access:pre-auth 类型相关 24808 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。
“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-9951 | WordPress plugin WP Photo Album Plus 跨站脚本漏洞 — WP Photo Album Plus CWE-79 | 6.1 | Medium | 2024-10-17 |
| CVE-2024-9213 | WordPress plugin Persian WooCommerce SMS 跨站脚本漏洞 — افزونه پیامک ووکامرس Persian WooCommerce SMS CWE-79 | 6.1 | Medium | 2024-10-17 |
| CVE-2024-9351 | WordPress plugin Forminator Forms 跨站请求伪造漏洞 — Forminator Forms – Contact Form, Payment Form & Custom Form Builder CWE-352 | 4.3 | Medium | 2024-10-17 |
| CVE-2024-9352 | WordPress plugin Forminator Forms 跨站请求伪造漏洞 — Forminator Forms – Contact Form, Payment Form & Custom Form Builder CWE-352 | 4.3 | Medium | 2024-10-17 |
| CVE-2024-8719 | WordPress plugin Flexmls® IDX Plugin 跨站脚本漏洞 — Flexmls® IDX Plugin CWE-79 | 6.1 | Medium | 2024-10-17 |
| CVE-2024-9347 | WordPress plugin The Ultimate WordPress Toolkit – WP Extended 跨站脚本漏洞 — The Ultimate WordPress Toolkit – WP Extended CWE-79 | 6.1 | Medium | 2024-10-17 |
| CVE-2024-9263 | WordPress plugin WP Timetics 安全漏洞 — Timetics – Appointment Booking & Scheduling CWE-639 | 9.8 | Critical | 2024-10-17 |
| CVE-2024-9863 | WordPress plugin UserPro 安全漏洞 — Miniorange OTP Verification with Firebase CWE-266 | 9.8 | Critical | 2024-10-17 |
| CVE-2024-9940 | WordPress plugin Calculated Fields Form 安全漏洞 — Calculated Fields Form CWE-75 | 5.3 | Medium | 2024-10-17 |
| CVE-2024-9240 | WordPress plugin ReDi Restaurant Reservation 安全漏洞 — ReDi Restaurant Reservation – Instant Availability & Confirmation CWE-79 | 6.1 | Medium | 2024-10-17 |
| CVE-2024-9862 | WordPress plugin Miniorange OTP Verification with Firebase 安全漏洞 — Miniorange OTP Verification with Firebase CWE-639 | 9.8 | Critical | 2024-10-17 |
| CVE-2024-9861 | WordPress plugin Miniorange OTP Verification with Firebase 安全漏洞 — Miniorange OTP Verification with Firebase CWE-288 | 8.1 | High | 2024-10-17 |
| CVE-2024-47836 | Admidio 代码问题漏洞 — admidio CWE-502 | 3.5 | Low | 2024-10-16 |
| CVE-2024-20512 | Cisco Unified Contact Center Management Portal 跨站脚本漏洞 — Cisco Unified Contact Center Management Portal CWE-79 | 6.1 | Medium | 2024-10-16 |
| CVE-2024-20463 | Cisco ATA 190 安全漏洞 — Cisco Analog Telephone Adaptor (ATA) Software CWE-305 | 5.4 | Medium | 2024-10-16 |
| CVE-2024-20460 | Cisco ATA 190 安全漏洞 — Cisco Analog Telephone Adaptor (ATA) Software CWE-80 | 6.1 | Medium | 2024-10-16 |
| CVE-2024-20458 | Cisco ATA 190 操作系统命令注入漏洞 — Cisco Analog Telephone Adaptor (ATA) Software CWE-78 | 8.2 | High | 2024-10-16 |
| CVE-2024-20421 | Cisco ATA 190 跨站请求伪造漏洞 — Cisco Analog Telephone Adaptor (ATA) Software CWE-352 | 7.1 | High | 2024-10-16 |
| CVE-2024-9893 | WordPress plugin Nextend Social Login Pro 安全漏洞 — Nextend Social Login Pro CWE-288 | 9.8 | Critical | 2024-10-16 |
| CVE-2020-36841 | WordPress plugin WooCommerce Smart Coupons 授权问题漏洞 — WooCommerce Smart Coupons CWE-285 | 5.3 | Medium | 2024-10-16 |
| CVE-2023-32193 | Rancher 安全漏洞 — norman CWE-80 | 8.3 | High | 2024-10-16 |
| CVE-2023-32192 | Rancher API Server 安全漏洞 — apiserver CWE-80 | 8.3 | High | 2024-10-16 |
| CVE-2023-7295 | WordPress plugin Video Grid 跨站脚本漏洞 — Video Grid CWE-79 | 6.1 | Medium | 2024-10-16 |
| CVE-2017-20194 | WordPress plugin Formidable Form Builder 信息泄露漏洞 — Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder CWE-200 | 5.3 | Medium | 2024-10-16 |
| CVE-2017-20193 | WordPress plugin Product Vendors 跨站脚本漏洞 — Product Vendors CWE-79 | 4.7 | Medium | 2024-10-16 |
| CVE-2020-36840 | WordPress plugin Timetable and Event Schedule by MotoPress 安全漏洞 — Timetable and Event Schedule by MotoPress CWE-862 | 7.3 | High | 2024-10-16 |
| CVE-2016-15042 | WordPress plugin Frontend File Manager 代码问题漏洞 — N-Media Post Front-end Form CWE-434 | 9.8 | Critical | 2024-10-16 |
| CVE-2024-9061 | WordPress plugin The WP Popup Builder 代码注入漏洞 — WP Popup Builder – Popup Forms and Marketing Lead Generation CWE-94 | 7.3 | High | 2024-10-16 |
| CVE-2024-8507 | WordPress plugin File Manager Pro 请求伪造漏洞 — File Manager Pro CWE-352 | 8.8 | High | 2024-10-16 |
| CVE-2020-36839 | WordPress plugin WP Lead Plus X 跨站请求伪造漏洞 — WordPress Landing Page – Squeeze Page – Responsive Landing Page Builder Free – WP Lead Plus X CWE-352 | 8.3 | High | 2024-10-16 |
access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 24808 条 CVE 漏洞。