目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

access:pre-auth 标签下的 CVE 漏洞 22137

access:pre-auth 类型相关 22137 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。

“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。

CVE IDタイトルCVSS深刻度公開日
CVE-2024-6309 Attachment File Icons (AF Icons) <= 1.3 - Cross-Site Request Forgery to Arbitrary File Upload — Attachment File Icons (AF Icons)CWE-352 8.8 High2024-07-09
CVE-2024-6316 Generate PDF using Contact Form 7 <= 4.1.2 - Cross-Site Request Forgery to Arbitrary File Upload — Generate PDF using Contact Form 7CWE-352 8.8 High2024-07-09
CVE-2024-6317 Generate PDF using Contact Form 7 <= 4.1.2 - Cross-Site Request Forgery to Arbitrary File Deletion — Generate PDF using Contact Form 7CWE-352 8.8 High2024-07-09
CVE-2024-6180 EventON <= 2.2.15 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting and Plugin Settings Updates — EventON – Events CalendarCWE-862 7.2 High2024-07-09
CVE-2024-28747 ifm: Use of Hard-coded Credentials — Smart PLC AC14xx FirmwareCWE-798 9.8 Critical2024-07-09
CVE-2024-5488 SEOPress < 7.9 - Unauthenticated Object Injection — SEOPress 9.8AICriticalAI2024-07-09
CVE-2024-5441 Modern Events Calendar <= 7.11.0 - Authenticated (Subscriber+) Arbitrary File Upload — Modern Events CalendarCWE-434 8.8 High2024-07-09
CVE-2024-6171 Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - IP Address Spoofing to Antispam Bypass — Unlimited Elements For ElementorCWE-348 5.3 Medium2024-07-09
CVE-2024-37173 [Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI) — SAP CRM WebClient UICWE-79 6.1 Medium2024-07-09
CVE-2024-6365 Product Table by WBW <= 2.0.1 - Unauthenticated Remote Code Execution — Product Table for WooCommerce by WBWCWE-94 9.8 Critical2024-07-09
CVE-2023-50805 SAMSUNG Mobile Processor和Wearable Processor安全漏洞 — n/a 8.1 High2024-07-09
CVE-2023-50807 SAMSUNG Wearable Processor 安全漏洞 — n/a 8.1 High2024-07-09
CVE-2024-23562 HCL Domino is susceptible to an information disclosure vulnerability — Domino Server 5.3 Medium2024-07-08
CVE-2024-5753 Local File Read (LFI) by Prompt Injection via Postgres SQL in vanna-ai/vanna — vanna-ai/vannaCWE-89 9.1AICriticalAI2024-07-05
CVE-2024-38346 Apache CloudStack: Unauthenticated cluster service port leads to remote execution — Apache CloudStackCWE-94 10.0 -2024-07-05
CVE-2024-39864 Apache CloudStack: Integration API service uses dynamic port when disabled — Apache CloudStackCWE-665 9.1 -2024-07-05
CVE-2024-5943 Nested Pages <= 3.2.7 - Cross-Site Request Forgery to Local File Inclusion — Nested PagesCWE-352 8.8 High2024-07-04
CVE-2024-1573 Mitsubishi Electric MC Works64 授权问题漏洞 — GENESIS64CWE-306 5.9 Medium2024-07-04
CVE-2024-31223 Fides Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL — fidesCWE-497 5.3 Medium2024-07-03
CVE-2024-6427 Uncontrolled Resource Consumption vulnerability in MESbook — MESbookCWE-400 7.5 High2024-07-03
CVE-2024-4543 Snippet Shortcodes <= 4.1.4 - Cross-Site Request Forgery — Snippet ShortcodesCWE-352 4.3 Medium2024-07-03
CVE-2024-6099 LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User Registration — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-420 5.3 Medium2024-07-02
CVE-2024-6088 LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration Bypass — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-862 5.3 Medium2024-07-02
CVE-2024-4836 LFI in sites managed by Edito CMS — Edito CMSCWE-552 7.5 High2024-07-02
CVE-2023-41918 Missing Authentication for Critical Function in Kiloview P1/P2 devices — P1/P2CWE-306 10.0 Critical2024-07-02
CVE-2024-5544 Media Library Assistant <= 3.17 - Reflected Cross-Site Scripting — Media Library AssistantCWE-79 6.1 Medium2024-07-02
CVE-2024-5545 Motors – Car Dealer, Classifieds & Listing <= 1.4.9 - Missing Authorization — Motors – Car Dealership & Classified Listings PluginCWE-862 5.3 Medium2024-07-02
CVE-2024-6172 Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.25 - Unauthenticated SQL Injection via unsubscribe — Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPressCWE-89 9.8 Critical2024-07-02
CVE-2024-39891 Twilio Authy API 安全漏洞 — n/a 5.3 Medium2024-07-02
CVE-2024-37146 GHSL-2023-248: Flowise xss in /api/v1/credentials/id — FlowiseCWE-79 6.1 Medium2024-07-01

access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 22137 条 CVE 漏洞。