目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

access:pre-auth 标签下的 CVE 漏洞 24864

access:pre-auth 类型相关 24864 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。

“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。

CVE ID 标题 CVSS 风险等级 Published
CVE-2025-52362 phproxy 安全漏洞 — n/a 9.1 - 2025-07-21
CVE-2020-26799 LuxSoft Luxcal 安全漏洞 — n/a 6.1 - 2025-07-21
CVE-2025-7858 PHPGurukul Apartment Visitors Management System 代码注入漏洞 — Apartment Visitors Management System CWE-79 3.5 Low 2025-07-19
CVE-2015-10138 WordPress plugin Work The Flow File Upload 代码问题漏洞 — Work The Flow File Upload CWE-434 9.8 Critical 2025-07-19
CVE-2012-10019 WordPress plugin Front End Editor 代码问题漏洞 — Front-end Editor CWE-434 9.8 Critical 2025-07-19
CVE-2015-10135 WordPress plugin WPshop 2 – E-Commerce 代码问题漏洞 — WPshop 2 – E-Commerce CWE-434 9.8 Critical 2025-07-19
CVE-2015-10136 WordPress plugin GI-Media Library 路径遍历漏洞 — GI-Media Library CWE-22 7.5 High 2025-07-19
CVE-2016-15043 WordPress plugin WP Mobile Detector 代码问题漏洞 — WP Mobile Detector CWE-434 9.8 Critical 2025-07-19
CVE-2025-6720 WordPress plugin Vchasno Kasa 安全漏洞 — MORKVA Vchasno Kasa Integration CWE-862 5.3 Medium 2025-07-19
CVE-2025-6721 WordPress plugin Vchasno Kasa 安全漏洞 — MORKVA Vchasno Kasa Integration CWE-862 5.3 Medium 2025-07-19
CVE-2025-7697 WordPress plugin Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms 代码问题漏洞 — Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms CWE-502 9.8 Critical 2025-07-19
CVE-2025-7696 WordPress plugin Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms 代码问题漏洞 — Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms CWE-502 9.8 Critical 2025-07-19
CVE-2025-7669 WordPress plugin Avishi WP PayPal Payment Button 跨站请求伪造漏洞 — Avishi WP PayPal Payment Button CWE-352 6.1 Medium 2025-07-19
CVE-2025-50057 RSJoomla! RSFiles! component for Joomla 资源管理错误漏洞 — RSFiles! component for Joomla CWE-400 7.5 - 2025-07-18
CVE-2025-7444 WordPress plugin LoginPress Pro 安全漏洞 — LoginPress Pro CWE-288 9.8 Critical 2025-07-18
CVE-2025-5811 WordPress plugin Listly: Listicles For WordPress 安全漏洞 — Listly: Listicles For WordPress CWE-862 5.3 Medium 2025-07-18
CVE-2025-7643 WordPress plugin Attachment Manager 路径遍历漏洞 — Attachment Manager CWE-22 9.1 Critical 2025-07-18
CVE-2025-6222 WordPress plugin WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet 代码问题漏洞 — WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet CWE-434 9.8 Critical 2025-07-18
CVE-2025-6053 WordPress plugin Zuppler Online Ordering 跨站请求伪造漏洞 — Zuppler Online Ordering CWE-352 6.1 Medium 2025-07-18
CVE-2025-6781 WordPress plugin Copymatic – AI Content Writer & Generator 跨站请求伪造漏洞 — Copymatic – AI Content Writer & Generator CWE-352 4.3 Medium 2025-07-18
CVE-2025-52168 Agorum core open 安全漏洞 — n/a 7.5 - 2025-07-18
CVE-2025-54068 Livewire 代码注入漏洞 — livewire CWE-94 9.8AI Critical AI 2025-07-17
CVE-2025-25257 Fortinet FortiWeb SQL注入漏洞 — FortiWeb CWE-89 9.6 Critical 2025-07-17
CVE-2025-7735 UNIMAX Hospital Information System SQL注入漏洞 — Hospital Information System CWE-89 7.5 High 2025-07-17
CVE-2025-7712 WordPress plugin Madara - Core 路径遍历漏洞 — Madara - Core CWE-22 9.1 Critical 2025-07-17
CVE-2025-5396 WordPress plugin Bears Backup 代码注入漏洞 — Bears Backup CWE-94 9.8 Critical 2025-07-17
CVE-2025-52046 TOTOLINK A3300R 安全漏洞 — n/a 9.8AI Critical AI 2025-07-17
CVE-2025-34130 LILIN Digital Video Recorder 安全漏洞 — DVR Firmware CWE-306 9.8AI Critical AI 2025-07-16
CVE-2025-34125 D-Link DSP-W110A1 安全漏洞 — DSP-W110A1 CWE-78 9.8AI Critical AI 2025-07-16
CVE-2025-34121 Idera Up.Time Monitoring Station 安全漏洞 — Up.Time Monitoring Station CWE-434 9.3 Critical 2025-07-16

access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 24864 条 CVE 漏洞。