access:pre-auth 类型相关 24806 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。
“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-6671 | WhatsUp Gold 安全漏洞 — WhatsUp Gold CWE-89 | 9.8 | Critical | 2024-08-29 |
| CVE-2024-6670 | WhatsUp Gold 安全漏洞 — WhatsUp Gold CWE-89 | 9.8 | Critical | 2024-08-29 |
| CVE-2024-3679 | WordPress plugin Premium SEO Pack – WP SEO Plugin 信息泄露漏洞 — Premium SEO Pack – WP SEO Plugin CWE-200 | 5.3 | Medium | 2024-08-29 |
| CVE-2024-2541 | WordPress plugin WordPress plugin 信息泄露漏洞 — Popup Builder – Create highly converting, mobile friendly marketing popups. CWE-200 | 5.3 | Medium | 2024-08-29 |
| CVE-2024-6551 | WordPress plugin GiveWP 信息泄露漏洞 — GiveWP – Donation Plugin and Fundraising Platform CWE-200 | 5.3 | Medium | 2024-08-29 |
| CVE-2024-5857 | WordPress plugin Funnelforms Free 安全漏洞 — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free CWE-862 | 5.3 | Medium | 2024-08-29 |
| CVE-2024-45043 | OpenTelemetry Collector 安全漏洞 — opentelemetry-collector-contrib CWE-200 | 5.3 | Medium | 2024-08-28 |
| CVE-2024-20446 | Cisco NX-OS Software 安全漏洞 — Cisco NX-OS Software CWE-476 | 8.6 | High | 2024-08-28 |
| CVE-2024-8195 | WordPress plugin Permalink Manager Lite 安全漏洞 — Permalink Manager Lite CWE-862 | 5.3 | Medium | 2024-08-28 |
| CVE-2024-6450 | HyperView Geoportal Toolkit 安全漏洞 — Geoportal Toolkit CWE-79 | 6.1AI | Medium AI | 2024-08-28 |
| CVE-2024-6449 | HyperView Geoportal Toolkit 安全漏洞 — Geoportal Toolkit CWE-942 | 6.5AI | Medium AI | 2024-08-28 |
| CVE-2024-7447 | WordPress plugin Funnelforms Free 安全漏洞 — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free CWE-862 | 5.3 | Medium | 2024-08-28 |
| CVE-2024-39771 | Safie QBiC CLOUD CC-2L和Safie One 安全漏洞 — QBiC CLOUD CC-2L | 6.8AI | Medium AI | 2024-08-28 |
| CVE-2024-6448 | WordPress plugin Mollie Payments for WooCommerce 信息泄露漏洞 — Mollie Payments for WooCommerce CWE-200 | 5.3 | Medium | 2024-08-28 |
| CVE-2024-8030 | WordPress plugin Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider 安全漏洞 — Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor CWE-502 | 9.8 | Critical | 2024-08-28 |
| CVE-2024-7573 | WordPress plugin Relevanssi Live Ajax Search 安全漏洞 — Relevanssi Live Ajax Search CWE-88 | 5.3 | Medium | 2024-08-28 |
| CVE-2024-45232 | TYPO3 安全漏洞 — n/a | 5.3AI | Medium AI | 2024-08-28 |
| CVE-2024-45233 | TYPO3 安全漏洞 — n/a | 9.1AI | Critical AI | 2024-08-28 |
| CVE-2024-8200 | WordPress plugin Reviews Feed 安全漏洞 — Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More CWE-352 | 4.3 | Medium | 2024-08-27 |
| CVE-2024-8181 | Flowise 安全漏洞 — Flowise | 9.8 | Critical | 2024-08-27 |
| CVE-2024-8182 | Flowise 安全漏洞 — Flowise | 7.5 | High | 2024-08-27 |
| CVE-2024-43798 | Chisel 安全漏洞 — chisel CWE-306 | 8.6 | High | 2024-08-26 |
| CVE-2024-45241 | CentralSquare CryWolf 安全漏洞 — n/a | 7.5AI | High AI | 2024-08-26 |
| CVE-2024-45256 | BYOB 安全漏洞 — n/a | 9.8AI | Critical AI | 2024-08-26 |
| CVE-2024-6499 | WordPress plugin WordPress Button Plugin MaxButtons 安全漏洞 — MaxButtons – Create buttons CWE-200 | 5.3 | Medium | 2024-08-24 |
| CVE-2024-8120 | WordPress plugin ImageRecycle pdf & image compression 安全漏洞 — ImageRecycle pdf & image compression CWE-352 | 4.7 | Medium | 2024-08-24 |
| CVE-2024-7568 | WordPress plugin Favicon Generator 安全漏洞 — Favicon Generator (CLOSED) CWE-352 | 9.6 | Critical | 2024-08-24 |
| CVE-2023-6987 | WordPress plugin String locator 安全漏洞 — String locator CWE-79 | 6.1 | Medium | 2024-08-24 |
| CVE-2024-7954 | SPIP 安全漏洞 — SPIP CWE-95 | 9.8 | Critical | 2024-08-23 |
| CVE-2024-43477 | Microsoft Entra ID 安全漏洞 — Microsoft Entra CWE-284 | 7.5 | High | 2024-08-23 |
access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 24806 条 CVE 漏洞。