Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-38202 Windows Update Stack Elevation of Privilege Vulnerability — Windows 10 Version 1809 7.3 High2024-08-08
CVE-2024-21302 Windows Secure Kernel Mode Elevation of Privilege Vulnerability — Windows 10 Version 1809 6.7 Medium2024-08-08
CVE-2024-7553 Accessing Untrusted Directory May Allow Local Privilege Escalation — MongoDB Server 7.3 High2024-08-07
CVE-2024-33027 Improper Access Control in Graphics Linux — Snapdragon 8.4 High2024-08-05
CVE-2024-41926 Malicious remote can claim that a user was synced from another remote — Mattermost 2.7 Low2024-08-01
CVE-2024-41162 Malicious remote can make an arbitrary local channel read-only — Mattermost 4.1 Medium2024-08-01
CVE-2024-41144 Malicious remote can create/update/delete arbitrary posts in arbitrary channels — Mattermost 5.5 Medium2024-08-01
CVE-2024-39839 Remote username set to an arbitrary string by remote user — Mattermost 4.3 Medium2024-08-01
CVE-2024-39837 Malicious remote can create arbitrary channels — Mattermost 3.8 Low2024-08-01
CVE-2024-39777 Malicious remote can invite itself to an arbitrary local channel — Mattermost 8.7 High2024-08-01
CVE-2024-39274 Malicious remote can add users to arbitrary teams and channels — Mattermost 8.7 High2024-08-01
CVE-2024-36492 Existing local user overwritten by malicious remote — Mattermost 7.4 High2024-08-01
CVE-2024-29977 Malicious remote can create arbitrary reactions on arbitrary posts — Mattermost 2.7 Low2024-08-01
CVE-2024-5331 Breakdance <= 1.7.2 - Missing Authorization — Breakdance 4.3 Medium2024-08-01
CVE-2024-6727 Broken Access Control in Delphix — Data Control Tower (DCT) 5.4 Medium2024-07-29
CVE-2024-7154 TOTOLINK A3700R Password Reset wizard.html access control — A3700R 4.3 Medium2024-07-28
CVE-2024-41806 Open edX Platform's instructor upload CSV for cohort creation not Private by Default — edx-platform 5.3 Medium2024-07-25
CVE-2024-7057 Improper Access Control in GitLab — GitLab 4.3 Medium2024-07-25
CVE-2024-38164 GroupMe Elevation of Privilege Vulnerability — GroupMe 9.6 Critical2024-07-23
CVE-2024-6738 WisdomGarden Tronclass - Broken Access Control — Tronclass 5.3 Medium2024-07-15
CVE-2024-6737 2100 TECHNOLOGY Electronic Official Document Management System - Broken Access Control — Electronic Official Document Management System 8.8 High2024-07-15
CVE-2024-2880 Improper Access Control in GitLab — GitLab 2.7 Low2024-07-11
CVE-2024-5257 Improper Access Control in GitLab — GitLab 4.9 Medium2024-07-11
CVE-2024-5470 Improper Access Control in GitLab — GitLab 3.8 Low2024-07-11
CVE-2024-6385 Improper Access Control in GitLab — GitLab 9.6 Critical2024-07-11
CVE-2024-37147 GLPI allows Authenticated File Upload to Restricted Tickets — glpi 4.3 Medium2024-07-10
CVE-2024-38100 Windows File Explorer Elevation of Privilege Vulnerability — Windows Server 2019 7.8 High2024-07-09
CVE-2024-38061 DCOM Remote Cross-Session Activation Elevation of Privilege Vulnerability — Windows 10 Version 1809 7.5 High2024-07-09
CVE-2024-23663 Fortinet FortiExtender 访问控制错误漏洞 — FortiExtender 8.1 High2024-07-09
CVE-2023-50181 Fortinet FortiADC 安全漏洞 — FortiADC 4.8 Medium2024-07-09

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.