Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-0451 AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_list_callback — WPBot – AI ChatBot for Live Support, Lead Generation, AI Services 5.0 Medium2024-05-22
CVE-2024-4263 Improper Access Control in mlflow/mlflow — mlflow/mlflow 8.1AIHighAI2024-05-16
CVE-2024-34099 ZDI-CAN-XXXX: [Pwn2Own] Acrobat sandbox bypass part 2 of 2 — Acrobat Reader 7.8 High2024-05-15
CVE-2024-0437 Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease <= 2.6.6 - Missing Authorization to Sensitive Information Exposure — Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content 4.3 Medium2024-05-14
CVE-2024-30059 Microsoft Intune for Android Mobile Application Management Tampering Vulnerability — Microsoft Intune Mobile Application Management 6.1 Medium2024-05-14
CVE-2024-33647 Siemens Polarion 访问控制错误漏洞 — Polarion ALM 6.5 Medium2024-05-14
CVE-2024-1230 SimpleShop <= 2.10.0 - Cross-Site Request Forgery — SimpleShop 4.3 Medium2024-05-09
CVE-2023-6810 ClickCease Click Fraud Protection <= 3.2.4 - Improper Authorization to sensitive information exposure via get_settings — ClickCease Click Fraud Protection 4.3 Medium2024-05-07
CVE-2024-23351 Improper Access Control in Graphics Linux — Snapdragon 8.4 High2024-05-06
CVE-2024-34068 Server-side Request Forgery during remote file pull in Pterodactyl wings — wings 6.4 Medium2024-05-03
CVE-2024-1678 Subway – Private Site Option <= 2.1.4 - Improper Access Control to Sensitive Information Exposure via REST API — Subway – Private Site Option 5.3 Medium2024-05-02
CVE-2024-1584 Analytify <= 5.2.1 - Missing Authorization to Unauthenticated Google Analytics Tracking ID Modification — Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) 5.3 Medium2024-05-02
CVE-2024-32973 Remote for TLS session may be trusted despite constraints in Pluto lang — Pluto 4.8 Medium2024-05-01
CVE-2024-28978 Dell OpenManage Enterprise 访问控制错误漏洞 — Dell OpenManage Enterprise 5.2 Medium2024-05-01
CVE-2024-3746 Measuresoft ScadaPro Improper Access Control — ScadaPro 5.5 Medium2024-04-30
CVE-2024-4225 NGDIN_ST v2.0D.0062 - Multiple Vulnerabilities — NetGuardian DIN Remote Telemetry Unit (RTU) 7.6 High2024-04-30
CVE-2024-4198 Mattermost 安全漏洞 — Mattermost 2.7 Low2024-04-26
CVE-2024-4195 Mattermost 安全漏洞 — Mattermost 2.7 Low2024-04-26
CVE-2023-43491 Peplink Smart Reader 访问控制错误漏洞 — Smart Reader 5.3 Medium2024-04-17
CVE-2023-45209 Peplink Smart Reader 访问控制错误漏洞 — Smart Reader 5.3 Medium2024-04-17
CVE-2023-45744 Peplink Smart Reader 访问控制错误漏洞 — Smart Reader 8.3 High2024-04-17
CVE-2024-29837 Poor session management in Evolution Controller allows administrator functionality for unauthenticated connections — Evolution Controller 8.8 High2024-04-14
CVE-2024-29836 Broken Authentication on USER_CHANGE in Evolution Controller allows unauthenticated account creation and takeover — Evolution Controller 9.8 Critical2024-04-14
CVE-2024-3765 Xiongmai AHB7804R-MH-V2 Sofia Service access control — AHB7804R-MH-V2 9.8 Critical2024-04-14
CVE-2024-2217 Improper Access Control in gaizhenbiao/chuanhuchatgpt — gaizhenbiao/chuanhuchatgpt 9.1AICriticalAI2024-04-10
CVE-2024-2731 Improper Access Control Issues Lead to Sensitive Data Exposure in Mautic — Mautic 5.4 Medium2024-04-10
CVE-2024-0899 s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 230815 - Information Exposure — s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions 5.3 Medium2024-04-09
CVE-2024-0626 WooCommerce Clover Payment Gateway <= 1.3.1 - Missing Authorization via callback_handler — Clover Payment Gateway by Zaytech for WooCommerce 5.3 Medium2024-04-09
CVE-2024-1308 WooCommerce Cloak Affiliate Links <= 1.0.33 - Missing Authorization to Unauthenticated Permalink Modification — Cloak Affiliate Links for WooCommerce 7.5 High2024-04-09
CVE-2024-29993 Azure CycleCloud Elevation of Privilege Vulnerability — Azure CycleCloud 8.6.0 8.8 High2024-04-09

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.