目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1000

100.0%

access:pre-auth 标签下的 CVE 漏洞 19065

access:pre-auth 类型相关 19065 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。

“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。

CVE ID标题CVSS风险等级Published
CVE-2022-24796 RaspberryMatic 操作系统命令注入漏洞 — RaspberryMaticCWE-78 10.0 Critical2022-03-31
CVE-2021-46006 TotoLink A3100R 访问控制错误漏洞 — n/a 7.5 -2022-03-30
CVE-2021-46009 TotoLink A3100R 访问控制错误漏洞 — n/a 9.8 -2022-03-30
CVE-2022-26951 RSA Archer 跨站脚本漏洞 — n/a 6.5 Medium2022-03-29
CVE-2021-44082 Textpattern CMS 跨站脚本漏洞 — n/a 8.0 -2022-03-29
CVE-2022-26871 Trend Micro Apex Central 数据伪造问题漏洞 — Trend Micro Apex Central 9.8 -2022-03-29
CVE-2022-1078 SourceCodester College Website Management System SQL注入漏洞 — College Website Management SystemCWE-89 7.3 High2022-03-29
CVE-2022-0331 Sophos Firewall 信息泄露漏洞 — Sophos Firewall 5.3 Medium2022-03-29
CVE-2021-4191 GitLab Enterprise Edition和GitLab Community Edition 授权问题漏洞 — GitLab 5.3 Medium2022-03-28
CVE-2022-0846 WordPress plugin SpeakOut! Email Petitions SQL注入漏洞 — SpeakOut! Email PetitionsCWE-89 9.8 -2022-03-28
CVE-2022-0833 WordPress plugin Church Admin 安全漏洞 — Church Admin 4.3 -2022-03-28
CVE-2022-0818 WordPress plugin WooCommerce Affiliate 跨站脚本漏洞 — WooCommerce Affiliate Plugin – Coupon AffiliatesCWE-79 6.1 -2022-03-28
CVE-2022-0787 WordPress plugin Limit Login Attempts SQL注入漏洞 — Limit Login Attempts (Spam Protection)CWE-89 9.8 -2022-03-28
CVE-2022-0784 WordPress plugin Title Experiments Free SQL注入漏洞 — Title Experiments FreeCWE-89 9.8 -2022-03-28
CVE-2022-0680 WordPress plugin Plezi 跨站脚本漏洞 — PleziCWE-79 6.1 -2022-03-28
CVE-2022-0679 WordPress plugin Narnoo Distributor 路径遍历漏洞 — Narnoo DistributorCWE-22 9.8 -2022-03-28
CVE-2021-24978 WordPress plugin OSMapper 安全漏洞 — OSMapperCWE-862 7.5 -2022-03-28
CVE-2021-26598 ImpressCMS 授权问题漏洞 — n/a 5.3 -2022-03-28
CVE-2022-26254 Envato WoWonder 安全漏洞 — n/a 5.3 -2022-03-27
CVE-2022-26258 D-Link Dir-820L 操作系统命令注入漏洞 — n/a 9.8 -2022-03-27
CVE-2022-22274 SonicOS 缓冲区错误漏洞 — SonicOSCWE-121 9.8 -2022-03-25
CVE-2021-40906 CheckMK Raw Edition 跨站脚本漏洞 — n/a 4.7 -2022-03-25
CVE-2021-44905 Fortessa FTBTLD Smart Lock 安全漏洞 — n/a 5.3 -2022-03-25
CVE-2022-25610 WordPress plugin Simple Ajax Chat 跨站脚本漏洞 — Simple Ajax Chat (WordPress plugin)CWE-79 3.4 Low2022-03-25
CVE-2021-31326 D-Link DIR-816 A2 授权问题漏洞 — n/a 9.8 -2022-03-23
CVE-2022-27192 Aseco Lietuva document management system DVS Avilys 日志信息泄露漏洞 — n/a 7.5 -2022-03-23
CVE-2022-0888 WordPress plugin Ninja Forms - File Uploads Extension 安全漏洞 — Ninja Forms - File UploadsCWE-434 9.8 Critical2022-03-23
CVE-2022-0889 WordPress plugin Ninja Forms - File Uploads Extension 安全漏洞 — Ninja Forms - File UploadsCWE-79 7.2 High2022-03-23
CVE-2021-27476 Rockwell Automation FactoryTalk AssetCentre 操作系统命令注入漏洞 — FactoryTalk AssetCentreCWE-78 10.0 Critical2022-03-23
CVE-2021-27470 Rockwell Automation FactoryTalk AssetCentre 代码问题漏洞 — FactoryTalk AssetCentreCWE-502 10.0 Critical2022-03-23

access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 19065 条 CVE 漏洞。