Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-26029 Adobe Experience Manager | Improper Access Control (CWE-284) — Adobe Experience Manager 7.5 High2024-06-13
CVE-2024-29060 Visual Studio Elevation of Privilege Vulnerability — Microsoft Visual Studio 2022 version 17.10 6.7 Medium2024-06-11
CVE-2023-6491 Strong Testimonials <= 3.1.12 - Authenticated(Contributor+) Improper Authorization to Views Modification — Strong Testimonials 4.3 Medium2024-06-07
CVE-2024-36399 Kanboard affected by Project Takeover via IDOR in ProjectPermissionController — kanboard 8.2 High2024-06-06
CVE-2024-0972 BuddyPress Members Only <= 3.4.8 - Improper Access Control to Sensitive Information Exposure via REST API — BuddyPress Members Only 5.3 Medium2024-06-06
CVE-2023-6966 The Moneytizer <= 9.6.3 - Missing Authorization via multiple AJAX actions — The Moneytizer 8.1 High2024-06-06
CVE-2023-6968 The Moneytizer <= 9.6.3 - Cross-Site Request Forgery via multiple AJAX actions — The Moneytizer 8.1 High2024-06-06
CVE-2024-2019 WP-DB-Table-Editor <= 1.8.4 - Missing Authorization to Authenticated(Contributor+) Database Access — WP-DB-Table-Editor 7.5 High2024-06-04
CVE-2024-23360 Improper Access Control in Graphics Windows — Snapdragon 8.4 High2024-06-03
CVE-2024-20065 MediaTek 芯片 安全漏洞 — MT6768, MT6781, MT6835, MT6853, MT6855, MT6877, MT6879, MT6885, MT6886, MT6893, MT6983, MT6985, MT6989 5.5AIMediumAI2024-06-03
CVE-2024-0434 WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly <= 1.7.1 - Missing Authorization via ttbm_new_place_save — Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Solution 5.3 Medium2024-05-29
CVE-2024-22187 AutomationDirect P3-550E 访问控制错误漏洞 — P3-550E 9.1 Critical2024-05-28
CVE-2024-23315 AutomationDirect P3-550E 访问控制错误漏洞 — P3-550E 7.5 High2024-05-28
CVE-2023-52712 Huawei PC Manager 安全漏洞 — CurieM-WFG9B 7.8 High2024-05-28
CVE-2023-52711 Huawei PC Manager 安全漏洞 — CurieM-WFG9B 7.8 High2024-05-28
CVE-2024-29215 Slash commands run in channel without channel membership via playbook task commands — Mattermost 4.3 Medium2024-05-26
CVE-2024-36241 /playbook add slash command allows viewing arbitrary post contents — Mattermost 3.1 Low2024-05-26
CVE-2024-31859 Member promoted to channel admin via playbooks run linking to channel — Mattermost 4.3 Medium2024-05-26
CVE-2024-5270 SAML to email switch possible when email signin is disabled — Mattermost 4.3 Medium2024-05-26
CVE-2024-5272 Run Details leak to guest via webhook event "custom_playbooks_playbook_run_updated" — Mattermost 4.3 Medium2024-05-26
CVE-2024-32045 Playbook run link to private channel grants channel access — Mattermost 5.9 Medium2024-05-26
CVE-2024-34152 Playbook Run Metadata leak to Guest — Mattermost 4.3 Medium2024-05-26
CVE-2024-1376 Event post <= 5.9.4 - Missing Authorization — Event post 4.3 Medium2024-05-24
CVE-2024-35222 iFrames Bypass Origin Checks for Tauri API Access Control — tauri 5.9 Medium2024-05-23
CVE-2024-5168 Improper access control vulnerability in Prodys Quantum Audio codec — Quantum Audio codec 9.8 Critical2024-05-23
CVE-2024-26139 OpenCTI Authenticated Privilege Escalation — opencti 8.3 High2024-05-23
CVE-2024-32969 vantage6 collaboration admins can extend their influence by expanding the collaboration — vantage6 2.7 Low2024-05-23
CVE-2024-20261 Cisco Firepower Threat Defense 安全漏洞 — Cisco Firepower Threat Defense Software 5.8 Medium2024-05-22
CVE-2024-0453 AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callback — WPBot – AI ChatBot for Live Support, Lead Generation, AI Services 5.0 Medium2024-05-22
CVE-2024-0451 AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_list_callback — WPBot – AI ChatBot for Live Support, Lead Generation, AI Services 5.0 Medium2024-05-22

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.