Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 22433

22433 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2026-8385 WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback — WP Go Maps--2026-06-15
CVE-2026-8386 WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Marker ID — WP Go Maps--2026-06-15
CVE-2026-8935 Advanced Google Maps < 6.1.1 - Unauthenticated Administrator Account Creation — WP MAPS PRO--2026-06-15
CVE-2026-54413 driftregion iso14229 缓冲区错误漏洞 — iso14229CWE-191 8.2 High2026-06-14
CVE-2026-54412 Liam Bindle MQTT-C 缓冲区错误漏洞 — MQTT-CCWE-125 8.2 High2026-06-14
CVE-2026-54410 Valerio De Benedetto nanoMODBUS 数字错误漏洞 — nanoMODBUSCWE-193 8.6 High2026-06-14
CVE-2026-12183 Nefteprodukttekhnika BUK TS-G Gas Station Automation System 授权问题漏洞 — BUK TS-G Gas Station Automation SystemCWE-287 9.8 Critical2026-06-13
CVE-2026-5513 Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie — Online Scheduling and Appointment Booking System – BooklyCWE-79 7.2 High2026-06-13
CVE-2026-2470 Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts' — Page Builder: Pagelayer – Drag and Drop website builderCWE-863 4.3 Medium2026-06-13
CVE-2026-9109 GPTranslate <= 2.31 - Unauthenticated Stored Cross-Site Scripting via REST API Translation Storage — GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate WebsitesCWE-79 7.2 High2026-06-13
CVE-2026-9848 WP Ticket <= 6.0.4 - Unauthenticated SQL Injection via WordPress Search 's' Parameter — Customer Support Ticket System & HelpdeskCWE-89 7.5 High2026-06-13
CVE-2026-53609 Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass — apostropheCWE-1321 9.1 Critical2026-06-12
CVE-2026-53607 @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header — apostropheCWE-918 3.7 Low2026-06-12
CVE-2026-45013 Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation — apostropheCWE-20 8.1 High2026-06-12
CVE-2026-54359 MISP automation endpoints may be exposed to CSRF when Sec-Fetch-Site protection is disabled by default — mispCWE-352--2026-06-12
CVE-2026-53726 Parse Server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL — parse-serverCWE-639--2026-06-12
CVE-2026-47138 Parse Server: Pre-authentication denial of service via client version header regex backtracking — parse-serverCWE-1333--2026-06-12
CVE-2026-47248 Parse Server: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers — parse-serverCWE-209--2026-06-12
CVE-2026-53408 Zoom Workplace 授权问题漏洞 — Zoom WorkplaceCWE-939 8.1 High2026-06-12
CVE-2026-53407 Zoom Workplace 授权问题漏洞 — Zoom WorkplaceCWE-939 8.1 High2026-06-12
CVE-2026-47216 Typesense: Unauthenticated Denial of Service in the Typesense /multi_search Endpoint — typesenseCWE-754--2026-06-12
CVE-2026-48558 SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification — SimpleHelpCWE-347 10.0 Critical2026-06-12
CVE-2026-50090 Aqara OAuth redirect_uri validation bypass — Cloud OAuth Authorization EndpointCWE-1289 9.3 Critical2026-06-12
CVE-2026-50086 Aqara unauthenticated AES oracle — Aqara IAM/SSO GatewayCWE-327 10.0 Critical2026-06-12
CVE-2026-50085 Aqara Board IoT insecure debug API — Board serviceCWE-306 8.6 High2026-06-12
CVE-2026-50084 Aqara API cross-account access — Cloud Production APICWE-862 9.6 Critical2026-06-12
CVE-2026-50083 Aqara hardcoded OAuth client credentials — Aquara IAM/SSO GatewayCWE-798 9.1 Critical2026-06-12
CVE-2026-50082 Aqara Developer Portal insecure authentication token — Cloud Developer PortalCWE-306 6.5 Medium2026-06-12
CVE-2026-8694 Improper access control on the API documentation endpoint in PowerShell Universal — PowerShell UniversalCWE-306--2026-06-12
CVE-2026-53787 Amasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File Upload — Order Attributes for Magento 2CWE-434 9.8 Critical2026-06-12

Vulnerabilities classified as access:pre-auth represent 22433 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.