access:pre-auth 类型相关 24931 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。
“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-11754 | WordPress plugin GDPR Cookie Consent 安全漏洞 — Cookie Banner for GDPR / CCPA – WPLP Cookie Consent CWE-862 | 7.5 | High | 2026-02-19 |
| CVE-2025-12172 | WordPress plugin Mailchimp List Subscribe Form 跨站请求伪造漏洞 — Mailchimp List Subscribe Form CWE-352 | 4.3 | Medium | 2026-02-19 |
| CVE-2025-11706 | WordPress plugin Aruba HiSpeed Cache 跨站脚本漏洞 — Aruba HiSpeed Cache CWE-79 | 6.1 | Medium | 2026-02-19 |
| CVE-2025-11725 | WordPress plugin Aruba HiSpeed Cache 安全漏洞 — Aruba HiSpeed Cache CWE-862 | 6.5 | Medium | 2026-02-19 |
| CVE-2026-25242 | Gogs 安全漏洞 — gogs CWE-862 | 9.8 | - | 2026-02-19 |
| CVE-2026-26744 | FormaLMS 安全漏洞 — n/a | 5.3AI | Medium AI | 2026-02-19 |
| CVE-2019-25355 | Genivia gSOAP 路径遍历漏洞 — gSOAP CWE-22 | 7.5 | High | 2026-02-18 |
| CVE-2026-27181 | MajorDoMo 安全漏洞 — MajorDoMo CWE-862 | 7.5 | High | 2026-02-18 |
| CVE-2026-27180 | MajorDoMo 安全漏洞 — MajorDoMo CWE-494 | 9.8 | Critical | 2026-02-18 |
| CVE-2026-27179 | MajorDoMo SQL注入漏洞 — MajorDoMo CWE-89 | 8.2 | High | 2026-02-18 |
| CVE-2026-27177 | MajorDoMo 跨站脚本漏洞 — MajorDoMo CWE-79 | 7.2 | High | 2026-02-18 |
| CVE-2026-27178 | MajorDoMo 跨站脚本漏洞 — MajorDoMo CWE-79 | 7.2 | High | 2026-02-18 |
| CVE-2026-27175 | MajorDoMo 操作系统命令注入漏洞 — MajorDoMo CWE-78 | 9.8 | Critical | 2026-02-18 |
| CVE-2026-27174 | MajorDoMo 代码注入漏洞 — MajorDoMo CWE-94 | 9.8 | Critical | 2026-02-18 |
| CVE-2026-27182 | Saturn Remote Mouse Server 访问控制错误漏洞 — Saturn Remote Mouse Server CWE-306 | 8.4 | High | 2026-02-18 |
| CVE-2026-23491 | InvoicePlane 路径遍历漏洞 — InvoicePlane CWE-22 | 7.5 | - | 2026-02-18 |
| CVE-2026-1404 | WordPress plugin Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 跨站脚本漏洞 — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin CWE-79 | 6.1 | Medium | 2026-02-18 |
| CVE-2026-2329 | Grandstream GXP series 安全漏洞 — GXP1610 CWE-121 | 9.8 | - | 2026-02-18 |
| CVE-2026-2464 | AMR Printer Management 路径遍历漏洞 — AMR Printer Management Beta web service CWE-22 | 7.5AI | High AI | 2026-02-18 |
| CVE-2026-1582 | WordPress plugin WP All Export 信息泄露漏洞 — WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel CWE-200 | 3.7 | Low | 2026-02-18 |
| CVE-2025-14799 | WordPress plugin Brevo - Email, SMS, Web Push, Chat, and more 安全漏洞 — Brevo – Email, SMS, Web Push, Chat, and more. CWE-843 | 6.5 | Medium | 2026-02-18 |
| CVE-2025-14444 | WordPress plugin RegistrationMagic 数据伪造问题漏洞 — RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login CWE-345 | 5.3 | Medium | 2026-02-18 |
| CVE-2026-2126 | WordPress plugin User Submitted Posts – Enable Users to Submit Posts from the Front End 安全漏洞 — User Submitted Posts – Enable Users to Submit Posts from the Front End CWE-863 | 5.3 | Medium | 2026-02-18 |
| CVE-2026-1656 | WordPress plugin Business Directory Plugin 安全漏洞 — Business Directory Plugin – Easy Listing Directories for WordPress CWE-862 | 5.3 | Medium | 2026-02-18 |
| CVE-2026-2495 | WordPress plugin WPNakama SQL注入漏洞 — WPNakama – Team and multi-Client Collaboration, Editorial and Project Management CWE-89 | 7.5 | High | 2026-02-18 |
| CVE-2026-2112 | WordPress plugin Dam Spam 跨站请求伪造漏洞 — Dam Spam CWE-352 | 4.3 | Medium | 2026-02-18 |
| CVE-2026-1666 | WordPress plugin Download Manager 跨站脚本漏洞 — Download Manager CWE-79 | 6.1 | Medium | 2026-02-18 |
| CVE-2026-1368 | WordPress plugin Video Conferencing with Zoom 安全漏洞 — Video Conferencing with Zoom | 7.5AI | High AI | 2026-02-18 |
| CVE-2026-1072 | WordPress plugin Keybase.io Verification 跨站请求伪造漏洞 — Keybase.io Verification CWE-352 | 4.3 | Medium | 2026-02-18 |
| CVE-2026-2023 | WordPress plugin WP Plugin Info Card 跨站请求伪造漏洞 — WP Plugin Info Card CWE-352 | 4.3 | Medium | 2026-02-18 |
access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 24931 条 CVE 漏洞。