目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

access:pre-auth 标签下的 CVE 漏洞 22137

access:pre-auth 类型相关 22137 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。

“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。

CVE IDタイトルCVSS深刻度公開日
CVE-2024-37145 GHSL-2023-247: Flowise xss in /api/v1/chatflows-streaming/id — FlowiseCWE-79 6.1 Medium2024-07-01
CVE-2024-36423 GHSL-2023-246: Flowise xss in /api/v1/public-chatflows/id — FlowiseCWE-79 6.1 Medium2024-07-01
CVE-2024-21586 Junos OS: SRX Series and NFX Series: Specific valid traffic leads to a PFE crash — Junos OSCWE-754 7.5 High2024-07-01
CVE-2024-36422 GHSL-2023-245: Flowise xss in api/v1/chatflows/id — FlowiseCWE-79 6.1 Medium2024-07-01
CVE-2024-36421 GHSL-2023-234: Flowise Cors Misconfiguration in packages/server/src/index.ts — FlowiseCWE-346 7.5 High2024-07-01
CVE-2024-36401 Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver — geoserverCWE-95 9.8 Critical2024-07-01
CVE-2024-6425 Incorrect Provision of Specified Functionality vulnerability in MESbook — MESbookCWE-684 9.1 Critical2024-07-01
CVE-2024-6424 Server-Side Request Forgery vulnerability in MESbook — MESbookCWE-918 9.3 Critical2024-07-01
CVE-2024-6387 Openssh: regresshion - race condition in ssh allows rce/dos CWE-364 8.1 High2024-07-01
CVE-2024-37763 Machform 安全漏洞 — n/a 6.1AIMediumAI2024-07-01
CVE-2023-4017 Goya <= 1.0.8.7 - Unauthenticated Reflected Cross-Site Scripting via Multiple Parameters — GoyaCWE-79 6.1 Medium2024-06-29
CVE-2024-5598 Advanced File Manager <= 5.2.4 - Sensitive Information Exposure via Directory Listing — Advanced File Manager – Ultimate File Manager for WordPress And Document Library SolutionCWE-922 7.5 High2024-06-29
CVE-2024-5889 Events Manager <= 6.4.8 - Reflected Cross-Site Scripting — Events Manager – Calendar, Bookings, Tickets, and more!CWE-79 6.1 Medium2024-06-29
CVE-2024-6265 UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sort_by' — UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WPCWE-89 9.8 Critical2024-06-29
CVE-2024-6405 Floating Social Buttons <= 1.5 - Cross-Site Request Forgery — Floating Social ButtonsCWE-352 6.1 Medium2024-06-29
CVE-2024-38528 Unlimited number of NTS-KE connections can crash ntpd-rs server — ntpd-rsCWE-770 7.5 High2024-06-28
CVE-2024-2795 SEO SIMPLE PACK <= 3.2.1 - Information Exposure — SEO SIMPLE PACKCWE-200 5.3 Medium2024-06-28
CVE-2024-6288 Conversios.io - All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce <= 7.1.0 - Reflected Cross-Site Scripting — Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-ChannelsCWE-79 4.7 Medium2024-06-28
CVE-2024-6071 PTC Creo Elements/Direct License Server Missing Authorization — Creo Elements/Direct LicenseCWE-862 10.0 Critical2024-06-27
CVE-2024-6127 BC Security Empire Path Traversal RCE — EmpireCWE-22 9.8 Critical2024-06-27
CVE-2024-6085 Path Traversal in parisneo/lollms — parisneo/lollmsCWE-22 9.1AICriticalAI2024-06-27
CVE-2024-3043 Zigbee co-ordinator realignment packet may lead to denial of service — Ember ZNet SDKCWE-829 7.5 High2024-06-27
CVE-2024-31883 IBM Security Verify Access denial of service — Security Verify AccessCWE-703 5.3 Medium2024-06-27
CVE-2024-36072 Netwrix CoSoSys Endpoint Protector 安全漏洞 — n/a 9.8AICriticalAI2024-06-27
CVE-2024-1839 Intrado 911 Emergency Gateway 安全漏洞 — 911 Emergency Gateway (EGW)CWE-89 10.0 Critical2024-06-26
CVE-2024-29175 Dell PowerProtect Data Domain 安全漏洞 — PowerProtect DDCWE-327 5.9 Medium2024-06-26
CVE-2024-23766 HMS Networks Anybus X-Gateway AB7832-F3 安全漏洞 — n/a 7.5AIHighAI2024-06-26
CVE-2024-23767 HMS Networks Anybus X-Gateway AB7832-F3 安全漏洞 — n/a 7.5AIHighAI2024-06-26
CVE-2024-4869 WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.2.0 - Unauthenticated Stored Cross-Site Scripting via Client-IP header — Cookie Banner for GDPR / CCPA – WPLP Cookie ConsentCWE-79 7.2 High2024-06-25
CVE-2024-5019 WhatsUp Gold LoadCSSUsingBasePath Directory Traversal Information Disclosure Vulnerability — WhatsUp GoldCWE-22 5.3 Medium2024-06-25

access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 22137 条 CVE 漏洞。