Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 19401

19401 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2022-34448 Dell PowerPath Management Appliance 跨站请求伪造漏洞 — PowerPath Management ApplianceCWE-352 8.8 High2023-02-10
CVE-2022-34444 Dell PowerScale OneFS 加密问题漏洞 — PowerScale OneFSCWE-327 5.9 Medium2023-02-10
CVE-2022-34389 Dell SupportAssist for Home PCs 安全漏洞 — SupportAssist CWE-307 3.7 Low2023-02-10
CVE-2022-24410 Dell BIOS 安全漏洞 — CPG BIOSCWE-200 6.8 Medium2023-02-10
CVE-2022-45699 APsystems Energy Communication Unit 操作系统命令注入漏洞 — n/a 9.8 -2023-02-10
CVE-2022-3568 ImageMagick Engine <= 1.7.5 - Cross-Site Request Forgery to PHAR Deserialization — ImageMagick EngineCWE-502 8.8 High2023-02-09
CVE-2023-24688 mojoPortal 安全漏洞 — n/a 5.3 -2023-02-09
CVE-2023-0726 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_edit_folder — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post TypesCWE-352 5.4 Medium2023-02-08
CVE-2023-0722 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_save_state — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post TypesCWE-352 5.4 Medium2023-02-08
CVE-2023-0725 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_clone_folder — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post TypesCWE-352 5.4 Medium2023-02-08
CVE-2023-0724 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_add_folder — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post TypesCWE-352 5.4 Medium2023-02-08
CVE-2023-0685 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_unassign_folders — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post TypesCWE-352 5.4 Medium2023-02-08
CVE-2023-0723 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery on ajax_move_object — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post TypesCWE-352 5.4 Medium2023-02-07
CVE-2023-0730 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_save_folder_order — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post TypesCWE-352 5.4 Medium2023-02-07
CVE-2023-0727 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_delete_folder — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post TypesCWE-352 5.4 Medium2023-02-07
CVE-2023-0728 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery on ajax_save_folder — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post TypesCWE-352 5.4 Medium2023-02-07
CVE-2022-3229 Rapid7 Metasploit 安全漏洞 — Unified RemoteCWE-285 9.8 -2023-02-06
CVE-2022-4681 Hide My WP < 6.2.9 - Unauthenticated SQLi — Hide My WP 9.8 -2023-02-06
CVE-2022-2933 0mk Shortener <= 0.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting — 0mk ShortenerCWE-352 5.4 Medium2023-02-06
CVE-2022-48164 WAVLINK WL-WN533A8 安全漏洞 — n/a 7.5 -2023-02-06
CVE-2022-48166 WAVLINK WL-WN530HG4 安全漏洞 — n/a 9.1 -2023-02-06
CVE-2023-23849 Synopsys Coverity Connect 跨站脚本漏洞 — CoverityCWE-79 6.1 -2023-02-06
CVE-2023-24576 Dell EMC NetWorker 代码注入漏洞 — NetWorker, NVECWE-94 7.5 High2023-02-03
CVE-2023-25135 Gimmie vBulletin 代码问题漏洞 — n/a 9.8 -2023-02-03
CVE-2023-25136 OpenSSH 资源管理错误漏洞 — n/a 7.4 -2023-02-03
CVE-2021-37304 jeecg 安全漏洞 — n/a 9.1 -2023-02-03
CVE-2022-48165 WAVLINK WL-WN530H4 安全漏洞 — n/a 7.5 -2023-02-03
CVE-2023-24574 Dell Enterprise SONiC OS 资源管理错误漏洞 — Enterprise SONiC OSCWE-400 7.5 High2023-02-02
CVE-2022-40269 Mitsubishi Electric GOT2000 和GT SoftGOT2000 安全漏洞 — GOT2000 Series GT27 modelCWE-290 6.8 Medium2023-02-02
CVE-2022-40268 Mitsubishi Electric GOT2000和GT SoftGOT2000 安全漏洞 — GOT2000 Series GT27 modelCWE-1021 6.1 Medium2023-02-02

Vulnerabilities classified as access:pre-auth represent 19401 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.