Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 19065

19065 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2017-3425 Oracle E-Business Suite 安全漏洞 — One-to-One Fulfillment 8.2 -2017-01-27
CVE-2017-3426 Oracle E-Business Suite 安全漏洞 — One-to-One Fulfillment 8.2 -2017-01-27
CVE-2017-3427 Oracle E-Business Suite 安全漏洞 — One-to-One Fulfillment 8.2 -2017-01-27
CVE-2017-3428 Oracle E-Business Suite 安全漏洞 — One-to-One Fulfillment 8.2 -2017-01-27
CVE-2017-3429 Oracle E-Business Suite 安全漏洞 — One-to-One Fulfillment 8.2 -2017-01-27
CVE-2017-3430 Oracle E-Business Suite 安全漏洞 — One-to-One Fulfillment 8.2 -2017-01-27
CVE-2017-3431 Oracle E-Business Suite 安全漏洞 — One-to-One Fulfillment 8.2 -2017-01-27
CVE-2017-3433 Oracle E-Business Suite 安全漏洞 — One-to-One Fulfillment 8.2 -2017-01-27
CVE-2017-3435 Oracle E-Business Suite 安全漏洞 — One-to-One Fulfillment 8.2 -2017-01-27
CVE-2017-3436 Oracle E-Business Suite 访问控制错误漏洞 — One-to-One Fulfillment 8.2 -2017-01-27
CVE-2017-3437 Oracle E-Business Suite 访问控制错误漏洞 — One-to-One Fulfillment 8.2 -2017-01-27
CVE-2017-3438 Oracle E-Business Suite 访问控制错误漏洞 — One-to-One Fulfillment 8.2 -2017-01-27
CVE-2017-3439 Oracle E-Business Suite 访问控制错误漏洞 — One-to-One Fulfillment 8.2 -2017-01-27
CVE-2017-3440 Oracle Customer Interaction History 访问控制错误漏洞 — Customer Interaction History 8.2 -2017-01-27
CVE-2017-3441 Oracle Customer Interaction History 访问控制错误漏洞 — Customer Interaction History 8.2 -2017-01-27
CVE-2017-3442 Oracle E-Business Suite 访问控制错误漏洞 — Customer Interaction History 8.2 -2017-01-27
CVE-2017-3443 Oracle E-Business Suite 安全漏洞 — Common Applications 8.2 -2017-01-27
CVE-2017-5599 eClinicalWorks Patient Portal 跨站脚本漏洞 — n/a 4.7 -2017-01-27
CVE-2016-9216 Cisco ASR 5000 Series Software 安全漏洞 — Cisco ASR 5000 Software 5.3 -2017-01-26
CVE-2016-9218 Cisco Hybrid Meeting Server 跨站请求伪造漏洞 — Cisco Hybrid Meeting Server 1.0 8.8 -2017-01-26
CVE-2016-9220 Cisco Mobility Express 2800 Series和3800 Series Access Points 资源管理错误漏洞 — Cisco Mobility Express 2800 and 3800 4.3 -2017-01-26
CVE-2016-9221 Cisco Mobility Express 2800和800 Access Points 安全漏洞 — Cisco Mobility Express 2800 Series and 3800 Series Access Points 4.3 -2017-01-26
CVE-2016-9222 Cisco NetFlow Generation Appliance 跨站脚本漏洞 — Cisco NetFlow Generation Appliance 1.0(2) 6.1 -2017-01-26
CVE-2017-3794 Cisco WebEx Meetings Server 跨站请求伪造漏洞 — Cisco WebEx Meetings Server 2.6 8.8 -2017-01-26
CVE-2017-3797 Cisco WebEx Meetings Server 信息泄露漏洞 — Cisco WebEx Meetings Server 2.7 5.3 -2017-01-26
CVE-2017-3798 Cisco Unified Communications Manager 跨站脚本漏洞 — Cisco Unified Communications Manager 6.1 -2017-01-26
CVE-2017-3799 Cisco WebEx Meeting Center 安全漏洞 — Cisco WebEx Meeting Center T28.1 6.1 -2017-01-26
CVE-2017-3800 Cisco Email Security Appliance for AsyncOS 输入验证漏洞 — Cisco AsyncOS 5.8 -2017-01-26
CVE-2017-3802 Cisco Unified Communications Manager 跨站脚本漏洞 — Cisco Unified Communications Manager 12.0(0.99000.9) 6.1 -2017-01-26
CVE-2017-3803 Cisco Catalyst 2960X和3750X Switches 安全漏洞 — Cisco IOS 4.7 -2017-01-26

Vulnerabilities classified as access:pre-auth represent 19065 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.