Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-21589 Paragon Active Assurance Control Center: Information disclosure vulnerability — Paragon Active Assurance 7.4 High2024-01-12
CVE-2024-20675 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability — Microsoft Edge (Chromium-based) 6.3 Medium2024-01-11
CVE-2024-0415 DeShang DSMall Image URL TaobaoExport.php access control — DSMall 6.3 Medium2024-01-11
CVE-2024-0414 DeShang DSCMS install.php access control — DSCMS 5.3 Medium2024-01-11
CVE-2024-0413 DeShang DSKMS install.php access control — DSKMS 5.3 Medium2024-01-11
CVE-2024-0412 DeShang DSShop HTTP GET Request install.php access control — DSShop 5.3 Medium2024-01-11
CVE-2024-0411 DeShang DSMall HTTP GET Request install.php access control — DSMall 5.3 Medium2024-01-11
CVE-2023-6582 ElementsKit Lite <= 3.0.3 - Unauthenticated Sensitive Information Exposure — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor 5.3 Medium2024-01-11
CVE-2024-21667 Pimcore Customer Data Framework Improper Access Control allows unprivileged user to access GDPR extracts — customer-data-framework 6.5 Medium2024-01-11
CVE-2024-21666 Pimcore Customer Data Framework Improper Access Control allows unprivileged user to access customers duplicates list — customer-data-framework 6.5 Medium2024-01-11
CVE-2024-21665 Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list — ecommerce-framework-bundle 4.3 Medium2024-01-11
CVE-2023-46712 Fortinet FortiPortal 访问控制错误漏洞 — FortiPortal 6.3 High2024-01-10
CVE-2024-0358 DeShang DSO2O install.php access control — DSO2O 5.3 Medium2024-01-10
CVE-2024-0356 Mandelo ssm_shiro_blog Backend updateRoles access control — ssm_shiro_blog 4.3 Medium2024-01-10
CVE-2024-20657 Windows Group Policy Elevation of Privilege Vulnerability — Windows 10 Version 1809 7.0 High2024-01-09
CVE-2023-7223 Totolink T6 cstecgi.cgi access control — T6 5.3 Medium2024-01-09
CVE-2024-21644 pyLoad unauthenticated flask configuration leakage — pyload 7.5 High2024-01-08
CVE-2023-29051 Open-Xchange App Suite 安全漏洞 — OX App Suite 8.1 High2024-01-08
CVE-2023-6733 WP-Members Membership Plugin <= 3.4.8 - Missing Authorization to Sensitive Information Exposure — WP-Members Membership Plugin 6.5 Medium2024-01-04
CVE-2023-47858 Details of archived public channels are leaked to members of another team — Mattermost 4.3 Medium2024-01-02
CVE-2023-50333 Lack of restriction to manage group names for freshly demoted guests — Mattermost 3.7 Low2024-01-02
CVE-2023-7193 MTab Bookmark Installation install.php access control — Bookmark 4.6 Medium2023-12-31
CVE-2023-50928 sandbox-accounts-for-events security misconfiguration leads to budget exceed — sandbox-accounts-for-events 7.1 High2023-12-22
CVE-2023-49791 Workflows do not require password confirmation on API level — security-advisories 5.4 Medium2023-12-22
CVE-2022-39337 Permission bypass due to incorrect configuration in github.com/dromara/hertzbeat — hertzbeat 7.5 High2023-12-22
CVE-2023-51661 Filesystem sandbox not enforced in wasmer-cli — wasmer 8.4 High2023-12-22
CVE-2023-7055 PHPGurukul Online Notes Sharing System Contact Information profile.php access control — Online Notes Sharing System 4.3 Medium2023-12-22
CVE-2023-50783 Apache Airflow: Improper access control vulnerability on the "varimport" endpoint — Apache Airflow 6.5AIMediumAI2023-12-21
CVE-2023-7025 KylinSoft hedron-domain-hook DBus init_kcm access control — hedron-domain-hook 7.8 High2023-12-21
CVE-2023-51390 Information Disclosure Vulnerability in Journalpump — journalpump 6.5 Medium2023-12-20

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.