Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-39697 phonenumber panics on parsing crafted phonenumber inputs — rust-phonenumber 8.6 High2024-07-09
CVE-2024-39701 Directus Incorrectly handles _in` filter — directus 6.3 Medium2024-07-08
CVE-2024-6428 Limited DoS due to permitting creating users with user-defined IDs — Mattermost 5.3 Medium2024-07-03
CVE-2024-39361 Creating posts with user-defined IDs permitted in CreatePost API — Mattermost 3.1 Low2024-07-03
CVE-2024-36257 Lack of permission check when updating the profile picture of a remote user (shared channels enabled) — Mattermost 2.7 Low2024-07-03
CVE-2024-36989 Low-privileged user could create notifications in Splunk Web Bulletin Messages — Splunk Enterprise 6.5 High2024-07-01
CVE-2024-38518 bbb-web API additional parameters considered — bigbluebutton 4.6 Medium2024-06-28
CVE-2024-38371 Insufficient access control for OAuth2 Device Code flow in authentik — authentik 8.6 High2024-06-28
CVE-2024-37905 Improper Access Control and Incorrect Authorization in github.com/goauthentik/authentik — authentik 8.8 High2024-06-28
CVE-2024-39376 Improper Access Control In TELSAT MarKoni FM Transmitter — Markoni-D (Compact) FM Transmitters 8.1AIHighAI2024-06-27
CVE-2024-2191 Improper Access Control in GitLab — GitLab 5.3 Medium2024-06-26
CVE-2024-5655 Improper Access Control in GitLab — GitLab 9.6 Critical2024-06-26
CVE-2024-5430 Improper Access Control in GitLab — GitLab 6.8 Medium2024-06-26
CVE-2024-38273 moodle: BigBlueButton web service leaks meeting joining information to users who should not have access — Moodle 5.4AIMediumAI2024-06-18
CVE-2024-5650 Yokogawa Electric 安全漏洞 — CENTUM CS 3000 8.5 High2024-06-17
CVE-2024-37887 Nextcloud Server's events information leaked with shared calendars on recurrence exceptions — security-advisories 3.5 Low2024-06-14
CVE-2024-37884 Nextcloud Server's users can delete old versions of read-only shared files — security-advisories 3.5 Low2024-06-14
CVE-2024-37883 Nextcloud Deck can access comments and attachments of deleted cards — security-advisories 4.3 Medium2024-06-14
CVE-2024-37882 Nextcloud Server can reshare read&share only folder with more permissions — security-advisories 8.1 High2024-06-14
CVE-2024-37317 Nextcloud Notes app can be tricked into using a received share created before the user logged in — security-advisories 4.6 Medium2024-06-14
CVE-2024-37315 Nextcloud Server's read-only users can restore old versions — security-advisories 3.5 Low2024-06-14
CVE-2024-37314 Nextcloud Photos' shared albums have no restriction on photo removal — security-advisories 3.5 Low2024-06-14
CVE-2024-37312 Nextcloud user_oidc app's ID4me feature is available even when disabled — security-advisories 6.3 Medium2024-06-14
CVE-2024-28969 Dell Secure Connect Gateway 访问控制错误漏洞 — Secure Connect Gateway-Application 4.3 Medium2024-06-13
CVE-2024-28968 Dell Secure Connect Gateway 访问控制错误漏洞 — Secure Connect Gateway-Application 5.4 Medium2024-06-13
CVE-2024-28967 Dell Secure Connect Gateway 访问控制错误漏洞 — Secure Connect Gateway-Application 5.4 Medium2024-06-13
CVE-2024-28966 Dell Secure Connect Gateway 访问控制错误漏洞 — Secure Connect Gateway-Application 5.4 Medium2024-06-13
CVE-2024-28965 Dell Secure Connect Gateway 访问控制错误漏洞 — Secure Connect Gateway-Application 5.4 Medium2024-06-13
CVE-2024-34112 ColdFusion CFDOCUMENT file retrieval / access control bypass — ColdFusion 7.5 High2024-06-13
CVE-2024-34107 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 5.3 Medium2024-06-13

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.