access:pre-auth 类型相关 22137 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。
“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-8234 | Zyxel NWA1100-N 操作系统命令注入漏洞 — NWA1100-N firmwareCWE-78 | 7.5 | High | 2024-08-30 |
| CVE-2024-6671 | WhatsUp Gold 安全漏洞 — WhatsUp GoldCWE-89 | 9.8 | Critical | 2024-08-29 |
| CVE-2024-6670 | WhatsUp Gold 安全漏洞 — WhatsUp GoldCWE-89 | 9.8 | Critical | 2024-08-29 |
| CVE-2024-3679 | WordPress plugin Premium SEO Pack – WP SEO Plugin 信息泄露漏洞 — Premium SEO Pack – WP SEO PluginCWE-200 | 5.3 | Medium | 2024-08-29 |
| CVE-2024-2541 | WordPress plugin WordPress plugin 信息泄露漏洞 — Popup Builder – Create highly converting, mobile friendly marketing popups.CWE-200 | 5.3 | Medium | 2024-08-29 |
| CVE-2024-6551 | WordPress plugin GiveWP 信息泄露漏洞 — GiveWP – Donation Plugin and Fundraising PlatformCWE-200 | 5.3 | Medium | 2024-08-29 |
| CVE-2024-5857 | WordPress plugin Funnelforms Free 安全漏洞 — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms FreeCWE-862 | 5.3 | Medium | 2024-08-29 |
| CVE-2024-45043 | OpenTelemetry Collector 安全漏洞 — opentelemetry-collector-contribCWE-200 | 5.3 | Medium | 2024-08-28 |
| CVE-2024-20446 | Cisco NX-OS Software 安全漏洞 — Cisco NX-OS SoftwareCWE-476 | 8.6 | High | 2024-08-28 |
| CVE-2024-8195 | WordPress plugin Permalink Manager Lite 安全漏洞 — Permalink Manager LiteCWE-862 | 5.3 | Medium | 2024-08-28 |
| CVE-2024-6450 | HyperView Geoportal Toolkit 安全漏洞 — Geoportal ToolkitCWE-79 | 6.1AI | MediumAI | 2024-08-28 |
| CVE-2024-6449 | HyperView Geoportal Toolkit 安全漏洞 — Geoportal ToolkitCWE-942 | 6.5AI | MediumAI | 2024-08-28 |
| CVE-2024-7447 | WordPress plugin Funnelforms Free 安全漏洞 — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms FreeCWE-862 | 5.3 | Medium | 2024-08-28 |
| CVE-2024-39771 | Safie QBiC CLOUD CC-2L和Safie One 安全漏洞 — QBiC CLOUD CC-2L | 6.8AI | MediumAI | 2024-08-28 |
| CVE-2024-6448 | WordPress plugin Mollie Payments for WooCommerce 信息泄露漏洞 — Mollie Payments for WooCommerceCWE-200 | 5.3 | Medium | 2024-08-28 |
| CVE-2024-8030 | WordPress plugin Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider 安全漏洞 — Ultimate Store Kit – Addon For WooCommerce, EDD and ElementorCWE-502 | 9.8 | Critical | 2024-08-28 |
| CVE-2024-7573 | WordPress plugin Relevanssi Live Ajax Search 安全漏洞 — Relevanssi Live Ajax SearchCWE-88 | 5.3 | Medium | 2024-08-28 |
| CVE-2024-45232 | TYPO3 安全漏洞 — n/a | 5.3AI | MediumAI | 2024-08-28 |
| CVE-2024-45233 | TYPO3 安全漏洞 — n/a | 9.1AI | CriticalAI | 2024-08-28 |
| CVE-2024-8200 | WordPress plugin Reviews Feed 安全漏洞 — Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and MoreCWE-352 | 4.3 | Medium | 2024-08-27 |
| CVE-2024-8181 | Flowise 安全漏洞 — Flowise | 9.8 | Critical | 2024-08-27 |
| CVE-2024-8182 | Flowise 安全漏洞 — Flowise | 7.5 | High | 2024-08-27 |
| CVE-2024-43798 | Chisel 安全漏洞 — chiselCWE-306 | 8.6 | High | 2024-08-26 |
| CVE-2024-45241 | CentralSquare CryWolf 安全漏洞 — n/a | 7.5AI | HighAI | 2024-08-26 |
| CVE-2024-45256 | BYOB 安全漏洞 — n/a | 9.8AI | CriticalAI | 2024-08-26 |
| CVE-2024-6499 | WordPress plugin WordPress Button Plugin MaxButtons 安全漏洞 — MaxButtons – Create buttonsCWE-200 | 5.3 | Medium | 2024-08-24 |
| CVE-2024-8120 | WordPress plugin ImageRecycle pdf & image compression 安全漏洞 — ImageRecycle pdf & image compressionCWE-352 | 4.7 | Medium | 2024-08-24 |
| CVE-2024-7568 | WordPress plugin Favicon Generator 安全漏洞 — Favicon Generator (CLOSED)CWE-352 | 9.6 | Critical | 2024-08-24 |
| CVE-2023-6987 | WordPress plugin String locator 安全漏洞 — String locatorCWE-79 | 6.1 | Medium | 2024-08-24 |
| CVE-2024-7954 | SPIP 安全漏洞 — SPIPCWE-95 | 9.8 | Critical | 2024-08-23 |
access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 22137 条 CVE 漏洞。