Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-43600 Microsoft Office Elevation of Privilege Vulnerability — Microsoft Office 2016 7.8 High2024-12-10
CVE-2024-49068 Microsoft SharePoint Elevation of Privilege Vulnerability — Microsoft SharePoint Enterprise Server 2016 8.2 High2024-12-10
CVE-2024-43594 Microsoft System Center Elevation of Privilege Vulnerability — Microsoft System Center 2022 7.3 High2024-12-10
CVE-2024-11868 LearnPress – WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses 5.3 Medium2024-12-10
CVE-2024-49600 Dell Power Manager 访问控制错误漏洞 — Dell Power Manager (DPM) 7.8 High2024-12-09
CVE-2024-12307 Function-Level Access Control Vulnerability Allows Unauthorized Modification of Student Data in Unifiedtransform — Unifiedtransform 4.3 Medium2024-12-09
CVE-2024-12306 Access Control Vulnerabilities Allow Unauthorized Access to User Profiles in Unifiedtransform — Unifiedtransform 4.3 Medium2024-12-09
CVE-2024-12235 Shenzhen Dashi Tongzhou Information Technology AgileBPM AuthorizationTokenCheckFilter.java doFilter access control — AgileBPM 6.3 Medium2024-12-05
CVE-2024-10937 Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.0.58 - Sensitive Information Exposure — Related Posts By PickPlugins 5.3 Medium2024-12-05
CVE-2024-20397 Cisco NX-OS Software Image Verification Bypass Vulnerability — Cisco NX-OS Software 5.2 Medium2024-12-04
CVE-2016-10408 Improper Access Control in Core. — Snapdragon 7.8 High2024-11-26
CVE-2024-11483 Automation-gateway: aap-gateway: improper scope handling in oauth2 tokens for aap 2.5 5.0 Medium2024-11-25
CVE-2024-8805 BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability — BlueZ 8.8 -2024-11-22
CVE-2023-51644 Allegra SiteConfigAction Improper Access Control Remote Code Execution Vulnerability — Allegra 9.8 -2024-11-22
CVE-2024-10393 Tutor LMS <= 2.7.6 - User Registration Setting Bypass to Unauthorized User Registration — Tutor LMS – eLearning and online course solution 5.3 Medium2024-11-21
CVE-2024-11484 Code4Berry Decoration Management System User Image update_image.php access control — Decoration Management System 6.3 Medium2024-11-20
CVE-2024-48899 Moodle: idor when accessing list of course badges 4.3AIMediumAI2024-11-20
CVE-2021-1410 Cisco Webex Meetings Unauthorized Distribution List Update Vulnerability — Cisco Webex Meetings 4.3 Medium2024-11-18
CVE-2024-37155 OpenCTI May Bypass Introspection Restriction — opencti 6.5 Medium2024-11-18
CVE-2024-52509 Nextcloud Mail app does not respect download permissions in shares — security-advisories 3.5 Low2024-11-15
CVE-2024-52514 Nextcloud Server allows users to copy folder that contain files that are blocked by the files access control — security-advisories 4.1 Medium2024-11-15
CVE-2021-34753 Cisco Firepower Threat Defense Ethernet Industrial Protocol Policy Bypass Vulnerabilities — Cisco Firepower Threat Defense Software 5.8 Medium2024-11-15
CVE-2024-20373 Cisco IOS and Cisco IOS XE SNMP Extended ACL Bypass Vulnerability — Cisco IOS XE Catalyst SD-WAN 5.3 Medium2024-11-15
CVE-2021-3987 Improper Access Control in janeczku/calibre-web — janeczku/calibre-web 4.3AIMediumAI2024-11-15
CVE-2024-49049 Visual Studio Code Remote Extension Elevation of Privilege Vulnerability — Visual Studio Code Remote - SSH Extension 7.1 High2024-11-12
CVE-2024-49044 Visual Studio Elevation of Privilege Vulnerability — Microsoft Visual Studio 2022 version 17.6 6.7 Medium2024-11-12
CVE-2024-43530 Windows Update Stack Elevation of Privilege Vulnerability — Windows Server 2022 7.8 High2024-11-12
CVE-2024-2315 SMM arbitrary code execution in Overclock — AptioV 5.5AIMediumAI2024-11-12
CVE-2024-50558 Siemens多款产品 访问控制错误漏洞 — RUGGEDCOM RM1224 LTE(4G) EU 4.3 Medium2024-11-12
CVE-2024-48010 Dell PowerProtect DD 访问控制错误漏洞 — PowerProtect DD 6.5 Medium2024-11-08

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.