Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-3127 Improper Access Control in GitLab — GitLab 4.3 Medium2024-08-22
CVE-2024-43780 Unauthorized channel file upload — Mattermost 4.3 Medium2024-08-22
CVE-2024-42497 Insufficient permissions checks on teams — Mattermost 6.0 Medium2024-08-22
CVE-2024-40884 Unauthorized disabling of invite URL — Mattermost 2.7 Low2024-08-22
CVE-2024-8071 System Role with edit access to permissions can elevate themselves to system admin — Mattermost 4.7 Medium2024-08-22
CVE-2024-43813 IDOR when marking read a user's channel — Mattermost 4.3 Medium2024-08-22
CVE-2024-32939 Email addresses of remote users visible in props regardless of server settings — Mattermost 4.3 Medium2024-08-22
CVE-2024-38175 Azure Managed Instance for Apache Cassandra Elevation of Privilege Vulnerability — Azure Managed Instance for Apache Cassandra 9.6 Critical2024-08-20
CVE-2024-27187 [20240804] - Core - Improper ACL for backend profile view — Joomla! CMS 6.5AIMediumAI2024-08-20
CVE-2024-43409 Ghost's improper authentication allows access to member information and actions — Ghost 6.5 Medium2024-08-20
CVE-2024-43397 Potential unauthorized access issue in apollo-portal — apollo 4.3 Medium2024-08-20
CVE-2024-43377 Umbraco CMS Improper Access Control vulnerability — Umbraco-CMS 5.4 Medium2024-08-20
CVE-2024-7921 Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 GetDataList access control — Jieshun JieLink+ JSOTC2016 4.3 Medium2024-08-19
CVE-2024-7920 Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 GetParkInThroughDeivces access control — Jieshun JieLink+ JSOTC2016 4.3 Medium2024-08-19
CVE-2024-7919 Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 GetDataList access control — Jieshun JieLink+ JSOTC2016 5.3 Medium2024-08-19
CVE-2024-6221 Improper Access Control in corydolphin/flask-cors — corydolphin/flask-cors 9.1AICriticalAI2024-08-18
CVE-2024-39414 Being able to import/export tax rates without proper privileges — Adobe Commerce 4.3 Medium2024-08-14
CVE-2024-38163 Windows Update Stack Elevation of Privilege Vulnerability — Windows Server 2022 7.8 High2024-08-13
CVE-2024-38223 Windows Initial Machine Configuration Elevation of Privilege Vulnerability — Windows 10 Version 1809 6.8 Medium2024-08-13
CVE-2024-38195 Azure CycleCloud Remote Code Execution Vulnerability — Azure CycleCloud 8.2.0 7.8 High2024-08-13
CVE-2024-38162 Azure Connected Machine Agent Elevation of Privilege Vulnerability — Azure Connected Machine Agent 7.8 High2024-08-13
CVE-2023-31341 AMD μProf 安全漏洞 — μProf Tool 7.3 High2024-08-13
CVE-2024-36505 Fortinet FortiOS 访问控制错误漏洞 — FortiOS 4.7 Medium2024-08-13
CVE-2024-41905 Siemens SINEC Traffic Analyzer 访问控制错误漏洞 — SINEC Traffic Analyzer 6.8 Medium2024-08-13
CVE-2024-41732 Improper Access Control in SAP Netweaver Application Server ABAP — SAP NetWeaver Application Server ABAP 4.7 Medium2024-08-13
CVE-2024-42480 Kamaji's RBAC Roles for `etcd` are not disjunct — kamaji 8.1 High2024-08-12
CVE-2024-29082 Vonets WiFi Bridges Improper Access Control — VAR1200-H 8.6 High2024-08-08
CVE-2024-0104 NVIDIA多款产品 安全漏洞 — Mellanox OS 4.2 Medium2024-08-08
CVE-2024-42354 Shopware vulnerable to Improper Access Control with ManyToMany associations in store-api — shopware 5.3 Medium2024-08-08
CVE-2024-42033 Huawei EMUI和Huawei HarmonyOS 安全漏洞 — HarmonyOS 6.9 Medium2024-08-08

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.