Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22551

22551 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2023-6737 Enable Media Replace <= 4.1.4 - Reflected Cross-Site Scripting — Enable Media ReplaceCWE-79 4.7 Medium2024-01-11
CVE-2023-7048 My Sticky Bar <= 2.6.6 - Cross-Site Request Forgery to Sensitive Information Exposure — My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu)CWE-352 3.1 Low2024-01-11
CVE-2023-6316 MW WP Form <= 5.0.1 - Unauthenticated Arbitrary File Upload — MW WP FormCWE-434 9.8 Critical2024-01-11
CVE-2023-6220 Piotnet Forms <= 1.0.28 - Unauthenticated Arbitrary File Upload — Piotnet FormsCWE-434 8.1 High2024-01-11
CVE-2023-6828 ARForms <= 1.5.8 - Unauthenticated Stored Cross-Site Scripting via arf_http_referrer_url — Contact Form, Survey, Quiz & Popup Form Builder – ARFormsCWE-79 7.2 High2024-01-11
CVE-2023-6567 LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-89 9.8 Critical2024-01-11
CVE-2023-6637 CAOS | Host Google Analytics Locally <= 4.7.14 - Missing Authorization to Unauthenticated Plugin Settings Update — CAOS | Host Google Analytics LocallyCWE-862 6.5 Medium2024-01-11
CVE-2023-6855 Paid Memberships Pro <= 2.12.5 - Missing Authorization via API — Paid Memberships Pro – Content Restriction, User Registration, & Paid SubscriptionsCWE-862 5.3 Medium2024-01-11
CVE-2023-6882 Simple Membership <= 4.3.8 - Reflected Cross-Site Scripting Vulnerability via environment_mode — Simple MembershipCWE-79 6.1 Medium2024-01-11
CVE-2023-4248 GiveWP <= 2.33.3 - Cross-Site Request Forgery to Stripe Integration Deletion — GiveWP – Donation Plugin and Fundraising PlatformCWE-352 5.4 Medium2024-01-11
CVE-2023-6634 LearnPress <= 4.2.5.7 - Command Injection — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-88 8.1 High2024-01-11
CVE-2023-6266 Backup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive Information Exposure — BackupBliss – Backup & Migration with Free Cloud StorageCWE-200 7.5 High2024-01-11
CVE-2023-6496 Manage Notification E-mails <= 1.8.5 - Missing Authorization — Manage Notification E-mailsCWE-285 5.3 Medium2024-01-11
CVE-2023-6632 Happy Addons for Elementor <= 3.9.1.1 - Reflected Cross-Site Scripting — Happy Addons for Elementor ProCWE-79 6.1 Medium2024-01-11
CVE-2023-6699 WP Compress – Image Optimizer [All-In-One] <= 6.10.33 - Unauthenticated Directory Traversal via css — WP Compress – Instant Performance & Speed OptimizationCWE-24 9.1 Critical2024-01-11
CVE-2023-6520 WP 2FA – Two-factor authentication for WordPress <= 2.5.0 - Cross-Site Request Forgery — WP 2FA – Two-factor authentication for WordPressCWE-352 4.3 Medium2024-01-11
CVE-2023-5448 WP Register Profile With Shortcode <= 3.5.9 - Cross-Site Request Forgery to User Password Reset — WP Register Profile With ShortcodeCWE-352 8.8 High2024-01-11
CVE-2024-21833 TP-LINK 多款产品安全漏洞 — Archer AX3000 8.8AIHighAI2024-01-10
CVE-2024-21773 TP-LINK 多款产品安全漏洞 — Archer AX3000 8.8AIHighAI2024-01-10
CVE-2023-40393 Apple macOS Sonoma 安全漏洞 — iOS and iPadOS 6.2AIMediumAI2024-01-10
CVE-2023-6158 EventON - WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Missing Authorization to Arbitrary Post Meta Update via evo_eventpost_update_meta — EventON – Events CalendarCWE-862 6.5 Medium2024-01-10
CVE-2023-48266 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-121 8.1 High2024-01-10
CVE-2023-48265 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-121 8.1 High2024-01-10
CVE-2023-48264 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-121 8.1 High2024-01-10
CVE-2023-48263 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-122 8.1 High2024-01-10
CVE-2023-48262 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-121 8.1 High2024-01-10
CVE-2023-48261 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-89 5.3 Medium2024-01-10
CVE-2023-48260 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-89 5.3 Medium2024-01-10
CVE-2023-48259 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-89 5.3 Medium2024-01-10
CVE-2023-48257 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-1391 7.8 High2024-01-10

Vulnerabilities classified as access:pre-auth represent 22551 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.