Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 19241

19241 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2023-20070 Cisco Firepower Threat Defense 安全漏洞 — Cisco Firepower Threat Defense SoftwareCWE-244 4.0 Medium2023-11-01
CVE-2023-20071 Cisco Firepower Threat Defense 安全漏洞 — Cisco Firepower Threat Defense SoftwareCWE-1039 5.8 Medium2023-11-01
CVE-2023-20031 Cisco Firepower Threat Defense 安全漏洞 — Cisco Firepower Threat Defense SoftwareCWE-244 4.0 Medium2023-11-01
CVE-2023-20255 Cisco Meeting Server 安全漏洞 — Cisco Meeting ServerCWE-20 5.3 Medium2023-11-01
CVE-2023-20213 Cisco Identity Services Engine 安全漏洞 — Cisco Identity Services Engine SoftwareCWE-787 4.3 Medium2023-11-01
CVE-2023-20245 Cisco Firepower Threat Defense 安全漏洞 — Cisco Adaptive Security Appliance (ASA) SoftwareCWE-290 5.8 Medium2023-11-01
CVE-2023-20256 Cisco Firepower Threat Defense 安全漏洞 — Cisco Adaptive Security Appliance (ASA) SoftwareCWE-290 5.0 Medium2023-11-01
CVE-2023-20005 Cisco Firepower Management Center 跨站脚本漏洞 — Cisco Firepower Management CenterCWE-79 4.8 Medium2023-11-01
CVE-2023-20074 Cisco Firepower Management Center 跨站脚本漏洞 — Cisco Firepower Management CenterCWE-79 4.8 Medium2023-11-01
CVE-2023-20206 Cisco Firepower Management Center 安全漏洞 — Cisco Firepower Management CenterCWE-79 6.1 Medium2023-11-01
CVE-2023-20041 Cisco Firepower Management Center 跨站脚本漏洞 — Cisco Firepower Management CenterCWE-79 4.8 Medium2023-11-01
CVE-2023-20270 Cisco Firepower Threat Defense 安全漏洞 — Cisco Firepower Threat Defense SoftwareCWE-20 5.8 Medium2023-11-01
CVE-2023-20244 Cisco Firepower Threat Defense 安全漏洞 — Cisco Firepower Threat Defense SoftwareCWE-771 8.6 High2023-11-01
CVE-2023-20155 Cisco Firepower Management Center 安全漏洞 — Cisco Firepower Management CenterCWE-770 7.5 High2023-11-01
CVE-2023-20086 Cisco Firepower Threat Defense和Cisco ASA 安全漏洞 — Cisco Adaptive Security Appliance (ASA) SoftwareCWE-248 8.6 High2023-11-01
CVE-2023-20177 Cisco Firepower Threat Defense 安全漏洞 — Cisco Firepower Threat Defense SoftwareCWE-244 4.0 Medium2023-11-01
CVE-2023-1719 Bitrix24 Insecure Global Variable Extraction — Bitrix24CWE-665 7.5 High2023-11-01
CVE-2023-1718 Bitrix24 Denial-of-Service (DoS) via Improper File Stream Access — Bitrix24CWE-835 7.5 High2023-11-01
CVE-2023-46237 FOG path traversal via unauthenticated endpoint — fogprojectCWE-22 5.8 Medium2023-10-31
CVE-2023-46236 FOG SSRF via unauthenticated endpoint(s) — fogprojectCWE-918 8.6 High2023-10-31
CVE-2023-22518 Atlassian Confluence Data Center 和 Confluence Server 安全漏洞 — Confluence Data Center 9.8 -2023-10-31
CVE-2023-5307 Photos and Files Contest Gallery – Contact Form < 21.2.8.1 - Unauthenticated Stored XSS via HTTP Headers — Photos and Files Contest Gallery 6.1 -2023-10-31
CVE-2023-5360 Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload — Royal Elementor Addons and Templates 9.8 -2023-10-31
CVE-2016-1203 NetMove SaAT Netizen和SaAT Netizen installer 安全漏洞 — SaAT Netizen installer 8.1 -2023-10-31
CVE-2022-3007 Unauthorized Access Vulnerability in Syska SW100 Smartwatch — Syska SW100 SmartwatchCWE-862 8.1 High2023-10-31
CVE-2023-46978 TOTOLINK X6000R 安全漏洞 — n/a 9.1 -2023-10-31
CVE-2023-46992 TOTOLINK A3300R 安全漏洞 — n/a 9.1 -2023-10-31
CVE-2023-45672 Frigate unsafe deserialization in `load_config_with_no_duplicates` of `frigate/util/builtin.py` — frigateCWE-502 7.5 High2023-10-30
CVE-2023-42804 BigBlueButton Path Traversal – Reading Certain File Extensions — bigbluebuttonCWE-22 3.1 Low2023-10-30
CVE-2023-36920 Clickjacking vulnerability in SAP Enable Now — SAP Enable NowCWE-1021 6.1 Medium2023-10-30

Vulnerabilities classified as access:pre-auth represent 19241 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.