Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 24129

24129 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2019-10178 pki-core 跨站脚本漏洞 — pki-coreCWE-79 4.6 Medium2020-03-18
CVE-2020-9325 Aquaforest TIFF Server 输入验证错误漏洞 — n/a 7.5 -2020-03-18
CVE-2020-9324 Aquaforest TIFF Server 安全漏洞 — n/a 7.5 -2020-03-18
CVE-2020-9323 Aquaforest TIFF Server 信息泄露漏洞 — n/a 5.3 -2020-03-18
CVE-2020-3922 ArmorX LisoMail - SQL Injection — LisoMail 9.8 Critical2020-03-18
CVE-2020-6988 多款Rockwell Automation产品授权问题漏洞 — Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and priorCWE-603 9.1 -2020-03-16
CVE-2019-17654 Fortinet FortiManager 数据伪造问题漏洞 — Fortinet FortiManager 8.8 -2020-03-15
CVE-2019-14310 RICOH SP C250DN 缓冲区错误漏洞 — n/a 7.5 -2020-03-13
CVE-2019-13194 Brother Industries HL-L8360CDW 访问控制错误漏洞 — n/a 7.5 -2020-03-13
CVE-2019-13165 Xerox Phaser 3320 缓冲区错误漏洞 — n/a 9.8 -2020-03-13
CVE-2019-13168 Xerox Phaser 3320 缓冲区错误漏洞 — n/a 9.8 -2020-03-13
CVE-2019-13171 Xerox Phaser 3320 缓冲区错误漏洞 — n/a 9.8 -2020-03-13
CVE-2019-13195 Kyocera ECOSYS M5526cdw 路径遍历漏洞 — n/a 7.5 -2020-03-13
CVE-2019-13197 Kyocera ECOSYS M5526cdw 缓冲区错误漏洞 — n/a 9.8 -2020-03-13
CVE-2019-13201 Kyocera ECOSYS M5526cdw 缓冲区错误漏洞 — n/a 9.8 -2020-03-13
CVE-2019-13202 Kyocera ECOSYS M5526cdw 缓冲区错误漏洞 — n/a 9.8 -2020-03-13
CVE-2019-13204 Kyocera ECOSYS M5526CDW 缓冲区错误漏洞 — n/a 9.8 -2020-03-13
CVE-2019-13205 Kyocera ECOSYS M5526CDW 信息泄露漏洞 — n/a 7.5 -2020-03-13
CVE-2019-19799 ZOHO ManageEngine Applications Manager 访问控制错误漏洞 — n/a 5.3 -2020-03-13
CVE-2019-12182 Safescan Timemoto TA-8000系列路径遍历漏洞 — n/a 9.8 -2020-03-13
CVE-2020-10196 WordPress popup-builder 跨站脚本漏洞 — n/a 6.1 -2020-03-13
CVE-2020-8571 NetApp StorageGRID 安全漏洞 — StorageGRID (formerly StorageGRID Webscale) 7.5 -2020-03-13
CVE-2019-17653 Fortinet FortiSIEM 跨站请求伪造漏洞 — Fortinet FortiSIEM 8.8 -2020-03-12
CVE-2020-1863 Huawei USG6000V 安全漏洞 — Huawei USG6000V 7.5 -2020-03-12
CVE-2019-16156 Fortinet FortiWeb 跨站脚本漏洞 — Fortinet FortiWeb 6.1 -2020-03-12
CVE-2020-0556 BlueZ 访问控制错误漏洞 — BlueZ 8.3 -2020-03-12
CVE-2020-8540 ZOHO ManageEngine Desktop Central 代码问题漏洞 — n/a 9.8 -2020-03-11
CVE-2020-6205 SAP NetWeaver AS ABAP Business Server Pages 跨站脚本漏洞 — SAP NetWeaver Application Server ABAP (Smart Forms) - SAP_BASIS 8.2 -2020-03-10
CVE-2020-6198 SAP Solution Manager 授权问题漏洞 — SAP Solution Manager (Diagnostics Agent) 9.8 -2020-03-10
CVE-2019-19281 多款Siemens产品资源管理错误漏洞 — SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants)CWE-400 7.5 -2020-03-10

Vulnerabilities classified as access:pre-auth represent 24129 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.