Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-43517 Improper Access Control in Automotive Multimedia — Snapdragon 8.4 High2024-02-06
CVE-2024-0969 ARMember <= 4.0.24 - Improper Access Control to Sensitive Information Exposure via REST API — ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup 5.3 Medium2024-02-05
CVE-2024-0373 Views for WPForms <= 3.2.2 - Cross-Site Request Forgery via save_view — Views for WPForms – Display & Edit WPForms Entries on your site frontend 4.3 Medium2024-02-05
CVE-2024-0366 Starbox – the Author Box for Humans <= 3.4.7 - Insecure Direct Object Reference — Starbox – the Author Box for Humans 4.3 Medium2024-02-05
CVE-2024-0371 Views for WPForms <= 3.2.2 - Missing Authorization via create_view — Views for WPForms – Display & Edit WPForms Entries on your site frontend 4.3 Medium2024-02-05
CVE-2024-1092 RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.1 - Missing Authorization — RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator 4.3 Medium2024-02-05
CVE-2024-0370 Views for WPForms <= 3.2.2 - Missing Authorization via save_view — Views for WPForms – Display & Edit WPForms Entries on your site frontend 4.3 Medium2024-02-05
CVE-2024-0374 Views for WPForms <= 3.2.2 - Cross-Site Request Forgery via create_view — Views for WPForms – Display & Edit WPForms Entries on your site frontend 4.3 Medium2024-02-05
CVE-2024-0324 User Profile Builder <= 3.10.8 - Missing Authorization to Plugin Settings Change via wppb_two_factor_authentication_settings_update — User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor 8.2 High2024-02-05
CVE-2024-22202 User Removal Page Allows Spoofing Of User Details — phpMyFAQ 5.7 Medium2024-02-05
CVE-2023-38263 IBM SOAR QRadar Plugin App improper access controls — SOAR QRadar Plugin App 6.5 Medium2024-02-02
CVE-2023-32333 IBM Maximo Asset Management improper access control — Maximo Asset Management 6.5 Medium2024-02-02
CVE-2023-47867 MachineSense FeverWarn Improper Access Control — FeverWarn 8.8 High2024-02-01
CVE-2024-1114 openBI Screen.php dlfile access control — openBI 6.5 Medium2024-01-31
CVE-2024-24566 Lobe Chat unauthorized access to plugins — lobe-chat 5.3 Medium2024-01-31
CVE-2024-21653 vantage6 insecure SSH configuration for node and server containers — vantage6 6.5 Medium2024-01-30
CVE-2024-1011 SourceCodester Employee Management System Leave delete-leave.php access control — Employee Management System 4.3 Medium2024-01-29
CVE-2024-0212 Cloudflare WordPress plugin enables information disclosure of Cloudflare API (for low privileged users) — Cloudflare-WordPress 8.1 High2024-01-29
CVE-2024-20263 Cisco Small Business 安全漏洞 — Cisco Small Business Smart and Managed Switches 5.8 Medium2024-01-26
CVE-2024-23675 Splunk App Key Value Store (KV Store) Improper Handling of Permissions Leads to KV Store Collection Deletion — Splunk Enterprise 6.5 Medium2024-01-22
CVE-2024-23681 Artemis Java Test Sandbox Libary Load Escape 8.6 -2024-01-19
CVE-2024-0712 Byzoro Smart S150 Management Platform userattea.php access control — Smart S150 Management Platform 7.3 High2024-01-19
CVE-2023-20260 Cisco Evolved Programmable Network Manager和Cisco Prime Infrastructure安全漏洞 — Cisco Prime Infrastructure 6.0 Medium2024-01-17
CVE-2024-0642 Inadequate access control in C21 Live Encoder and Live Mosaic — C21 Live Encoder and Live Mosaic 9.8 Critical2024-01-17
CVE-2024-22407 Broken Access Control order API in Shopware — shopware 4.9 Medium2024-01-16
CVE-2024-0570 Totolink N350RT Setting cstecgi.cgi access control — N350RT 7.3 High2024-01-16
CVE-2024-22209 XBlock custom auth does not respect JWT Scopes — edx-platform 6.4 Medium2024-01-13
CVE-2023-49099 Discourse secure uploads accessible to guests even when login is required — discourse 3.1 Low2024-01-12
CVE-2023-49098 Reaction data for user notifications exposed in Discourse-reactions — discourse-reactions 3.5 Low2024-01-12
CVE-2024-22206 @clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR) — javascript 9.1 Critical2024-01-12

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.