Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-51995 Logic bug in ajax.render.php allows for bypass of 'backOffice' access control in Combodo iTop — iTop 7.5AIHighAI2024-11-07
CVE-2024-51988 HTTP API's queue deletion endpoint does not verify that the user has a required permission — rabbitmq-server 6.5 Medium2024-11-06
CVE-2023-29121 Exposed TCF agent service in Enel X Juicebox — JuiceBox Pro 3.0 22kW Cellular 9.6 Critical2024-11-05
CVE-2023-29115 Denial of Service via Web Management interface in Enel X JuiceBox — JuiceBox Pro 3.0 22kW Cellular 6.5 Medium2024-11-05
CVE-2024-7429 Zotpress <= 7.3.12 - Missing Authorization — Zotpress 4.3 Medium2024-11-05
CVE-2024-51734 User data deletion by anoynmous users in Zope — AccessControl 6.5AIMediumAI2024-11-04
CVE-2024-7424 Multiple Page Generator Plugin – MPG <= 4.0.1 - Missing Authorization — Multiple Page Generator Plugin – MPG 5.4 Medium2024-11-01
CVE-2024-50353 ICG.AspNetCore.Utilities.CloudStorage's Secure Token Durations Different Than Expected — aspnetcore.utilities.cloudstorage 5.3 Medium2024-10-30
CVE-2024-10241 Private channel names leaked with Ctrl+K when ElasticSearch is enabled — Mattermost 4.3 Medium2024-10-29
CVE-2024-47481 Dell Data Lakehouse 访问控制错误漏洞 — Dell Data Lakehouse 6.5 Medium2024-10-25
CVE-2024-10353 SourceCodester Online Exam System admin-dashboard access control — Online Exam System 6.3 Medium2024-10-24
CVE-2024-48932 ZimaOS Unauthenticated API Discloses Usernames — ZimaOS 5.3 Medium2024-10-24
CVE-2024-9692 Improper Access Control in Input in VIMESA VHF/FM Transmitter Blue Plus — VHF/FM Transmitter Blue Plus 7.5AIHighAI2024-10-24
CVE-2024-48925 Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook API — Umbraco-CMS--2024-10-22
CVE-2020-36838 Facebook Chat Plugin <= 1.5 - Missing Capabilities Check — Facebook Chat Plugin – Live Chat Plugin for WordPress 7.4 High2024-10-16
CVE-2020-36831 NextScripts: Social Networks Auto-Poster <= 4.3.17 - Missing Authorization — NextScripts: Social Networks Auto-Poster 5.0 Medium2024-10-16
CVE-2024-38204 Imagine Cup site Information Disclosure Vulnerability — Microsoft Azure Functions 7.5 High2024-10-15
CVE-2024-45734 Low Privilege User can View Images on the Host Machine by using the PDF Export feature in Splunk Classic Dashboard — Splunk Enterprise 4.3 Medium2024-10-14
CVE-2024-45735 Improper Access Control for low-privileged user in Splunk Secure Gateway App — Splunk Enterprise 4.3 Medium2024-10-14
CVE-2024-45397 H2O alllows bypassing address-based access control with 0-RTT — h2o 5.9 Medium2024-10-11
CVE-2024-45133 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 2.7 Low2024-10-10
CVE-2024-45124 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 5.3 Medium2024-10-10
CVE-2024-45121 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 4.3 Medium2024-10-10
CVE-2024-45122 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 4.3 Medium2024-10-10
CVE-2024-45135 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 2.7 Low2024-10-10
CVE-2024-45130 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 4.3 Medium2024-10-10
CVE-2024-45129 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 4.3 Medium2024-10-10
CVE-2024-45118 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 6.5 Medium2024-10-10
CVE-2024-45149 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 2.7 Low2024-10-10
CVE-2024-43590 Visual C++ Redistributable Installer Elevation of Privilege Vulnerability — Visual C++ Redistributable Installer 7.8 High2024-10-08

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.