Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 23256

23256 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2023-34388 Improper authentication could lead to session hijacking — SEL-451CWE-287 6.5 Medium2023-11-30
CVE-2023-31176 Insufficient entropy vulnerability could lead to authentication bypass — SEL-451CWE-331 7.5 High2023-11-30
CVE-2023-6360 WordPress Plugin My Calendar 安全漏洞 CWE-89 8.6 High2023-11-30
CVE-2023-5772 Debug Log Manager <= 2.2.0 - Cross-Site Request Forgery — Debug Log Manager – Conveniently Monitor and Inspect ErrorsCWE-352 4.3 Medium2023-11-30
CVE-2023-4474 Zyxel NAS326 操作系统命令注入漏洞 — NAS326 firmwareCWE-78 9.8 Critical2023-11-30
CVE-2023-4473 Zyxel NAS326 操作系统命令注入漏洞 — NAS326 firmwareCWE-78 9.8 Critical2023-11-30
CVE-2023-35138 Zyxel NAS326 安全漏洞 — NAS326 firmwareCWE-78 9.8 Critical2023-11-30
CVE-2023-35137 Zyxel NAS326 授权问题漏洞 — NAS326 firmwareCWE-287 7.5 High2023-11-30
CVE-2023-46326 ZStack 安全漏洞 — n/a 9.1 -2023-11-30
CVE-2023-49693 NETGEAR ProSAFE Network Management System RCE via Unprotected Access to Java Debug Wire Protocol — NETGEAR ProSAFE Network Management SystemCWE-306 9.8 Critical2023-11-29
CVE-2023-4220 Chamilo LMS Unauthenticated Big Upload File Remote Code Execution — ChamiloCWE-434 8.1 High2023-11-28
CVE-2023-3545 Chamilo LMS Htaccess File Upload Security Bypass — ChamiloCWE-178 9.8 Critical2023-11-28
CVE-2023-3533 Chamilo LMS Unauthenticated Remote Code Execution via Arbitrary File Write — ChamiloCWE-22 9.8 Critical2023-11-28
CVE-2023-3368 Chamilo LMS Unauthenticated Command Injection — ChamiloCWE-78 9.8 Critical2023-11-28
CVE-2023-4398 Zyxel ATP 输入验证错误漏洞 — ATP series firmwareCWE-190 7.5 High2023-11-28
CVE-2023-35139 Zyxel ATP 跨站脚本漏洞 — ATP series firmwareCWE-79 5.2 Medium2023-11-28
CVE-2023-42000 Arcserve UDP Agent Unauthenticated Path Traversal File Upload — Arcserve UDPCWE-22 9.8 Critical2023-11-27
CVE-2023-41999 Arcserve UDP Management Authentication Bypass — Arcserve UDPCWE-287 9.8 Critical2023-11-27
CVE-2023-6329 Control iD iDSecure passwordCustom Authentication Bypass — iDSecureCWE-287 9.8 Critical2023-11-27
CVE-2023-5559 10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion — 10Web Booster 8.2 -2023-11-27
CVE-2023-5611 Seraphinite Accelerator < 2.20.32 - Unauthorised Settings Reset/Import — Seraphinite Accelerator 5.3 -2023-11-27
CVE-2023-5958 POST SMTP Mailer < 2.7.1 - Unauthenticated Cross-site Scripting — POST SMTP Mailer 6.1 -2023-11-27
CVE-2023-5845 Simple Social Buttons < 5.1.1 - Unauthenticated Password Protected Post Access — Simple Social Media Share Buttons 5.3 -2023-11-27
CVE-2023-5604 Asgaros Forum < 2.7.1 - Unauthenticated Arbitrary File Upload — Asgaros Forum 9.8 -2023-11-27
CVE-2023-5653 WassUp Real Time Analytics <= 1.9.4.5 - Unauthenticated Stored XSS — WassUp Real Time Analytics 6.1 -2023-11-27
CVE-2023-5560 WP-UserOnline < 2.88.3 - Unauthenticated Stored XSS — WP-UserOnline 6.1 -2023-11-27
CVE-2023-44303 Robware RVTools 安全漏洞 — RVTools CWE-310 7.5 High2023-11-24
CVE-2023-6264 Devolutions Server 安全漏洞 — Server 5.3AIMediumAI2023-11-22
CVE-2023-2497 UserPro <= 5.1.0 - Cross-Site Request Forgery to PHP Object Injection — UserPro - Community and User Profile WordPress PluginCWE-352 8.8 High2023-11-22
CVE-2023-6008 UserPro <= 5.1.1 - Cross-Site Request Forgery via multiple functions — UserPro - Community and User Profile WordPress PluginCWE-352 6.3 Medium2023-11-22

Vulnerabilities classified as access:pre-auth represent 23256 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.