Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 19430

19430 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2021-35048 Unauthenticated SQL Injection Vulnerability in Fidelis Network and Deception — Fidelis NetworkCWE-89 9.8 Critical2021-06-25
CVE-2021-21571 Dell BIOSConnect信任管理问题漏洞 — UEFI BIOS https stackCWE-295 5.9 Medium2021-06-24
CVE-2021-22382 华为 LTE USB Dongle 安全漏洞 — E3372 7.3 -2021-06-22
CVE-2021-3044 Cortex XSOAR: Unauthorized Usage of the REST API — Cortex XSOARCWE-285 9.8 Critical2021-06-22
CVE-2020-22176 PHPGurukul Hospital Management System 信息泄露漏洞 — n/a 7.5 -2021-06-22
CVE-2020-22170 PHPGurukul Hospital Management System SQL注入漏洞 — n/a 7.5 -2021-06-22
CVE-2020-22164 PHPGurukul Hospital Management System SQL注入漏洞 — n/a 7.5 -2021-06-22
CVE-2020-22165 PHPGurukul Hospital Management System SQL注入漏洞 — n/a 7.5 -2021-06-22
CVE-2020-22166 PHPGurukul Hospital Management System SQL注入漏洞 — n/a 7.5 -2021-06-22
CVE-2020-22168 PHPGurukul Hospital Management System SQL注入漏洞 — n/a 7.5 -2021-06-22
CVE-2020-22169 PHPGurukul Hospital Management System SQL注入漏洞 — n/a 7.5 -2021-06-22
CVE-2020-22171 PHPGurukul Hospital Management System SQL注入漏洞 — n/a 7.5 -2021-06-22
CVE-2020-22172 PHPGurukul Hospital Management System SQL注入漏洞 — n/a 7.5 -2021-06-22
CVE-2020-22173 PHPGurukul Hospital Management System SQL注入漏洞 — n/a 7.5 -2021-06-22
CVE-2020-22174 PHPGurukul Hospital Management System SQL注入漏洞 — n/a 7.5 -2021-06-22
CVE-2020-22175 PHPGurukul Hospital Management System SQL注入漏洞 — n/a 7.5 -2021-06-22
CVE-2021-24379 Comments Like Dislike < 1.1.4 - Add Like/Dislike Bypass — Comments Like DislikeCWE-863 5.3 -2021-06-21
CVE-2021-24361 GeoDirectory Location Manager < 2.1.0.10 - Multiple Unauthenticated SQL Injections — Location ManagerCWE-89 9.8 -2021-06-21
CVE-2021-24370 Fancy Product Designer < 4.6.9 - Unauthenticated Arbitrary File Upload and RCE — Fancy Product DesignerCWE-434 9.8 -2021-06-21
CVE-2020-35373 Fiyo CMS 跨站脚本漏洞 — n/a 6.1 -2021-06-17
CVE-2020-25754 Enphase Envoy 安全漏洞 — n/a 7.5 -2021-06-16
CVE-2020-25753 Enphase Envoy 安全漏洞 — n/a 7.5 -2021-06-16
CVE-2020-25752 Enphase Envoy 信任管理问题漏洞 — n/a 5.3 -2021-06-16
CVE-2021-1395 Cisco Unified Intelligence Center Reflected Cross-Site Scripting Vulnerability — Cisco Unified Contact Center ExpressCWE-79 4.7 Medium2021-06-16
CVE-2021-1566 Cisco Email Security Appliance and Cisco Web Security Appliance Certificate Validation Vulnerability — Cisco Web Security Appliance (WSA)CWE-296 7.4 High2021-06-16
CVE-2021-32033 Protectimus SLIM NFC 授权问题漏洞 — n/a 6.1 -2021-06-16
CVE-2021-20094 Wibu-Systems CodeMeter 缓冲区错误漏洞 — Wibu-Systems CodeMeter 7.5 -2021-06-16
CVE-2021-20093 Wibu-Systems CodeMeter 缓冲区错误漏洞 — Wibu-Systems CodeMeter 9.1 -2021-06-16
CVE-2021-27388 Siemens SINAMICS SL150 输入验证错误漏洞 — SINAMICS Medium Voltage Products, Remote AccessCWE-20 9.8 -2021-06-15
CVE-2021-32682 Multiple vulnerabilities leading to RCE — elFinderCWE-918 9.8 Critical2021-06-14

Vulnerabilities classified as access:pre-auth represent 19430 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.