Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 19263

19263 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2023-22047 Oracle PeopleSoft Enterprise PeopleTools 安全漏洞 — PeopleSoft Enterprise PT PeopleTools 7.5 High2023-07-18
CVE-2023-22045 Oracle Java SE 安全漏洞 — Java SE JDK and JRE 3.7 Low2023-07-18
CVE-2023-22044 Oracle Java SE 安全漏洞 — Java SE JDK and JRE 3.7 Low2023-07-18
CVE-2023-22043 Oracle Java SE 安全漏洞 — Java SE JDK and JRE 5.9 Medium2023-07-18
CVE-2023-22042 Oracle E-Business Suite 安全漏洞 — Applications Framework 6.1 Medium2023-07-18
CVE-2023-22041 Oracle Java SE 安全漏洞 — Java SE JDK and JRE 5.1 Medium2023-07-18
CVE-2023-22036 Oracle Java SE 安全漏洞 — Java SE JDK and JRE 3.7 Low2023-07-18
CVE-2023-22035 Oracle E-Business Suite 跨站脚本漏洞 — Scripting 6.1 Medium2023-07-18
CVE-2023-22018 Oracle Virtualization 安全漏洞 — VM VirtualBox 8.1 High2023-07-18
CVE-2023-22014 Oracle PeopleSoft Enterprise PeopleTools 安全漏洞 — PeopleSoft Enterprise PT PeopleTools 8.4 High2023-07-18
CVE-2023-22006 Oracle Java SE 安全漏洞 — Java SE JDK and JRE 3.1 Low2023-07-18
CVE-2023-21994 Oracle Fusion Middleware 安全漏洞 — Mobile Security Suite 6.5 Medium2023-07-18
CVE-2023-22004 Oracle E-Business Suite 安全漏洞 — E-Business Suite Technology Stack 4.3 Medium2023-07-18
CVE-2023-21983 Oracle Application Express 安全漏洞 — Application Express (APEX) 5.6 Medium2023-07-18
CVE-2023-21949 Oracle Database Server 安全漏洞 — Advanced Networking Option 3.7 Low2023-07-18
CVE-2023-35763 Iagona ScrutisWeb Use of Hard-coded Cryptographic Key — ScrutisWeb 5.5 Medium2023-07-18
CVE-2023-33871 Iagona ScrutisWeb Absolute Path Traversal — ScrutisWeb 7.5 High2023-07-18
CVE-2023-38257 CVE-2023-38257 — ScrutisWeb 7.5 High2023-07-18
CVE-2023-35189 Iagona ScrutisWeb Unrestricted Upload of File with Dangerous Type — ScrutisWebCWE-434 10.0 Critical2023-07-18
CVE-2023-3709 Royal Elementor Addons <=1.3.70 - Unauthenticated MailChimp API Key Disclosure — Royal Addons for Elementor – Addons and Templates Kit for ElementorCWE-200 5.3 Medium2023-07-18
CVE-2023-3708 Multiple DeoThemes Themes <= (Various Versions) - Reflected Cross-Site Scripting — AmelaCWE-79 6.1 Medium2023-07-18
CVE-2023-37265 Incorrect identification of source IP addresses in CasaOS — CasaOS-GatewayCWE-306 9.8 Critical2023-07-17
CVE-2023-37266 Weak json web token (JWT) secrets in CasaOS — CasaOSCWE-287 9.8 Critical2023-07-17
CVE-2023-34141 Zyxel ATP 操作系统命令注入漏洞 — ATP series firmwareCWE-78 8.0 High2023-07-17
CVE-2023-34140 Zyxel ATP 安全漏洞 — ATP series firmwareCWE-120 6.5 Medium2023-07-17
CVE-2023-34139 Zyxel USG FLEX 操作系统命令注入漏洞 — USG FLEX series firmwareCWE-78 8.8 High2023-07-17
CVE-2023-34138 Zyxel ATP 操作系统命令注入漏洞 — ATP series firmwareCWE-78 8.0 High2023-07-17
CVE-2023-33012 Zyxel ATP 操作系统命令注入漏洞 — ATP series firmwareCWE-78 8.8 High2023-07-17
CVE-2023-33011 Zyxel ATP 格式化字符串错误漏洞 — ATP series firmwareCWE-134 8.8 High2023-07-17
CVE-2023-28767 Zyxel ATP 操作系统命令注入漏洞 — ATP series firmwareCWE-78 8.8 High2023-07-17

Vulnerabilities classified as access:pre-auth represent 19263 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.