision (Server) — Topkapi Vision (Server)CWE-295 6.5 Medium2024-01-31
CVE-2023-6943 Mitsubishi Electric 多款产品安全漏洞 — EZSocketCWE-470 9.8 Critical2024-01-30
CVE-2023-6942 Mitsubishi Electric 多款产品安全漏洞 — EZSocketCWE-306 7.5 High2024-01-30
CVE-2023-6374 Mitsubishi Electric MELSEC WS Series 安全漏洞 — MELSEC WS Series WS0-GETH00200CWE-294 5.9 Medium2024-01-30
CVE-2024-1061 WordPress Plugin HTML5 Video Player SQL注入漏洞 CWE-89 8.6 High2024-01-30
CVE-2023-4553 Unauthenticated Access to AppBuilder Configuration Files — AppBuilderCWE-20 5.3 Medium2024-01-29
CVE-2023-4550 Unauthenticated Arbitrary File Read — AppBuilderCWE-20 7.5 High2024-01-29
CVE-2023-7199 Relevanssi (Free < 4.22.0, Premium < 2.25.0) - Unauthenticated Private/Draft Post Disclosure — Relevanssi 7.5 -2024-01-29
CVE-2023-6389 WordPress Toolbar <= 2.2.6 - Open Redirect — WordPress Toolbar 6.1 -2024-01-29
CVE-2023-6200 Kernel: icmpv6 router advertisement packets, aka linux tcp/ip remote code execution vulnerability — kernelCWE-362 7.5 High2024-01-28
CVE-2024-0667 Form-Maker (twb_form-maker) <= 1.15.21 - Cross-Site Request Forgery to Limited Code Execution via Execute — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form BuilderCWE-1078 5.4 Medium2024-01-27
CVE-2024-20253 Cisco Unified Communications Products 安全漏洞 — Cisco Unified Contact Center EnterpriseCWE-502 9.9 Critical2024-01-26
CVE-2024-20263 Cisco Small Business 安全漏洞 — Cisco Small Business Smart and Managed SwitchesCWE-284 5.8 Medium2024-01-26
CVE-2024-22545 TRENDnet TEW-824DRU 安全漏洞 — n/a 9.8 -2024-01-26
CVE-2024-23625 D-Link DAP-1650 SUBSCRIBE Callback Command Injection Vulnerability — DAP-1650CWE-77 9.6 Critical2024-01-25
CVE-2024-23624 D-Link DAP-1650 gena.cgi SUBSCRIBE Command Injection Vulnerability — DAP-1650CWE-77 9.6 Critical2024-01-25

Vulnerabilities classified as access:pre-auth represent 22551 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.