Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22766

22766 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-25626 Yocto Project Security Advisory - BitBake/Toaster — pokyCWE-78 8.8 High2024-02-19
CVE-2024-0610 Piraeus Bank WooCommerce Payment Gateway <= 1.6.5.1 - Unauthenticated SQL Injection — Piraeus Bank WooCommerce Payment GatewayCWE-89 9.8 Critical2024-02-17
CVE-2024-1512 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection — MasterStudy LMS WordPress Plugin – for Online Courses and EducationCWE-89 9.8 Critical2024-02-17
CVE-2024-20986 Oracle Fusion Middleware 安全漏洞 — WebLogic Server 6.1 Medium2024-02-17
CVE-2024-20951 Oracle E-Business Suite 安全漏洞 — Customer Interaction History 6.1 Medium2024-02-17
CVE-2024-20956 Oracle Supply Chain Products Suite 安全漏洞 — Agile Product Lifecycle Management for Process 7.3 High2024-02-17
CVE-2024-20949 Oracle E-Business Suite 安全漏洞 — Customer Interaction History 6.1 Medium2024-02-17
CVE-2024-20941 Oracle E-Business Suite 安全漏洞 — Installed Base 6.1 Medium2024-02-17
CVE-2024-20935 Oracle E-Business Suite 安全漏洞 — Installed Base 6.1 Medium2024-02-17
CVE-2024-20931 Oracle Fusion Middleware 的 WebLogic Server 安全漏洞 — WebLogic Server 7.5 High2024-02-17
CVE-2024-20933 Oracle E-Business Suite 安全漏洞 — Installed Base 6.1 Medium2024-02-17
CVE-2024-20925 Oracle Java SE和Oracle GraalVM 安全漏洞 — Java SE JDK and JRE 3.1 Low2024-02-17
CVE-2024-20927 Oracle Fusion Middleware 安全漏洞 — WebLogic Server 8.6 High2024-02-17
CVE-2024-20929 Oracle E-Business Suite 安全漏洞 — Application Object Library 6.5 Medium2024-02-17
CVE-2024-20921 Oracle Java SE 安全漏洞 — Java SE JDK and JRE 5.9 Medium2024-02-17
CVE-2024-20923 Oracle部分产品安全漏洞 — Java SE JDK and JRE 3.1 Low2024-02-17
CVE-2024-20915 Oracle E-Business Suite 安全漏洞 — Application Object Library 5.3 Medium2024-02-17
CVE-2024-20917 Oracle Enterprise Manager Base Platform 安全漏洞 — Enterprise Manager Base Platform 7.5 High2024-02-17
CVE-2024-20919 Oracle Java SE 安全漏洞 — Java SE JDK and JRE 5.9 Medium2024-02-17
CVE-2024-20907 Oracle E-Business Suite 安全漏洞 — Web Applications Desktop Integrator 6.1 Medium2024-02-17
CVE-2024-20909 Oracle Audit Vault and Database Firewall 安全漏洞 — Audit Vault and Database Firewall 7.5 High2024-02-17
CVE-2024-22426 Dell RecoverPoint for Virtual Machines 代码问题漏洞 — RecoverPoint for VMsCWE-434 7.2 High2024-02-16
CVE-2024-22425 Dell RecoverPoint for Virtual Machines 安全漏洞 — RecoverPoint for VMsCWE-307 6.5 Medium2024-02-16
CVE-2024-23477 SolarWinds Access Rights Manager (ARM) Directory Traversal Remote Code Execution Vulnerability — Access Rights ManagerCWE-22 7.9 High2024-02-15
CVE-2024-23476 SolarWinds Access Rights Manager (ARM) Directory Traversal Remote Code Execution Vulnerability — Access Rights ManagerCWE-22 9.6 Critical2024-02-15
CVE-2024-23479 SolarWinds Access Rights Manager (ARM) Directory Traversal Remote Code Execution Vulnerability — Access Rights ManagerCWE-22 9.6 Critical2024-02-15
CVE-2023-47537 Fortinet FortiOS 信任管理问题漏洞 — FortiOSCWE-295 4.4 Medium2024-02-15
CVE-2023-39245 Dell ESI for SAP LaMa 安全漏洞 — ESI (Enterprise Storage Integrator) for SAP LAMACWE-319 9.8 Critical2024-02-15
CVE-2023-39244 Dell Enterprise Storage Integrator 访问控制错误漏洞 — ESI (Enterprise Storage Integrator) for SAP LAMACWE-284 7.3 High2024-02-15
CVE-2023-32484 Dell EMC Enterprise SONiC 输入验证错误漏洞 — Enterprise SONiC OSCWE-20 9.8 Critical2024-02-15

Vulnerabilities classified as access:pre-auth represent 22766 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.