access:pre-auth 类型相关 24857 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。
“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-1061 | WordPress plugin Nextend Social Login Pro 安全漏洞 — Nextend Social Login Pro CWE-288 | 9.8 | Critical | 2025-02-07 |
| CVE-2025-0675 | Elber Communications Equipment 安全漏洞 — Signum DVB-S/S2 IRD CWE-912 | 7.5 | High | 2025-02-06 |
| CVE-2024-52892 | IBM Jazz for Service Management 跨站脚本漏洞 — Jazz for Service Management CWE-79 | 6.1 | Medium | 2025-02-06 |
| CVE-2025-24786 | WhoDB 安全漏洞 — whodb CWE-35 | 10.0 | Critical | 2025-02-06 |
| CVE-2024-37358 | Apache James 输入验证错误漏洞 — Apache James server CWE-770 | 8.6 | High | 2025-02-06 |
| CVE-2024-13487 | WordPress plugin CURCY 代码注入漏洞 — CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x CWE-94 | 7.3 | High | 2025-02-06 |
| CVE-2025-23094 | Mitel OpenScape 4000和OpenScape 4000 Manager 安全漏洞 — n/a | 9.8 | - | 2025-02-06 |
| CVE-2025-20183 | Cisco Secure Web Appliance 输入验证错误漏洞 — Cisco Secure Web Appliance CWE-20 | 5.8 | Medium | 2025-02-05 |
| CVE-2025-20179 | Cisco Expressway Series 跨站脚本漏洞 — Cisco TelePresence Video Communication Server (VCS) Expressway CWE-79 | 6.1 | Medium | 2025-02-05 |
| CVE-2024-13829 | WordPress plugin Tripetto 信息泄露漏洞 — WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto CWE-200 | 5.3 | Medium | 2025-02-05 |
| CVE-2025-1028 | WordPress plugin Contact Manager 代码问题漏洞 — Contact Manager CWE-434 | 8.1 | High | 2025-02-05 |
| CVE-2025-25246 | NETGEAR XR1000和NETGEAR XR500 安全漏洞 — XR1000 CWE-94 | 8.1 | High | 2025-02-05 |
| CVE-2024-13722 | NagVis 安全漏洞 — NagVis CWE-79 | 6.1 | - | 2025-02-04 |
| CVE-2024-40700 | IBM Security Verify Access 跨站脚本漏洞 — Security Verify Access Appliance CWE-79 | 6.1 | Medium | 2025-02-04 |
| CVE-2025-0364 | BigAntSoft BigAnt Server 安全漏洞 — BigAnt Server CWE-288 | 9.8 | Critical | 2025-02-04 |
| CVE-2024-9644 | Four-Faith F3x36 安全漏洞 — F3x36 CWE-489 | 9.8 | Critical | 2025-02-04 |
| CVE-2024-13510 | WordPress plugin ShopSite 跨站请求伪造漏洞 — ShopSite CWE-352 | 6.1 | Medium | 2025-02-04 |
| CVE-2024-13356 | WordPress plugin DSGVO All in one for WP 跨站请求伪造漏洞 — DSGVO All in one for WP CWE-352 | 6.5 | Medium | 2025-02-04 |
| CVE-2025-0466 | WordPress plugin Sensei LMS 安全漏洞 — Sensei LMS | 5.3 | - | 2025-02-04 |
| CVE-2025-0368 | WordPress plugin Banner Garden Plugin 安全漏洞 — Banner Garden Plugin for WordPress | 6.1 | - | 2025-02-04 |
| CVE-2025-0148 | Zoom Jenkins Marketplace plugin 安全漏洞 — Zoom Jenkins Marketplace plugin CWE-549 | 2.6 | Low | 2025-02-03 |
| CVE-2024-11133 | WordPress plugin Eventer 安全漏洞 — Eventer - WordPress Event & Booking Manager Plugin CWE-862 | 5.3 | Medium | 2025-02-03 |
| CVE-2024-13371 | WordPress plugin WP Job Portal 安全漏洞 — WP Job Portal – AI-Powered Recruitment System for Company or Job Board website CWE-862 | 5.3 | Medium | 2025-02-01 |
| CVE-2024-13372 | WordPress plugin WP Job Portal 安全漏洞 — WP Job Portal – AI-Powered Recruitment System for Company or Job Board website CWE-639 | 5.3 | Medium | 2025-02-01 |
| CVE-2024-13428 | WordPress plugin WP Job Portal 安全漏洞 — WP Job Portal – AI-Powered Recruitment System for Company or Job Board website CWE-639 | 5.3 | Medium | 2025-02-01 |
| CVE-2024-12041 | WordPress plugin Directorist 安全漏洞 — Directorist: AI-Powered Business Directory, Listings & Classified Ads CWE-359 | 5.3 | Medium | 2025-02-01 |
| CVE-2024-12184 | WordPress plugin WordPress Contact Forms by Cimatti 安全漏洞 — Contact Forms by Cimatti CWE-862 | 5.3 | Medium | 2025-02-01 |
| CVE-2024-12620 | WordPress plugin AnimateGL Animations for WordPress 安全漏洞 — AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations CWE-862 | 5.3 | Medium | 2025-02-01 |
| CVE-2024-12415 | WordPress plugin The AI Infographic Maker 代码注入漏洞 — AI Infographic Maker CWE-94 | 6.5 | Medium | 2025-01-31 |
| CVE-2024-12267 | WordPress plugin Contact Form 安全漏洞 — Drag and Drop Multiple File Upload for Contact Form 7 CWE-73 | 5.3 | Medium | 2025-01-31 |
access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 24857 条 CVE 漏洞。