Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22649

22649 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2023-35137 Zyxel NAS326 授权问题漏洞 — NAS326 firmwareCWE-287 7.5 High2023-11-30
CVE-2023-46326 ZStack 安全漏洞 — n/a 9.1 -2023-11-30
CVE-2023-49693 NETGEAR ProSAFE Network Management System RCE via Unprotected Access to Java Debug Wire Protocol — NETGEAR ProSAFE Network Management SystemCWE-306 9.8 Critical2023-11-29
CVE-2023-4220 Chamilo LMS Unauthenticated Big Upload File Remote Code Execution — ChamiloCWE-434 8.1 High2023-11-28
CVE-2023-3545 Chamilo LMS Htaccess File Upload Security Bypass — ChamiloCWE-178 9.8 Critical2023-11-28
CVE-2023-3533 Chamilo LMS Unauthenticated Remote Code Execution via Arbitrary File Write — ChamiloCWE-22 9.8 Critical2023-11-28
CVE-2023-3368 Chamilo LMS Unauthenticated Command Injection — ChamiloCWE-78 9.8 Critical2023-11-28
CVE-2023-4398 Zyxel ATP 输入验证错误漏洞 — ATP series firmwareCWE-190 7.5 High2023-11-28
CVE-2023-35139 Zyxel ATP 跨站脚本漏洞 — ATP series firmwareCWE-79 5.2 Medium2023-11-28
CVE-2023-42000 Arcserve UDP Agent Unauthenticated Path Traversal File Upload — Arcserve UDPCWE-22 9.8 Critical2023-11-27
CVE-2023-41999 Arcserve UDP Management Authentication Bypass — Arcserve UDPCWE-287 9.8 Critical2023-11-27
CVE-2023-6329 Control iD iDSecure passwordCustom Authentication Bypass — iDSecureCWE-287 9.8 Critical2023-11-27
CVE-2023-5559 10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion — 10Web Booster 8.2 -2023-11-27
CVE-2023-5611 Seraphinite Accelerator < 2.20.32 - Unauthorised Settings Reset/Import — Seraphinite Accelerator 5.3 -2023-11-27
CVE-2023-5958 POST SMTP Mailer < 2.7.1 - Unauthenticated Cross-site Scripting — POST SMTP Mailer 6.1 -2023-11-27
CVE-2023-5845 Simple Social Buttons < 5.1.1 - Unauthenticated Password Protected Post Access — Simple Social Media Share Buttons 5.3 -2023-11-27
CVE-2023-5604 Asgaros Forum < 2.7.1 - Unauthenticated Arbitrary File Upload — Asgaros Forum 9.8 -2023-11-27
CVE-2023-5653 WassUp Real Time Analytics <= 1.9.4.5 - Unauthenticated Stored XSS — WassUp Real Time Analytics 6.1 -2023-11-27
CVE-2023-5560 WP-UserOnline < 2.88.3 - Unauthenticated Stored XSS — WP-UserOnline 6.1 -2023-11-27
CVE-2023-44303 Robware RVTools 安全漏洞 — RVTools CWE-310 7.5 High2023-11-24
CVE-2023-6264 Devolutions Server 安全漏洞 — Server 5.3AIMediumAI2023-11-22
CVE-2023-2497 UserPro <= 5.1.0 - Cross-Site Request Forgery to PHP Object Injection — UserPro - Community and User Profile WordPress PluginCWE-352 8.8 High2023-11-22
CVE-2023-6008 UserPro <= 5.1.1 - Cross-Site Request Forgery via multiple functions — UserPro - Community and User Profile WordPress PluginCWE-352 6.3 Medium2023-11-22
CVE-2023-5383 Funnelforms Free <= 3.4 - Cross-Site Request Forgery to Arbitrary Post Duplication — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms FreeCWE-352 4.3 Medium2023-11-22
CVE-2023-2437 UserPro <= 5.1.1 - Authentication Bypass to Administrator — UserPro - Community and User Profile WordPress PluginCWE-288 9.8 Critical2023-11-22
CVE-2023-2438 UserPro <= 5.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via userpro_save_userdata — UserPro - Community and User Profile WordPress PluginCWE-352 6.1 Medium2023-11-22
CVE-2023-2448 UserPro <= 5.1.4 - Missing Authorization to Arbitrary Shortcode Execution via userpro_shortcode_template — UserPro - Community and User Profile WordPress PluginCWE-862 6.5 Medium2023-11-22
CVE-2023-2440 UserPro <= 5.1.1 - Cross-Site Request Forgery to Privilege Escalation — UserPro - Community and User Profile WordPress PluginCWE-352 8.8 High2023-11-22
CVE-2023-5382 Funnelforms Free <= 3.4 - Cross-Site Request Forgery to Arbitrary Post Deletion — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms FreeCWE-352 6.5 Medium2023-11-22
CVE-2023-6007 UserPro <= 5.1.1 - Missing Authorization via multiple functions — UserPro - Community and User Profile WordPress PluginCWE-862 7.3 High2023-11-22

Vulnerabilities classified as access:pre-auth represent 22649 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.