Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 23340

23340 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2019-5016 KCodes NetUSB.ko 信息泄露漏洞 — KCodesCWE-200 9.1 -2019-06-17
CVE-2017-9386 Vera VeraEdge和Veralite 安全漏洞 — n/a 6.5 -2019-06-17
CVE-2019-7579 Linksys WRT1900ACS 信任管理问题漏洞 — n/a 7.5 -2019-06-17
CVE-2019-11408 FusionPBX Operator Panel模块跨站脚本漏洞 — n/a 6.1 -2019-06-17
CVE-2019-0130 Intel Rapid Storage Technology Enterprise Intel Accelerated Storage Manager 跨站脚本漏洞 — Intel(R) Accelerated Storage Manager in Intel® Rapid Storage Technology Enterprise Advisory 7.4 -2019-06-13
CVE-2019-0136 Intel PROSet/Wireless WiFi Software driver 访问控制错误漏洞 — Intel® PROSet/Wireless WiFi Software 6.5 -2019-06-13
CVE-2019-11119 Intel RAID Web Console 3 输入验证错误漏洞 — Intel(R) RAID Web Console 3 for Windows* 9.8 -2019-06-13
CVE-2019-3946 Fuji Electric V-Server 输入验证错误漏洞 — Fuji Electric V-Server 7.5 -2019-06-12
CVE-2019-6571 Siemens LOGO!8 缓冲区错误漏洞 — SIEMENS LOGO!8CWE-119 7.5 -2019-06-12
CVE-2019-9881 WordPress WPGraphQL 访问控制错误漏洞 — n/a 5.3 -2019-06-10
CVE-2019-9880 WordPress WPGraphQL 访问控制错误漏洞 — n/a 9.1 -2019-06-10
CVE-2019-12780 Belkin Wemo Enabled Crock-Pot 命令注入漏洞 — n/a 9.8 -2019-06-10
CVE-2019-12506 Logitech R700 Laser Presentation Remote R-R0010 访问控制错误漏洞 — n/a 8.8 -2019-06-07
CVE-2019-12504 Inateck Technology Inateck WP2002 数据伪造问题漏洞 — n/a 8.8 -2019-06-07
CVE-2019-12505 Inateck Technology WP1001 注入漏洞 — n/a 8.8 -2019-06-07
CVE-2019-3957 SolarWinds Dameware Remote Mini Control 缓冲区错误漏洞 — Solarwinds Dameware Remote Mini Controller 7.4 -2019-06-07
CVE-2019-3956 SolarWinds Dameware Remote Mini Control 缓冲区错误漏洞 — Solarwinds Dameware Remote Mini Controller 7.4 -2019-06-07
CVE-2019-3955 SolarWinds Dameware Remote Mini Control 缓冲区错误漏洞 — Solarwinds Dameware Remote Mini Controller 7.5 -2019-06-07
CVE-2019-12774 ENTTEC Datagate MK2 跨站脚本漏洞 — n/a 6.1 -2019-06-07
CVE-2019-12477 Zoran Supra Smart Cloud TV 路径遍历漏洞 — n/a 5.5 -2019-06-07
CVE-2019-3723 Web Parameter Tampering Vulnerability — OpenManage Server Administrator 9.1 -2019-06-06
CVE-2019-3722 XML External Entity (XXE) Injection Vulnerability — OpenManage Server Administrator 7.5 -2019-06-06
CVE-2018-8047 Vtiger CRM 跨站脚本漏洞 — n/a 6.1 -2019-06-06
CVE-2019-6451 SOYAL AR-727H和AR-829E 访问控制错误漏洞 — n/a 7.5 -2019-06-06
CVE-2019-8385 Thomson Reuters Desktop Extensions 路径遍历漏洞 — n/a 9.8 -2019-06-05
CVE-2019-12276 GrandNode 路径遍历漏洞 — n/a 7.5 -2019-06-05
CVE-2019-1881 Cisco Industrial Network Director Cross-Site Request Forgery Vulnerability — Cisco Industrial Network DirectorCWE-352 8.8 -2019-06-05
CVE-2019-1870 Cisco Enterprise Chat and Email Cross-Site Scripting Vulnerability — Cisco Enterprise Chat and EmailCWE-79 6.1 -2019-06-05
CVE-2019-1872 Cisco TelePresence Video Communication Server and Cisco Expressway Series Server-Side Request Forgery Vulnerability — Cisco TelePresence Video Communication Server (VCS)CWE-918 5.3 -2019-06-05
CVE-2019-1845 Cisco Unified Communications Manager IM&P Service, Cisco TelePresence VCS, and Cisco Expressway Series Denial of Service Vulnerability — Cisco TelePresence Video Communication Server (VCS)CWE-20 8.6 -2019-06-05

Vulnerabilities classified as access:pre-auth represent 23340 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.