目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

access:pre-auth 标签下的 CVE 漏洞 24858

access:pre-auth 类型相关 24858 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。

“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。

CVE ID 标题 CVSS 风险等级 Published
CVE-2024-13871 Bitdefender Box 命令注入漏洞 — BOX v1 CWE-77 8.8 - 2025-03-12
CVE-2024-13872 Bitdefender BOX 安全漏洞 — BOX v1 CWE-319 7.5 - 2025-03-12
CVE-2024-13446 WordPress plugin Workreap 安全漏洞 — Workreap CWE-288 9.8 Critical 2025-03-12
CVE-2024-13498 WordPress plugin NEX-Forms – Ultimate Form Builder – Contact forms and much more 信息泄露漏洞 — NEX-Forms – Ultimate Forms Plugin for WordPress CWE-200 5.3 Medium 2025-03-12
CVE-2025-2077 WordPress plugin Simple Amazon Affiliate 跨站脚本漏洞 — Simple Amazon Affiliate CWE-79 6.1 Medium 2025-03-12
CVE-2025-25683 AlekSIS-Core 安全漏洞 — n/a 5.3 - 2025-03-12
CVE-2023-48790 Fortinet FortiNDR 跨站请求伪造漏洞 — FortiNDR CWE-352 7.1 High 2025-03-11
CVE-2024-52285 Siemens SiPass Integrated 访问控制错误漏洞 — SiPass integrated AC5102 (ACC-G2) CWE-306 5.3 Medium 2025-03-11
CVE-2024-13413 WordPress plugin ProductDyno 跨站脚本漏洞 — ProductDyno CWE-79 6.1 Medium 2025-03-11
CVE-2024-13436 WordPress plugin Appsero Helper 跨站请求伪造漏洞 — Appsero Helper CWE-352 6.1 Medium 2025-03-11
CVE-2025-2169 WordPress plugin WPCS 代码注入漏洞 — WPCS – WordPress Currency Switcher Professional CWE-94 7.3 High 2025-03-11
CVE-2025-1661 WordPress plugin HUSKY Products Filter Professional for WooCommerce 路径遍历漏洞 — HUSKY – Products Filter Professional for WooCommerce CWE-22 9.8 Critical 2025-03-11
CVE-2025-27434 SAP Commerce 跨站脚本漏洞 — SAP Commerce (Swagger UI) CWE-79 8.8 High 2025-03-11
CVE-2024-11638 WordPress plugin Gtbabel 安全漏洞 — Gtbabel 8.1 - 2025-03-10
CVE-2025-1926 WordPress plugin Page Builder: Pagelayer 跨站请求伪造漏洞 — Page Builder: Pagelayer – Drag and Drop website builder CWE-352 4.3 Medium 2025-03-10
CVE-2024-43107 Gallagher Milestone Integration Plugin 信任管理问题漏洞 — Milestone Integration Plugin CWE-295 7.2 High 2025-03-10
CVE-2024-13924 WordPress plugin Starter Templates by FancyWP 代码问题漏洞 — Starter Templates by FancyWP CWE-918 5.3 Medium 2025-03-08
CVE-2024-11640 WordPress plugin VikRentCar Car Rental Management System 跨站请求伪造漏洞 — VikRentCar Car Rental Management System CWE-352 8.8 High 2025-03-08
CVE-2025-1322 WordPress plugin WP-Recall 信息泄露漏洞 — WP-Recall – Registration, Profile, Commerce & More CWE-200 4.3 Medium 2025-03-08
CVE-2025-1323 WordPress plugin WP-Recall SQL注入漏洞 — WP-Recall – Registration, Profile, Commerce & More CWE-89 7.5 High 2025-03-08
CVE-2024-13359 WordPress plugin Product Input Fields for WooCommerce 代码问题漏洞 — Product Input Fields for WooCommerce CWE-434 8.1 High 2025-03-08
CVE-2025-0177 WordPress plugin Javo Core 安全漏洞 — Javo Core CWE-269 9.8 Critical 2025-03-08
CVE-2024-11087 WordPress plugin miniOrange Social Login and Register 授权问题漏洞 — miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) CWE-287 8.1 High 2025-03-08
CVE-2024-13640 WordPress plugin Print Invoice & Delivery Notes for WooCommerce 信息泄露漏洞 — Print Invoice & Delivery Notes for WooCommerce CWE-200 5.9 Medium 2025-03-08
CVE-2024-13774 WordPress plugin Wishlist for WooCommerce 跨站请求伪造漏洞 — Wishlist for WooCommerce: Multi Wishlists Per Customer CWE-352 6.1 Medium 2025-03-08
CVE-2024-12634 WordPress plugin Related Posts 跨站请求伪造漏洞 — Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins CWE-352 6.1 Medium 2025-03-07
CVE-2024-13552 WordPress plugin SupportCandy 授权问题漏洞 — SupportCandy – Helpdesk & Customer Support Ticket System CWE-285 4.3 Medium 2025-03-07
CVE-2025-1315 WordPress plugin InWave Jobs 安全漏洞 — InWave Jobs CWE-288 9.8 Critical 2025-03-07
CVE-2024-12876 WordPress plugin Golo - City Travel Guide WordPress Theme 安全漏洞 — Golo - City Travel Guide WordPress Theme CWE-862 9.8 Critical 2025-03-07
CVE-2024-13431 WordPress plugin Appointment Booking Calendar 跨站脚本漏洞 — Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin CWE-79 6.1 Medium 2025-03-07

access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 24858 条 CVE 漏洞。