access:pre-auth 类型相关 24850 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。
“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-13179 | Ivanti Avalanche 安全漏洞 — Avalanche CWE-22 | 7.3 | High | 2025-01-14 |
| CVE-2024-39363 | WAVLINK AC3000 安全漏洞 — Wavlink AC3000 CWE-80 | 9.6 | Critical | 2025-01-14 |
| CVE-2024-39760 | WAVLINK AC3000 命令注入漏洞 — Wavlink AC3000 CWE-77 | 10.0 | Critical | 2025-01-14 |
| CVE-2024-39761 | WAVLINK AC3000 命令注入漏洞 — Wavlink AC3000 CWE-77 | 10.0 | Critical | 2025-01-14 |
| CVE-2024-36290 | WAVLINK AC3000 安全漏洞 — Wavlink AC3000 CWE-120 | 10.0 | Critical | 2025-01-14 |
| CVE-2024-39759 | WAVLINK AC3000 命令注入漏洞 — Wavlink AC3000 CWE-77 | 10.0 | Critical | 2025-01-14 |
| CVE-2024-39608 | WAVLINK AC3000 访问控制错误漏洞 — Wavlink AC3000 CWE-306 | 10.0 | Critical | 2025-01-14 |
| CVE-2024-23106 | Fortinet FortiClientEMS 安全漏洞 — FortiClientEMS CWE-307 | 7.7 | High | 2025-01-14 |
| CVE-2024-46666 | Fortinet FortiOS 安全漏洞 — FortiOS CWE-770 | 4.8 | Medium | 2025-01-14 |
| CVE-2024-36510 | Fortinet FortiClientEMS和FortiSOAR 安全漏洞 — FortiClientEMS CWE-204 | 4.9 | Medium | 2025-01-14 |
| CVE-2024-54021 | Fortinet FortiOS和Fortinet FortiProxy 注入漏洞 — FortiOS CWE-113 | 6.4 | Medium | 2025-01-14 |
| CVE-2024-48884 | Fortinet多款产品 路径遍历漏洞 — FortiManager CWE-22 | 7.1 | High | 2025-01-14 |
| CVE-2024-46668 | Fortinet FortiOS 安全漏洞 — FortiOS CWE-770 | 7.1 | High | 2025-01-14 |
| CVE-2024-46670 | Fortinet FortiOS 缓冲区错误漏洞 — FortiOS CWE-125 | 7.5 | High | 2025-01-14 |
| CVE-2024-56841 | Siemens Mendix 注入漏洞 — Mendix LDAP CWE-90 | 7.4 | High | 2025-01-14 |
| CVE-2024-47100 | Siemens SIMATIC S7-1200 跨站请求伪造漏洞 — SIMATIC S7-1200 CPU 1211C AC/DC/Rly CWE-352 | 7.1 | High | 2025-01-14 |
| CVE-2024-12919 | WordPress plugin Paid Membership Subscriptions 授权问题漏洞 — Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction CWE-287 | 9.8 | Critical | 2025-01-14 |
| CVE-2025-0393 | WordPress plugin Royal Elementor Addons and Templates 跨站请求伪造漏洞 — Royal Addons for Elementor – Addons and Templates Kit for Elementor CWE-352 | 6.1 | Medium | 2025-01-14 |
| CVE-2024-12006 | WordPress plugin W3 Total Cache 安全漏洞 — W3 Total Cache CWE-862 | 5.3 | Medium | 2025-01-14 |
| CVE-2024-12008 | WordPress plugin W3 Total Cache 信息泄露漏洞 — W3 Total Cache CWE-200 | 5.3 | Medium | 2025-01-14 |
| CVE-2025-23082 | Veeam Backup 代码问题漏洞 — Backup for Microsoft Azure | 6.5 | - | 2025-01-14 |
| CVE-2025-0061 | SAP BusinessObjects Business Intelligence Platform 安全漏洞 — SAP BusinessObjects Business Intelligence Platform CWE-497 | 8.7 | High | 2025-01-14 |
| CVE-2025-0053 | SAP NetWeaver Application Server 安全漏洞 — SAP NetWeaver Application Server for ABAP and ABAP Platform CWE-209 | 5.3 | Medium | 2025-01-14 |
| CVE-2025-22983 | IceCMS 安全漏洞 — n/a | 7.5 | - | 2025-01-14 |
| CVE-2025-22984 | IceCMS 安全漏洞 — n/a | 7.5 | - | 2025-01-14 |
| CVE-2024-11396 | WordPress plugin Event Monster 安全漏洞 — Event Monster – Manager & Ticket Booking CWE-359 | 5.3 | Medium | 2025-01-13 |
| CVE-2024-12274 | WordPress plugin Appointment Booking Calendar 安全漏洞 — Appointment Booking Calendar Plugin and Scheduling Plugin | 7.5 | - | 2025-01-13 |
| CVE-2024-46310 | Cfx.re FXServer 安全漏洞 — n/a | 9.1 | - | 2025-01-13 |
| CVE-2024-12407 | WordPress plugin Push Notification for Post and BuddyPress 跨站脚本漏洞 — Push Notification for Post and BuddyPress CWE-79 | 6.1 | Medium | 2025-01-11 |
| CVE-2024-12877 | WordPress plugin GiveWP 代码问题漏洞 — GiveWP – Donation Plugin and Fundraising Platform CWE-502 | 9.8 | Critical | 2025-01-11 |
access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 24850 条 CVE 漏洞。