目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1310

100%

access:pre-auth 标签下的 CVE 漏洞 19704

access:pre-auth 类型相关 19704 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。

“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。

CVE ID标题CVSS风险等级Published
CVE-2026-30860 WeKnora SQL注入漏洞 — WeKnoraCWE-89 10.0 Critical2026-03-07
CVE-2026-30858 Tencent WeKnora 代码问题漏洞 — WeKnoraCWE-918 6.5 Medium2026-03-07
CVE-2026-30855 WeKnora 访问控制错误漏洞 — WeKnoraCWE-284 8.8 High2026-03-07
CVE-2026-30854 Parse Server 安全漏洞 — parse-serverCWE-863 5.3 -2026-03-07
CVE-2026-30848 Parse Server 路径遍历漏洞 — parse-serverCWE-22 7.5 -2026-03-07
CVE-2026-29787 mcp-memory-service 信息泄露漏洞 — mcp-memory-serviceCWE-200 5.3 Medium2026-03-07
CVE-2026-1086 WordPress plugin Font Pairing Preview For Landing Pages 跨站请求伪造漏洞 — Font Pairing Preview For Landing PagesCWE-352 4.3 Medium2026-03-07
CVE-2026-1087 WordPress plugin Guardian News Feed 跨站请求伪造漏洞 — The Guardian News FeedCWE-352 4.3 Medium2026-03-07
CVE-2026-1085 WordPress plugin True Ranker 跨站请求伪造漏洞 — True RankerCWE-352 4.3 Medium2026-03-07
CVE-2026-1074 WordPress plugin WP App Bar 跨站脚本漏洞 — WP App BarCWE-79 7.2 High2026-03-07
CVE-2026-1073 WordPress plugin Purchase Button For Affiliate Link 跨站请求伪造漏洞 — Purchase Button For Affiliate LinkCWE-352 4.3 Medium2026-03-07
CVE-2026-2433 WordPress plugin RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging 跨站脚本漏洞 — RSS Aggregator – RSS Import, News Feeds, Feed to Post, and AutobloggingCWE-79 6.1 Medium2026-03-07
CVE-2026-27796 homarr 安全漏洞 — homarrCWE-200 5.3 Medium2026-03-07
CVE-2026-27797 homarr 代码问题漏洞 — homarrCWE-918 5.3 Medium2026-03-07
CVE-2026-30829 Checkmate 信息泄露漏洞 — CheckmateCWE-200 5.3 Medium2026-03-07
CVE-2026-30824 Flowise 访问控制错误漏洞 — FlowiseCWE-306 10.0 -2026-03-07
CVE-2026-30822 Flowise 安全漏洞 — FlowiseCWE-915 5.3 -2026-03-07
CVE-2026-30821 Flowise 代码问题漏洞 — FlowiseCWE-434 9.8 -2026-03-07
CVE-2026-2431 WordPress plugin CM Custom Reports 跨站脚本漏洞 — CM Custom Reports – Flexible reporting to track what matters mostCWE-79 6.1 Medium2026-03-07
CVE-2026-1650 WordPress plugin MDJM Event Management 安全漏洞 — MDJM Event ManagementCWE-862 5.3 Medium2026-03-07
CVE-2026-2494 WordPress plugin ProfileGrid – User Profiles, Groups and Communities 跨站请求伪造漏洞 — ProfileGrid – User Profiles, Groups and CommunitiesCWE-352 4.3 Medium2026-03-07
CVE-2025-14353 WordPress plugin ZIP Code Based Content Protection SQL注入漏洞 — ZIP Code Based Content ProtectionCWE-89 7.5 High2026-03-07
CVE-2026-25071 XikeStor SKS8310-8X 访问控制错误漏洞 — XikeStor SKS8310-8XCWE-306 5.3 -2026-03-07
CVE-2026-25070 XikeStor SKS8310-8X 操作系统命令注入漏洞 — XikeStor SKS8310-8XCWE-78 9.8 -2026-03-07
CVE-2026-1644 WordPress plugin WP Frontend Profile 跨站请求伪造漏洞 — WP Frontend ProfileCWE-352 4.3 Medium2026-03-06
CVE-2026-2371 WordPress plugin Greenshift – animation and page builder blocks 安全漏洞 — Greenshift – animation and page builder blocksCWE-862 5.3 Medium2026-03-06
CVE-2026-30244 Plane 访问控制错误漏洞 — planeCWE-284 7.5 High2026-03-06
CVE-2026-30231 Flare 安全漏洞 — FlareCWE-639 6.5 -2026-03-06
CVE-2026-30846 WeKan 访问控制错误漏洞 — WekanCWE-306 7.5 -2026-03-06
CVE-2026-30845 WeKan 安全漏洞 — WekanCWE-200 7.5 -2026-03-06

access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 19704 条 CVE 漏洞。