Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22880

22880 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2021-36381 Edifecs Transaction Management 注入漏洞 — n/a 5.3 -2021-07-12
CVE-2021-21588 Dell EMC PowerFlex数据伪造问题漏洞 — PowerFlexCWE-345 6.5 Medium2021-07-12
CVE-2021-26088 Fortinet FSSO Collector Agent 授权问题漏洞 — Fortinet FSSO Windows DC Agent, FSSO Windows CA 7.1 High2021-07-12
CVE-2021-26090 Fortinet FortiMail 安全漏洞 — Fortinet FortiMail 5.3 Medium2021-07-12
CVE-2021-29104 There is a stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below. — ArcGIS ServerCWE-79 6.1 -2021-07-11
CVE-2021-29102 There is a Server-Side Request Forgery (SSRF) vulnerability in Esri ArcGIS Server Manager version 10.8.1 and below. — ArcGIS ServerCWE-918 7.5 -2021-07-11
CVE-2021-29107 There is a stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below. — ArcGIS ServerCWE-79 6.1 -2021-07-10
CVE-2021-26100 Fortinet FortiMail 数据伪造问题漏洞 — Fortinet FortiMail 5.9 Medium2021-07-09
CVE-2021-24020 Fortinet FortiMail 数据伪造问题漏洞 — Fortinet FortiMail 7.5 High2021-07-09
CVE-2021-33012 Allen Bradley Micrologix 1100 输入验证错误漏洞 — Rockwell Automation MicroLogix 1100CWE-20 8.6 -2021-07-09
CVE-2021-30118 Unauthenticated Remote Code Execution in Kaseya VSA < v9.5.5 — n/a 9.8 Critical2021-07-09
CVE-2021-30116 Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6 — n/a 10.0 Critical2021-07-09
CVE-2021-1598 Cisco Video Surveillance 7000 Series IP Cameras Link Layer Discovery Protocol Memory Leak Vulnerabilities — Cisco Video Surveillance 7000 Series IP CamerasCWE-401 6.5 Medium2021-07-08
CVE-2021-1597 Cisco Video Surveillance 7000 Series IP Cameras Link Layer Discovery Protocol Memory Leak Vulnerabilities — Cisco Video Surveillance 7000 Series IP CamerasCWE-401 6.5 Medium2021-07-08
CVE-2021-1596 Cisco Video Surveillance 7000 Series IP Cameras Link Layer Discovery Protocol Memory Leak Vulnerabilities — Cisco Video Surveillance 7000 Series IP CamerasCWE-401 6.5 Medium2021-07-08
CVE-2021-1595 Cisco Video Surveillance 7000 Series IP Cameras Link Layer Discovery Protocol Memory Leak Vulnerabilities — Cisco Video Surveillance 7000 Series IP CamerasCWE-401 6.5 Medium2021-07-08
CVE-2021-1585 Cisco Adaptive Security Device Manager Remote Code Execution Vulnerability — Cisco Adaptive Security Appliance (ASA) SoftwareCWE-94 7.5 High2021-07-08
CVE-2021-1575 Cisco Virtualized Voice Browser Cross-Site Scripting Vulnerability — Cisco Virtualized Voice BrowserCWE-79 6.1 Medium2021-07-08
CVE-2021-33221 CommScope Ruckus IoT Controller 访问控制错误漏洞 — n/a 9.8 -2021-07-07
CVE-2021-32535 QSAN SANOS - Use of Hard-coded Credentials — SANOSCWE-798 9.8 Critical2021-07-07
CVE-2021-32530 QSAN XEVO - Command Injection Following via Array function — XEVOCWE-78 9.8 Critical2021-07-07
CVE-2021-32529 QSAN XEVO, SANOS - Command Injection -1 — XEVOCWE-77 9.8 Critical2021-07-07
CVE-2021-32527 QSAN Storage Manager - Path Traversal-2 — Storage ManagerCWE-22 7.5 High2021-07-07
CVE-2021-32513 QSAN Storage Manager - Command Injection Following via QsanTorture function — Storage ManagerCWE-78 9.8 Critical2021-07-07
CVE-2021-32512 QSAN Storage Manager - Command Injection Following via QuickInstall function — Storage ManagerCWE-78 9.8 Critical2021-07-07
CVE-2021-31925 Pexip Infinity 输入验证错误漏洞 — n/a 7.5 -2021-07-07
CVE-2020-25868 Pexip Infinity 输入验证错误漏洞 — n/a 7.5 -2021-07-07
CVE-2021-35451 Teradici PCoIP Management Console 跨站脚本漏洞 — n/a 4.3 -2021-07-07
CVE-2021-20739 ELECOM 多款产品操作系统命令注入漏洞 — WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, and WRH-300WH-S 8.8 -2021-07-07
CVE-2021-20738 ELECOM 多款产品安全漏洞 — WRC-1167FS-W, WRC-1167FS-B, and WRC-1167FSA 4.3 -2021-07-07

Vulnerabilities classified as access:pre-auth represent 22880 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.