目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

access:pre-auth 标签下的 CVE 漏洞 19065

access:pre-auth 类型相关 19065 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。

“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。

CVE IDタイトルCVSS深刻度公開日
CVE-2026-41495 n8n-MCP Logs Sensitive Request Data on Unauthorized /mcp Requests — n8n-mcpCWE-532 5.3 Medium2026-05-08
CVE-2026-42030 MapServer: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in OpenLayers viewer — MapServerCWE-80 6.1 Medium2026-05-08
CVE-2026-42028 novaGallery: Unauthenticated Path Traversal in Album and Cached Image Routes Allows Reading Images Outside Gallery Root — novagalleryCWE-22 5.3 Medium2026-05-08
CVE-2026-42793 Atom table exhaustion via attacker-controlled GraphQL SDL names in absinthe — absintheCWE-770 7.5AIHighAI2026-05-08
CVE-2026-43967 Quadratic fragment-name uniqueness check causes denial of service in absinthe — absintheCWE-407 7.5AIHighAI2026-05-08
CVE-2026-41690 Prototype pollution and path traversal in i18next-http-middleware via user-controlled language and namespace parameters — i18next-http-middlewareCWE-22 8.6 High2026-05-08
CVE-2026-44499 ZEBRA: Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning — zebraCWE-770 7.5AIHighAI2026-05-08
CVE-2026-44500 ZEBRA: Allocation Amplification in Inbound Network Deserializers — zebraCWE-770 5.3 Medium2026-05-08
CVE-2026-41308 Password Pusher: JSON API `/p.json` file upload alias bypasses file-push authentication — PasswordPusherCWE-288 6.5 Medium2026-05-08
CVE-2026-44126 Insecure deserialization — Secure Email GatewayCWE-502 9.8AICriticalAI2026-05-08
CVE-2026-44125 Missing Authorization in GINAv2 — Secure Email GatewayCWE-862 9.8AICriticalAI2026-05-08
CVE-2026-44128 Unauthenticated Remote Code Execution — Secure Email GatewayCWE-95 9.8AICriticalAI2026-05-08
CVE-2026-44127 Local File Inclusion (LFI) and Arbitrary File Deletion — Secure Email GatewayCWE-73 9.1AICriticalAI2026-05-08
CVE-2026-7864 Exposure of Sensitive Information to an Unauthorized Actor — Secure Email GatewayCWE-497 7.5AIHighAI2026-05-08
CVE-2026-43287 drm: Account property blob allocations to memcg — Linux 5.5 -2026-05-08
CVE-2026-41161 Username Enumeration via Timing Attack — serverCWE-208 5.3AIMediumAI2026-05-08
CVE-2022-50994 DrayTek Vigor 2960 < 1.5.1.4 OS Command Injection via mainfunction.cgi — Vigor 2960CWE-78 8.1 High2026-05-08
CVE-2026-8153 Command injection in Dashboard Server interface — PolyScope 5CWE-78 9.8 Critical2026-05-08
CVE-2026-6213 Remote Spark SparkView RCE — SparkViewCWE-807 8.4AIHighAI2026-05-08
CVE-2026-7330 Auto Affiliate Links <= 6.8.8 - Unauthenticated Stored Cross-Site Scripting via 'url' Parameter — Auto Affiliate LinksCWE-79 7.2 High2026-05-08
CVE-2026-4935 SureTriggers < 1.1.23 – Unauthenticated SQLi — OttoKit: All-in-One Automation Platform 9.8AICriticalAI2026-05-08
CVE-2026-42208 LiteLLM: SQL injection in Proxy API key verification — litellmCWE-89 9.1AICriticalAI2026-05-08
CVE-2023-42344 Alkacon OpenCMS 代码问题漏洞 — n/a 7.5AIHighAI2026-05-08
CVE-2022-45899 编号已被CVE保留 — n/a 9.8AICriticalAI2026-05-08
CVE-2022-23961 Thruk Monitoring 跨站脚本漏洞 — n/a 6.1AIMediumAI2026-05-08
CVE-2025-67888 Control Web Panel 操作系统命令注入漏洞 — n/a 8.1AIHighAI2026-05-08
CVE-2026-34354 Akamai Guardicore Platform Agent 安全漏洞 — Guardicore Platform AgentCWE-367 7.4 High2026-05-08
CVE-2026-7541 Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via unauthenticated API endpoint — Enterprise ServerCWE-770 7.5AIHighAI2026-05-07
CVE-2026-6736 Authentication bypass vulnerability in GitHub Enterprise Server allowed creation of local user accounts bypassing the configured external identity provider — Enterprise ServerCWE-306 6.5AIMediumAI2026-05-07
CVE-2026-41928 Vvveb < 1.0.8.2 Information Disclosure via Cron Controller — VvvebCWE-497 5.3 Medium2026-05-07

access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 19065 条 CVE 漏洞。