目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

access:pre-auth 标签下的 CVE 漏洞 22133

access:pre-auth 类型相关 22133 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。

“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。

CVE ID标题CVSS风险等级Published
CVE-2024-9347 WordPress plugin The Ultimate WordPress Toolkit – WP Extended 跨站脚本漏洞 — The Ultimate WordPress Toolkit – WP ExtendedCWE-79 6.1 Medium2024-10-17
CVE-2024-9263 WordPress plugin WP Timetics 安全漏洞 — Timetics – Appointment Booking & SchedulingCWE-639 9.8 Critical2024-10-17
CVE-2024-9863 WordPress plugin UserPro 安全漏洞 — Miniorange OTP Verification with FirebaseCWE-266 9.8 Critical2024-10-17
CVE-2024-9940 WordPress plugin Calculated Fields Form 安全漏洞 — Calculated Fields FormCWE-75 5.3 Medium2024-10-17
CVE-2024-9240 WordPress plugin ReDi Restaurant Reservation 安全漏洞 — ReDi Restaurant Reservation – Instant Availability & ConfirmationCWE-79 6.1 Medium2024-10-17
CVE-2024-9862 WordPress plugin Miniorange OTP Verification with Firebase 安全漏洞 — Miniorange OTP Verification with FirebaseCWE-639 9.8 Critical2024-10-17
CVE-2024-9861 WordPress plugin Miniorange OTP Verification with Firebase 安全漏洞 — Miniorange OTP Verification with FirebaseCWE-288 8.1 High2024-10-17
CVE-2024-47836 Admidio 代码问题漏洞 — admidioCWE-502 3.5 Low2024-10-16
CVE-2024-20512 Cisco Unified Contact Center Management Portal 跨站脚本漏洞 — Cisco Unified Contact Center Management PortalCWE-79 6.1 Medium2024-10-16
CVE-2024-20463 Cisco ATA 190 安全漏洞 — Cisco Analog Telephone Adaptor (ATA) SoftwareCWE-305 5.4 Medium2024-10-16
CVE-2024-20460 Cisco ATA 190 安全漏洞 — Cisco Analog Telephone Adaptor (ATA) SoftwareCWE-80 6.1 Medium2024-10-16
CVE-2024-20458 Cisco ATA 190 操作系统命令注入漏洞 — Cisco Analog Telephone Adaptor (ATA) SoftwareCWE-78 8.2 High2024-10-16
CVE-2024-20421 Cisco ATA 190 跨站请求伪造漏洞 — Cisco Analog Telephone Adaptor (ATA) SoftwareCWE-352 7.1 High2024-10-16
CVE-2024-9893 WordPress plugin Nextend Social Login Pro 安全漏洞 — Nextend Social Login ProCWE-288 9.8 Critical2024-10-16
CVE-2020-36841 WordPress plugin WooCommerce Smart Coupons 授权问题漏洞 — WooCommerce Smart CouponsCWE-285 5.3 Medium2024-10-16
CVE-2023-32193 Rancher 安全漏洞 — normanCWE-80 8.3 High2024-10-16
CVE-2023-32192 Rancher API Server 安全漏洞 — apiserverCWE-80 8.3 High2024-10-16
CVE-2023-7295 WordPress plugin Video Grid 跨站脚本漏洞 — Video GridCWE-79 6.1 Medium2024-10-16
CVE-2017-20194 WordPress plugin Formidable Form Builder 信息泄露漏洞 — Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form BuilderCWE-200 5.3 Medium2024-10-16
CVE-2017-20193 WordPress plugin Product Vendors 跨站脚本漏洞 — Product VendorsCWE-79 4.7 Medium2024-10-16
CVE-2020-36840 WordPress plugin Timetable and Event Schedule by MotoPress 安全漏洞 — Timetable and Event Schedule by MotoPressCWE-862 7.3 High2024-10-16
CVE-2016-15042 WordPress plugin Frontend File Manager 代码问题漏洞 — N-Media Post Front-end FormCWE-434 9.8 Critical2024-10-16
CVE-2024-9061 WordPress plugin The WP Popup Builder 代码注入漏洞 — WP Popup Builder – Popup Forms and Marketing Lead GenerationCWE-94 7.3 High2024-10-16
CVE-2024-8507 WordPress plugin File Manager Pro 请求伪造漏洞 — File Manager ProCWE-352 8.8 High2024-10-16
CVE-2020-36839 WordPress plugin WP Lead Plus X 跨站请求伪造漏洞 — WordPress Landing Page – Squeeze Page – Responsive Landing Page Builder Free – WP Lead Plus XCWE-352 8.3 High2024-10-16
CVE-2019-25216 WordPress plugin Rich Review 跨站脚本漏洞 — Rich Reviews by StarfishCWE-79 7.2 High2024-10-16
CVE-2019-25214 WordPress plugin ShopWP 安全漏洞 — ShopWPCWE-862 7.2 High2024-10-16
CVE-2016-15041 WordPress plugin MainWP Dashboard 跨站脚本漏洞 — MainWP Dashboard: Self-hosted WordPress Management for AgenciesCWE-79 7.2 High2024-10-16
CVE-2018-25105 WordPress plugin File Manager 安全漏洞 — File ManagerCWE-862 9.8 Critical2024-10-16
CVE-2022-4972 WordPress plugin Download Monitor 安全漏洞 — Download MonitorCWE-862 7.5 High2024-10-16

access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 22133 条 CVE 漏洞。