Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-32458 Dell EMC AppSync 访问控制错误漏洞 — Dell EMC AppSync 7.3 High2023-09-27
CVE-2023-41322 Privilege Escalation from technician to super-admin in GLPI — glpi 4.9 Medium2023-09-26
CVE-2023-39376 SiberianCMS - CWE-284: Improper Access Control Authorized user may disable a security feature over the network — SiberianCMS 6.5 Medium2023-09-26
CVE-2023-25525 NVIDIA Cumulus Linux 访问控制错误漏洞 — Cumulus Linux 7.5 High2023-09-20
CVE-2022-47558 Improper Access Control in Ormazabal products — ekorCCP 9.4 Critical2023-09-19
CVE-2023-38205 ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298 — ColdFusion 7.5 High2023-09-14
CVE-2023-38206 ColdFusion | Improper Access Control (CWE-284) — ColdFusion 5.3 Medium2023-09-14
CVE-2023-20191 Cisco IOS XR 安全漏洞 — Cisco IOS XR Software 5.8 Medium2023-09-13
CVE-2023-36638 Fortinet FortiManager 安全漏洞 — FortiManager 4.2 Medium2023-09-13
CVE-2023-34470 Improper access control — AptioV 6.8 Medium2023-09-12
CVE-2023-34469 Cold Rest Vulnerabiltiy — AptioV 4.9 Medium2023-09-12
CVE-2023-40730 Siemens QMS Automotive 访问控制错误漏洞 — QMS Automotive 7.1 High2023-09-12
CVE-2023-3039 Dell SD ROM Utility 访问控制错误漏洞 — SD ROM Utility 7.3 High2023-09-12
CVE-2023-40060 2FA/MFA Bypass Vulnerability in Serv-U 15.4 and 15.4 Hotfix 1 — Serv-U 7.2 High2023-09-07
CVE-2021-40699 ColdFusion CFIDE Improper Access Control Leads To Privilege Escalation — ColdFusion 7.4 High2023-09-07
CVE-2023-36635 Fortinet FortiSwitchManager 安全漏洞 — FortiSwitchManager 6.9 High2023-09-07
CVE-2021-36036 Magento Commerce Media Gallery Upload Improper Access Control Could Lead To Remote Code Execution — Adobe Commerce 7.2 High2023-09-06
CVE-2023-31242 Open Automation Software OAS Platform 授权问题漏洞 — OAS Platform 8.1 High2023-09-05
CVE-2023-4696 Improper Access Control in usememos/memos — usememos/memos 4.3 -2023-09-01
CVE-2023-4650 Improper Access Control in instantsoft/icms2 — instantsoft/icms2 6.5 -2023-08-31
CVE-2023-4640 Set Logging Level Without Authentication — Anywhere 6.5 Medium2023-08-30
CVE-2023-40170 cross-site inclusion (XSSI) of files in jupyter-server — jupyter_server 4.6 Medium2023-08-28
CVE-2023-4546 Byzoro Smart S85F Management Platform licence.php access control — Smart S85F Management Platform 3.5 Low2023-08-26
CVE-2023-40579 OpenFGA Authorization Bypass — openfga 6.5 Medium2023-08-25
CVE-2023-40573 XWiki Platform's Groovy jobs check the wrong author, allowing remote code execution — xwiki-platform 9.1 Critical2023-08-24
CVE-2022-3746 Lenovo Notebook 访问控制错误漏洞 — Notebook 6.7 Medium2023-08-23
CVE-2023-20230 Cisco Application Policy Infrastructure Controller 安全漏洞 — Cisco Application Policy Infrastructure Controller (APIC) 5.4 Medium2023-08-23
CVE-2023-39972 Extension - acymailing.com - Improper Access Control in AcyMailing Enterprise component for Joomla 6.7.0-8.6.3 — AcyMailing Enterprise component for Joomla 5.3 -2023-08-17
CVE-2023-39973 Extension - acymailing.com - Improper Access Control in AcyMailing Enterprise component for Joomla 6.7.0-8.6.3 — AcyMailing Enterprise component for Joomla 5.3 -2023-08-17
CVE-2023-20224 Cisco ThousandEyes Enterprise Agent 参数注入漏洞 — Cisco ThousandEyes Recorder Application 7.8 High2023-08-16

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.