目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

access:pre-auth 标签下的 CVE 漏洞 24858

access:pre-auth 类型相关 24858 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。

“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。

CVE ID 标题 CVSS 风险等级 Published
CVE-2025-29266 Unraid 安全漏洞 — Unraid CWE-289 9.6 Critical 2025-03-31
CVE-2024-13804 Hewlett Packard Enterprise Insight Cluster Management Utility 安全漏洞 — HPE Insight Cluster Management Utility (CMU) 8.8 - 2025-03-30
CVE-2024-13557 WordPress plugin Shortcodes by United Themes 代码注入漏洞 — Shortcodes by United Themes CWE-94 6.5 Medium 2025-03-29
CVE-2025-2006 WordPress plugin Inline Image Upload for BBPress 代码问题漏洞 — Inline Image Upload for BBPress CWE-434 8.8 High 2025-03-29
CVE-2025-2266 WordPress plugin Checkout Mestres do WP for WooCommerce 安全漏洞 — Checkout Mestres do WP for WooCommerce CWE-862 9.8 Critical 2025-03-29
CVE-2025-2803 WordPress plugin So-Called Air Quotes 代码注入漏洞 — So-Called Air Quotes CWE-94 7.3 High 2025-03-29
CVE-2025-2840 WordPress plugin DAP to Autoresponders Email Syncing 信息泄露漏洞 — DAP to Autoresponders Email Syncing CWE-200 5.3 Medium 2025-03-29
CVE-2025-2863 Arteche saTECH BCU 跨站请求伪造漏洞 — saTECH BCU CWE-352 8.8 - 2025-03-28
CVE-2021-24008 Fortinet多款产品 信息泄露漏洞 — FortiDDoS CWE-200 5.0 Medium 2025-03-28
CVE-2025-1705 WordPress plugin tagDiv Composer 跨站脚本漏洞 — tagDiv Composer CWE-79 6.1 Medium 2025-03-28
CVE-2025-2578 WordPress plugin Booking for Appointments and Events Calendar Amelia 信息泄露漏洞 — Booking for Appointments and Events Calendar – Amelia CWE-200 5.3 Medium 2025-03-28
CVE-2025-2485 WordPress plugin Drag and Drop Multiple File Upload for Contact Form 代码问题漏洞 — Drag and Drop Multiple File Upload for Contact Form 7 CWE-502 7.5 High 2025-03-28
CVE-2025-2328 WordPress plugin Drag and Drop Multiple File Upload for Contact Form 路径遍历漏洞 — Drag and Drop Multiple File Upload for Contact Form 7 CWE-22 8.8 High 2025-03-28
CVE-2025-2804 WordPress plugin tagDiv Composer 跨站脚本漏洞 — tagDiv Composer CWE-79 6.1 Medium 2025-03-28
CVE-2025-2294 WordPress plugin Kubio AI Page Builder 路径遍历漏洞 — Kubio AI Page Builder CWE-22 9.8 Critical 2025-03-28
CVE-2025-24381 Dell Unity 输入验证错误漏洞 — Unity CWE-601 8.8 High 2025-03-28
CVE-2024-49601 Dell Unity 操作系统命令注入漏洞 — Unity CWE-78 7.3 High 2025-03-28
CVE-2025-24382 Dell Unity 操作系统命令注入漏洞 — Unity CWE-78 7.3 High 2025-03-28
CVE-2025-22398 Dell Unity 操作系统命令注入漏洞 — Unity CWE-78 9.8 Critical 2025-03-28
CVE-2025-24383 Dell Unity 安全漏洞 — Unity CWE-78 9.1 Critical 2025-03-28
CVE-2025-2332 WordPress plugin Export All Posts, Products, Orders, Refunds & Users 代码问题漏洞 — Export All Posts, Products, Orders, Refunds & Users CWE-502 9.8 Critical 2025-03-27
CVE-2025-2481 WordPress plugin MediaView 跨站脚本漏洞 — MediaView CWE-79 6.1 Medium 2025-03-27
CVE-2025-28138 TOTOLINK A810R 安全漏洞 — n/a 9.8AI Critical AI 2025-03-27
CVE-2025-1440 WordPress plugin Advanced iFrame 输入验证错误漏洞 — Advanced iFrame CWE-20 5.3 Medium 2025-03-26
CVE-2025-1514 WordPress plugin Active Products Tables for WooCommerce 输入验证错误漏洞 — Active Products Tables for WooCommerce. Use constructor to create tables CWE-20 7.3 High 2025-03-26
CVE-2025-2009 WordPress plugin Newsletters 跨站脚本漏洞 — Newsletters CWE-79 7.2 High 2025-03-26
CVE-2025-1490 WordPress plugin Smart Maintenance Mode 跨站脚本漏洞 — Smart Maintenance Mode CWE-79 6.1 Medium 2025-03-26
CVE-2025-2165 WordPress plugin SH Email Alert 跨站脚本漏洞 — SH Email Alert CWE-79 6.1 Medium 2025-03-26
CVE-2025-2109 WordPress plugin WP Compress 代码问题漏洞 — WP Compress – Instant Performance & Speed Optimization CWE-918 5.8 Medium 2025-03-25
CVE-2025-2635 WordPress plugin Digital License Manager 跨站脚本漏洞 — Digital License Manager CWE-79 6.1 Medium 2025-03-25

access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 24858 条 CVE 漏洞。