Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22564

22564 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-21833 TP-LINK 多款产品安全漏洞 — Archer AX3000 8.8AIHighAI2024-01-10
CVE-2024-21773 TP-LINK 多款产品安全漏洞 — Archer AX3000 8.8AIHighAI2024-01-10
CVE-2023-40393 Apple macOS Sonoma 安全漏洞 — iOS and iPadOS 6.2AIMediumAI2024-01-10
CVE-2023-6158 EventON - WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Missing Authorization to Arbitrary Post Meta Update via evo_eventpost_update_meta — EventON – Events CalendarCWE-862 6.5 Medium2024-01-10
CVE-2023-48266 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-121 8.1 High2024-01-10
CVE-2023-48265 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-121 8.1 High2024-01-10
CVE-2023-48264 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-121 8.1 High2024-01-10
CVE-2023-48263 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-122 8.1 High2024-01-10
CVE-2023-48262 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-121 8.1 High2024-01-10
CVE-2023-48261 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-89 5.3 Medium2024-01-10
CVE-2023-48260 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-89 5.3 Medium2024-01-10
CVE-2023-48259 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-89 5.3 Medium2024-01-10
CVE-2023-48257 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-1391 7.8 High2024-01-10
CVE-2023-48255 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-79 6.3 Medium2024-01-10
CVE-2023-48247 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-862 5.3 Medium2024-01-10
CVE-2023-48245 Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001)CWE-862 6.5 Medium2024-01-10
CVE-2023-51127 Teledyne FLIR AX8 安全漏洞 — n/a 7.5AIHighAI2024-01-10
CVE-2020-26629 Hospital Management System 安全漏洞 — n/a 9.8AICriticalAI2024-01-10
CVE-2023-5770 HTML injection in email body through email subject — Proofpoint Enterprise ProtectionCWE-838 5.3 Medium2024-01-09
CVE-2023-49252 Siemens SIMATIC CN 4100 输入验证错误漏洞 — SIMATIC CN 4100CWE-20 7.5 High2024-01-09
CVE-2023-6830 Formidable Forms <= 6.7 - HTML Injection — Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form BuilderCWE-79 6.5 Medium2024-01-09
CVE-2023-6788 Metform Elementor Contact Form Builder <= 3.8.1 - Cross-Site Request Forgery — MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for ElementorCWE-352 5.4 Medium2024-01-09
CVE-2023-6042 Getwid < 2.0.3 - Unauthenticated Arbitrary Email Sending to Admin — Getwid 9.8AICriticalAI2024-01-08
CVE-2023-6529 WP VR < 8.3.15 - Unauthenticated Plugin Downgrade leading to XSS — WP VR 6.1AIMediumAI2024-01-08
CVE-2024-21644 pyLoad unauthenticated flask configuration leakage — pyloadCWE-284 7.5 High2024-01-08
CVE-2024-21645 pyLoad Log Injection — pyloadCWE-74 5.3 Medium2024-01-08
CVE-2023-6493 Depicter Slider – Responsive Image Slider, Video Slider & Post Slider <= 2.0.6 - Cross-Site Request Forgery via save — Depicter — Popup & Slider BuilderCWE-352 4.3 Medium2024-01-05
CVE-2024-0241 encoded_id-rails Denial of Service Vulnerability CWE-400 7.5AIHighAI2024-01-04
CVE-2024-22051 CommonMarker Integer Overflow Vulnerability CWE-190 9.8AICriticalAI2024-01-04
CVE-2024-22050 Iodine Static File Server Path Traversal Vulnerability CWE-22 7.5AIHighAI2024-01-04

Vulnerabilities classified as access:pre-auth represent 22564 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.