Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22564

22564 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2023-48383 NetVision Information airPASS - Path Traversal — airPASSCWE-22 7.5 High2024-01-15
CVE-2024-0251 Advanced Woo Search <= 2.96 - Reflected Cross-Site Scripting — Advanced Woo Search – Product Search for WooCommerceCWE-79 6.1 Medium2024-01-13
CVE-2023-51062 QStar Archive Solutions 安全漏洞 — n/a 7.5 -2024-01-13
CVE-2023-51065 QStar Archive Solutions 安全漏洞 — n/a 7.5 -2024-01-13
CVE-2023-51067 QStar Archive Solutions 安全漏洞 — n/a 6.1 -2024-01-13
CVE-2023-51070 QStar Archive Solutions 安全漏洞 — n/a 8.2 -2024-01-13
CVE-2023-51071 QStar Archive Solutions 安全漏洞 — n/a 6.5 -2024-01-13
CVE-2023-52288 Flaskcode 安全漏洞 — n/a 7.5 -2024-01-13
CVE-2023-52289 Flaskcode 安全漏洞 — n/a 7.5 -2024-01-13
CVE-2023-31024 CVE — DGX A100CWE-121 9.0 Critical2024-01-12
CVE-2023-31030 CVE — DGX A100CWE-121 9.3 Critical2024-01-12
CVE-2023-31029 CVE — DGX A100CWE-121 9.3 Critical2024-01-12
CVE-2023-49255 Router console accessible without authentication — H8951-4G-ESPCWE-306 9.8 -2024-01-12
CVE-2023-34061 CVE-2023-34061 – Gorouter route pruning — Routing Release 7.5 High2024-01-12
CVE-2024-21617 Junos OS: BGP flap on NSR-enabled devices causes memory leak — Junos OSCWE-459 6.5 Medium2024-01-12
CVE-2024-21616 Junos OS: MX Series and SRX Series: Processing of a specific SIP packet causes NAT IP allocation to fail — Junos OSCWE-1286 7.5 High2024-01-12
CVE-2024-21614 Junos OS and Junos OS Evolved: A specific query via DREND causes rpd crash — Junos OSCWE-754 7.5 High2024-01-12
CVE-2024-21613 Junos OS and Junos OS Evolved: A link flap causes patroot memory leak which leads to rpd crash — Junos OSCWE-401 6.5 Medium2024-01-12
CVE-2024-21612 Junos OS Evolved: Specific TCP traffic causes OFP core and restart of RE — Junos OS EvolvedCWE-228 7.5 High2024-01-12
CVE-2024-21611 Junos OS and Junos OS Evolved: In a jflow scenario continuous route churn will cause a memory leak and eventually an rpd crash — Junos OSCWE-401 7.5 High2024-01-12
CVE-2024-21607 Junos OS: MX Series and EX9200 Series: If the "tcp-reset" option used in an IPv6 filter, matched packets are accepted instead of rejected — Junos OSCWE-447 5.3 Medium2024-01-12
CVE-2024-21606 Junos OS: SRX Series: When "tcp-encap" is configured and specific packets are received flowd will crash — Junos OSCWE-415 7.5 High2024-01-12
CVE-2024-21604 Junos OS Evolved: A high rate of specific traffic will cause a complete system outage — Junos OS EvolvedCWE-770 7.5 High2024-01-12
CVE-2024-21602 Junos OS Evolved: ACX7024, ACX7100-32C and ACX7100-48L: Traffic stops when a specific IPv4 UDP packet is received by the RE — Junos OS EvolvedCWE-476 7.5 High2024-01-12
CVE-2024-21601 Junos OS: SRX Series: Due to an error in processing TCP events flowd will crash — Junos OSCWE-362 5.9 Medium2024-01-12
CVE-2024-21600 Junos OS: PTX Series: In an FTI scenario MPLS packets hitting reject next-hop will cause a host path wedge condition — Junos OSCWE-76 6.5 Medium2024-01-12
CVE-2024-21599 Junos OS: MX Series: MPC3E memory leak with PTP configuration — Junos OSCWE-401 6.5 Medium2024-01-12
CVE-2024-21597 Junos OS: MX Series: In an AF scenario traffic can bypass configured lo0 firewall filters — Junos OSCWE-668 5.3 Medium2024-01-12
CVE-2024-21596 Junos OS and Junos OS Evolved: A specific BGP UPDATE message will cause a crash in the backup Routing Engine in NSR-enabled devices — Junos OSCWE-122 5.3 Medium2024-01-12
CVE-2024-21595 Junos OS: EX4100, EX4400, EX4600, QFX5000 Series: A high rate of specific ICMP traffic will cause the PFE to hang — Junos OSCWE-1286 7.5 High2024-01-12

Vulnerabilities classified as access:pre-auth represent 22564 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.