Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22348

22348 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2018-0369 多款Cisco产品Cisco StarOS 输入验证漏洞 — Cisco StarOS unknownCWE-20 8.6 -2018-07-16
CVE-2018-0370 Cisco Firepower System Software检测引擎资源管理错误漏洞 — Cisco Firepower unknownCWE-399 7.5 -2018-07-16
CVE-2018-0383 Cisco FireSIGHT System Software检测引擎安全漏洞 — Cisco FireSIGHT unknownCWE-693 8.6 -2018-07-16
CVE-2018-0384 Cisco FireSIGHT System Software检测引擎安全漏洞 — Cisco FireSIGHT unknownCWE-693 5.8 -2018-07-16
CVE-2018-0385 Cisco Firepower System Software检测引擎安全漏洞 — Cisco Firepower unknownCWE-399 7.5 -2018-07-16
CVE-2018-11716 ZOHO ManageEngine Desktop Central 安全漏洞 — n/a 9.1 -2018-07-16
CVE-2018-13980 Zeta Producer Desktop CMS 路径遍历漏洞 — n/a 6.2 -2018-07-16
CVE-2018-13981 Zeta Producer Desktop CMS 安全漏洞 — n/a 9.8 -2018-07-16
CVE-2016-6543 A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS data — EasyCWE-799 7.5 -2018-07-13
CVE-2016-6544 iTrack Easy's getgps data can be modified without authentication — EasyCWE-306 7.5 -2018-07-13
CVE-2016-6549 Zizai Tech Nut allows for unauthenticated Bluetooth pairing — Tech NutCWE-306 4.3 -2018-07-13
CVE-2016-6566 The Sungard eTRAKiT3 software version 3.2.1.17 may be vulnerable to SQL injection which may allow a remote unauthenticated attacker to run a subset of SQL commands against the back-end database — eTRAKiT3CWE-89 9.8 -2018-07-13
CVE-2016-9482 PHP FormMail Generator generates PHP code for standard web forms, and the code generated is vulnerable to authentication bypass — GeneratorCWE-302 9.8 -2018-07-13
CVE-2016-9483 PHP FormMail Generator generates PHP code for standard web forms, and the code generated is vulnerable to unsafe deserialization of untrusted data — GeneratorCWE-502 9.8 -2018-07-13
CVE-2016-9484 PHP FormMail Generator generates PHP code for standard web forms, and the code generated does not properly validate user input folder directories and is vulnerable to path traversal — GeneratorCWE-22 7.5 -2018-07-13
CVE-2016-9496 Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication to access certain pages — HN7740SCWE-306 6.5 -2018-07-13
CVE-2016-9497 Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate path or channel — HN7740SCWE-288 8.8 -2018-07-13
CVE-2016-9498 ManageEngine Applications Manager 12 and 13, allows unserialization of unsafe Java objects — Applications ManagerCWE-502 9.8 -2018-07-13
CVE-2018-1255 Reflected Cross-Site Scripting Vulnerability — RSA Identity Governance and Lifecycle 6.1 -2018-07-13
CVE-2018-12981 WAGO e!DISPLAY 跨站脚本漏洞 — n/a 5.4 -2018-07-12
CVE-2018-12463 MFSBGN03811 rev.1 - Fortify Software Security Center (SSC), Multiple vulnerabilities — Fortify Software Security Center 9.8 -2018-07-12
CVE-2018-1000614 ONOS Controller 安全漏洞 — n/a 9.8 -2018-07-09
CVE-2018-11351 Jirafeau 跨站脚本漏洞 — n/a 6.1 -2018-07-07
CVE-2016-6540 TrackR Bravo is missing authentication for the cloud service and allows querying or sending of GPS data from unauthenticated users — Bravo Mobile ApplicationCWE-306 8.1 -2018-07-06
CVE-2016-6541 TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributes — Bravo Mobile ApplicationCWE-306 8.8 -2018-07-06
CVE-2018-12103 D-Link DIR-890L A2 访问控制错误漏洞 — n/a 6.5 -2018-07-05
CVE-2018-11051 RSA Certificate Manager Path Traversal Vulnerability — Certificate Manager Path Traversal Vulnerability 7.5 -2018-07-03
CVE-2018-11052 Dell EMC ECS S3 Authentication Bypass Vulnerability — ECS 9.8 -2018-07-03
CVE-2018-12426 WordPress WP Live Chat Support Pro插件安全漏洞 — n/a 9.8 -2018-07-02
CVE-2017-17175 Huawei Mate 9 Pro Short Message Service模块安全漏洞 — Mate 9 Pro 6.5 -2018-07-02

Vulnerabilities classified as access:pre-auth represent 22348 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.