access:pre-auth 类型相关 19065 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。
“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2022-1951 | WordPress core plugin for kitestudio 跨站脚本漏洞 — core plugin for kitestudio themesCWE-79 | 6.1 | - | 2022-07-11 |
| CVE-2022-1938 | WordPress plugin Awin Data Feed 跨站脚本漏洞 — Awin Data FeedCWE-79 | 5.4 | - | 2022-07-11 |
| CVE-2022-1937 | WordPress plugin Awin Data Feed 跨站脚本漏洞 — Awin Data FeedCWE-79 | 6.1 | - | 2022-07-11 |
| CVE-2022-1057 | WordPress plugin Pricing Deals for WooCommerce SQL注入漏洞 — Pricing Deals for WooCommerceCWE-89 | 9.8 | - | 2022-07-11 |
| CVE-2022-35411 | rpc.py 代码问题漏洞 — n/a | 9.8 | - | 2022-07-08 |
| CVE-2021-46825 | Symantec Advanced Secure Gateway 环境问题漏洞 — Advance Secure Gateway and ProxySG | 5.3 | - | 2022-07-07 |
| CVE-2022-20815 | Cisco Unified Communications Manager 跨站脚本漏洞 — Cisco Unified Communications ManagerCWE-79 | 6.1 | Medium | 2022-07-06 |
| CVE-2022-20800 | Cisco Unified Communications Manager 跨站脚本漏洞 — Cisco Unity ConnectionCWE-79 | 6.1 | Medium | 2022-07-06 |
| CVE-2022-20752 | Cisco Unified Communications Manager 和 Cisco Unity Connection安全漏洞 — Cisco Unified Communications ManagerCWE-208 | 5.3 | Medium | 2022-07-06 |
| CVE-2022-31126 | Roxy-WI 注入漏洞 — roxy-wiCWE-74 | 10.0 | Critical | 2022-07-06 |
| CVE-2022-31125 | Roxy-WI 授权问题漏洞 — roxy-wiCWE-287 | 10.0 | Critical | 2022-07-06 |
| CVE-2022-1946 | WordPress plugin Gallery 跨站脚本漏洞 — Gallery – Image and Video Gallery with ThumbnailsCWE-79 | 6.1 | - | 2022-07-04 |
| CVE-2021-37524 | FusionPBX 跨站脚本漏洞 — n/a | 6.1 | - | 2022-07-01 |
| CVE-2022-1963 | GitLab 信息泄露漏洞 — GitLab | 5.3 | Medium | 2022-07-01 |
| CVE-2022-1953 | WordPress plugin WooCommerce 路径遍历漏洞 — Product Configurator for WooCommerceCWE-22 | 9.1 | - | 2022-06-27 |
| CVE-2022-1916 | WordPress plugin Active Products Tables for WooCommerce 跨站脚本漏洞 — Active Products Tables for WooCommerce. Professional products tables for WooCommerce storeCWE-79 | 6.1 | - | 2022-06-27 |
| CVE-2022-1904 | WordPress plugin Pricing Tables 跨站脚本漏洞 — Pricing Tables WordPress Plugin – Easy Pricing TablesCWE-79 | 6.1 | - | 2022-06-27 |
| CVE-2022-1903 | WordPress plugin ARMember 安全漏洞 — ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signupCWE-862 | 8.1 | - | 2022-06-27 |
| CVE-2022-1574 | WordPress plugin HTML2WP 代码问题漏洞 — HTML2WP | 9.8 | - | 2022-06-27 |
| CVE-2022-0444 | WordPress plugin XCloner 安全漏洞 — Backup, Restore and Migrate WordPress Sites With the XCloner Plugin | 4.3 | - | 2022-06-27 |
| CVE-2022-2105 | Secheron SEPCOS Control and Protection Relay 安全漏洞 — SEPCOS Control and Protection Relay firmware packageCWE-841 | 9.4 | Critical | 2022-06-24 |
| CVE-2022-1517 | Illumina Local Run Manager 代码注入漏洞 — NextSeq 550DxCWE-250 | 10.0 | Critical | 2022-06-24 |
| CVE-2022-23170 | Sysaid Technologies SysAid 代码问题漏洞 — SysAid - Okta SSO integrationCWE-611 | 5.9 | Medium | 2022-06-24 |
| CVE-2022-31804 | CODESYS Gateway Server安全漏洞 — CODESYS Gateway Server V2CWE-789 | 7.5 | High | 2022-06-24 |
| CVE-2022-31803 | CODESYS Gateway Server 资源管理错误漏洞 — CODESYS Gateway Server V2CWE-400 | 5.3 | Medium | 2022-06-24 |
| CVE-2022-31801 | 多款Phoenix Contact产品数据伪造问题漏洞 — MULTIPROGCWE-345 | 9.8 | Critical | 2022-06-21 |
| CVE-2022-31800 | 多款Phoenix Contact产品数据伪造问题漏洞 — ILC 1x0CWE-345 | 9.8 | Critical | 2022-06-21 |
| CVE-2022-1905 | WordPress plugin Events Made Easy SQL注入漏洞 — Events Made EasyCWE-89 | 9.8 | - | 2022-06-20 |
| CVE-2022-26668 | ASUS Control Center 安全漏洞 — Control CenterCWE-269 | 7.3 | High | 2022-06-20 |
| CVE-2022-21742 | Realtek USB driver 安全漏洞 — USB FE/1GbE/2.5GbE/5GbE NIC FamilyCWE-120 | 6.2 | Medium | 2022-06-20 |
access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 19065 条 CVE 漏洞。