access:pre-auth 类型相关 24644 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。
“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-4308 | WordPress Plugin User Submitted Posts 跨站脚本漏洞 — User Submitted Posts – Enable Users to Submit Posts from the Front End CWE-79 | 7.2 | High | 2023-08-15 |
| CVE-2022-32876 | Apple macOS Ventura 安全漏洞 — macOS | 6.2 | - | 2023-08-14 |
| CVE-2023-3435 | WordPress plugin User Activity Log SQL注入漏洞 — User Activity Log | 9.8 | - | 2023-08-14 |
| CVE-2023-28768 | Zyxel XGS2220-30 安全漏洞 — XGS2220-30 firmware CWE-755 | 6.5 | Medium | 2023-08-14 |
| CVE-2023-3266 | CyberPower PowerPanel Business Edition 安全漏洞 — PowerPanel Enterprise CWE-358 | 9.8 | Critical | 2023-08-14 |
| CVE-2023-3265 | Cyber Power Systems CyberPower PowerPanel Enterprise 安全漏洞 — PowerPanel Enterprise CWE-150 | 9.8 | Critical | 2023-08-14 |
| CVE-2023-32748 | Mitel MiVoice Connect 安全漏洞 — n/a | 8.8 | - | 2023-08-14 |
| CVE-2023-40293 | Harman Infotainment 命令注入漏洞 — n/a | 9.8 | - | 2023-08-14 |
| CVE-2023-3452 | WordPress plugin Canto 安全漏洞 — Canto CWE-98 | 9.8 | Critical | 2023-08-12 |
| CVE-2022-29887 | Intel Manageability Commander 跨站脚本漏洞 — Intel(R) Manageability Commander software | 8.1 | High | 2023-08-11 |
| CVE-2023-27515 | Intel Driver and Support Assistant 跨站脚本漏洞 — Intel(R) DSA software | 8.1 | High | 2023-08-11 |
| CVE-2023-28380 | Intel AI Hackathon 代码问题漏洞 — Intel(R) AI Hackathon software | 8.8 | High | 2023-08-11 |
| CVE-2023-25775 | Intel Ethernet Controllers 安全漏洞 — Intel(R) Ethernet Controller RDMA driver for linux | 5.6 | Medium | 2023-08-11 |
| CVE-2022-36392 | Intel AMT SDK 安全漏洞 — Intel(R) AMT and Intel(R) Standard Manageability in Intel (R) CSME | 8.6 | High | 2023-08-11 |
| CVE-2022-36351 | Intel PROSet/Wireless WiFi Software 安全漏洞 — Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software | 4.3 | Medium | 2023-08-11 |
| CVE-2023-32563 | Ivanti Avalanche 路径遍历漏洞 — Avalanche | 9.8 | - | 2023-08-10 |
| CVE-2023-39959 | Nextcloud 访问控制错误漏洞 — security-advisories CWE-284 | 3.5 | Low | 2023-08-10 |
| CVE-2023-38210 | Adobe XMP Toolkit 资源管理错误漏洞 — XMP Toolkit CWE-400 | 5.5 | Medium | 2023-08-10 |
| CVE-2023-38245 | Adobe Acrobat Reader 信息泄露漏洞 — Acrobat Reader CWE-200 | 5.5 | Medium | 2023-08-10 |
| CVE-2023-4276 | WordPress Plugin Absolute Privacy 跨站请求伪造漏洞 — Absolute Privacy CWE-352 | 8.8 | High | 2023-08-10 |
| CVE-2023-4277 | WordPress Plugin Realia 跨站请求伪造漏洞 — Realia CWE-352 | 8.8 | High | 2023-08-10 |
| CVE-2023-37862 | PHOENIX CONTACTs WP 6xxx series web panels 安全漏洞 — WP 6070-WVPS CWE-862 | 8.2 | High | 2023-08-09 |
| CVE-2023-37860 | PHOENIX CONTACTs WP 6xxx series web panels 安全漏洞 — WP 6070-WVPS CWE-862 | 7.5 | High | 2023-08-09 |
| CVE-2023-39213 | Zoom Client 注入漏洞 — Zoom Desktop Client for Windows and Zoom VDI Client CWE-176 | 9.6 | Critical | 2023-08-08 |
| CVE-2023-39217 | Zoom Client 安全漏洞 — Zoom SDK's CWE-80 | 5.3 | Medium | 2023-08-08 |
| CVE-2023-39216 | Zoom Client 安全漏洞 — Zoom Desktop Client for Windows CWE-80 | 9.6 | Critical | 2023-08-08 |
| CVE-2023-36534 | Zoom Client 路径遍历漏洞 — Zoom Desktop Client for Windows CWE-22 | 9.3 | Critical | 2023-08-08 |
| CVE-2023-36533 | Zoom Client SDK 安全漏洞 — Zoom SDK's CWE-772 | 7.1 | High | 2023-08-08 |
| CVE-2023-36532 | Zoom Client 缓冲区错误漏洞 — Zoom Clients CWE-122 | 5.9 | Medium | 2023-08-08 |
| CVE-2023-37373 | Siemens RUGGEDCOM CROSSBOW 访问控制错误漏洞 — RUGGEDCOM CROSSBOW CWE-306 | 5.3 | Medium | 2023-08-08 |
access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 24644 条 CVE 漏洞。