access:pre-auth 类型相关 24770 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。
“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-48247 | Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001) CWE-862 | 5.3 | Medium | 2024-01-10 |
| CVE-2023-48245 | Bosch Nexo cordless nutrunner 安全漏洞 — Nexo cordless nutrunner NXA015S-36V (0608842001) CWE-862 | 6.5 | Medium | 2024-01-10 |
| CVE-2023-51127 | Teledyne FLIR AX8 安全漏洞 — n/a | 7.5AI | High AI | 2024-01-10 |
| CVE-2020-26629 | Hospital Management System 安全漏洞 — n/a | 9.8AI | Critical AI | 2024-01-10 |
| CVE-2023-5770 | Proofpoint Enterprise Protection 安全漏洞 — Proofpoint Enterprise Protection CWE-838 | 5.3 | Medium | 2024-01-09 |
| CVE-2023-49252 | Siemens SIMATIC CN 4100 输入验证错误漏洞 — SIMATIC CN 4100 CWE-20 | 7.5 | High | 2024-01-09 |
| CVE-2023-6830 | WordPress Plugin Formidable Forms 安全漏洞 — Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder CWE-79 | 6.5 | Medium | 2024-01-09 |
| CVE-2023-6788 | WordPress Plugin Metform Elementor Contact Form Builder 安全漏洞 — MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor CWE-352 | 5.4 | Medium | 2024-01-09 |
| CVE-2023-6042 | WordPress Plugin Getwid 安全漏洞 — Getwid | 9.8AI | Critical AI | 2024-01-08 |
| CVE-2023-6529 | WordPress Plugin WP VR 安全漏洞 — WP VR | 6.1AI | Medium AI | 2024-01-08 |
| CVE-2024-21644 | pyLoad 访问控制错误漏洞 — pyload CWE-284 | 7.5 | High | 2024-01-08 |
| CVE-2024-21645 | pyLoad 注入漏洞 — pyload CWE-74 | 5.3 | Medium | 2024-01-08 |
| CVE-2023-6493 | WordPress plugin Depicter Slider 安全漏洞 — Depicter — Popup & Slider Builder CWE-352 | 4.3 | Medium | 2024-01-05 |
| CVE-2024-0241 | encoded_id-rails 安全漏洞 CWE-400 | 7.5AI | High AI | 2024-01-04 |
| CVE-2024-22051 | CommonMarker 输入验证错误漏洞 CWE-190 | 9.8AI | Critical AI | 2024-01-04 |
| CVE-2024-22050 | Iodine 路径遍历漏洞 CWE-22 | 7.5AI | High AI | 2024-01-04 |
| CVE-2024-22049 | httparty 安全漏洞 CWE-472 | 6.5AI | Medium AI | 2024-01-04 |
| CVE-2023-50867 | Travel Website SQL注入漏洞 — Travel Website CWE-89 | 9.8 | Critical | 2024-01-04 |
| CVE-2023-50866 | Travel Website SQL注入漏洞 — Travel Website CWE-89 | 9.8 | Critical | 2024-01-04 |
| CVE-2023-50865 | Travel Website SQL注入漏洞 — Travel Website CWE-89 | 9.8 | Critical | 2024-01-04 |
| CVE-2023-50864 | Travel Website SQL注入漏洞 — Travel Website CWE-89 | 9.8 | Critical | 2024-01-04 |
| CVE-2023-50863 | Travel Website SQL注入漏洞 — Travel Website CWE-89 | 9.8 | Critical | 2024-01-04 |
| CVE-2023-50862 | Travel Website SQL注入漏洞 — Travel Website CWE-89 | 9.8 | Critical | 2024-01-04 |
| CVE-2023-50753 | Online Notice Board System SQL注入漏洞 — Online Notice Board System CWE-89 | 9.8 | Critical | 2024-01-04 |
| CVE-2023-50752 | Online Notice Board System SQL注入漏洞 — Online Notice Board System CWE-89 | 9.8 | Critical | 2024-01-04 |
| CVE-2023-50743 | Online Notice Board System SQL注入漏洞 — Online Notice Board System CWE-89 | 9.8 | Critical | 2024-01-04 |
| CVE-2023-49666 | Kashipara Billing Software SQL注入漏洞 — Billing Software CWE-89 | 9.8 | Critical | 2024-01-04 |
| CVE-2023-49665 | Kashipara Billing Software SQL注入漏洞 — Billing Software CWE-89 | 9.8 | Critical | 2024-01-04 |
| CVE-2023-49658 | Kashipara Billing Software SQL注入漏洞 — Billing Software CWE-89 | 9.8 | Critical | 2024-01-04 |
| CVE-2023-49639 | Kashipara Billing Software SQL注入漏洞 — Billing Software CWE-89 | 9.8 | Critical | 2024-01-04 |
access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 24770 条 CVE 漏洞。