Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2021-1601 Cisco Intersight Virtual Appliance IPv4 and IPv6 Forwarding Vulnerabilities — Cisco Intersight Virtual Appliance 8.3 High2021-07-22
CVE-2021-25320 Rancher: Cloud credentials can be used through proxy API by users without access — Rancher 9.9 Critical2021-07-15
CVE-2021-32753 Weak password in API gateway in EdgeX Foundry Edinburgh, Fuji, Geneva, and Hanoi releases allows remote attackers to obtain authentication token via dictionary-based password attack when OAuth2 authentication method is enabled. — edgex-go 8.3 High2021-07-09
CVE-2021-25440 SAMSUNG FactoryCameraFB 安全漏洞 — FactoryCameraFB 7.8 -2021-07-08
CVE-2021-25439 SAMSUNG Members 安全漏洞 — Samsung Members 4.4 -2021-07-08
CVE-2021-25438 SAMSUNG Members 安全漏洞 — Samsung Members 7.3 -2021-07-08
CVE-2021-25431 SAMSUNG Mobile devices 安全漏洞 — Cameralyzer 5.5 -2021-07-08
CVE-2021-28809 Missing Authentication for Critical Function in RTRR Server in HBS3 — HBS 3 9.8 Critical2021-07-08
CVE-2021-32517 QSAN Storage Manager - Improper Access Control — Storage Manager 7.5 High2021-07-07
CVE-2021-32514 QSAN Storage Manager - Improper Access Control Following via FirwareUpgrade function — Storage Manager 7.5 High2021-07-07
CVE-2021-34627 WP Upload Restriction <= 2.2.3 - Missing Access Control in getSelectedMimeTypesByRole function — WP Upload Restriction 4.3 Medium2021-07-07
CVE-2021-34626 WP Upload Restriction <= 2.2.3 - Missing Access Control in deleteCustomType function — WP Upload Restriction 4.3 Medium2021-07-07
CVE-2021-28579 Adobe Connect improper access control could lead to privilege escalation — Connect 4.3 Medium2021-06-28
CVE-2021-21083 Adobe Experience Manager broken access control in DSRPReindexServlet could lead to denial-of-service — Experience Manager 7.5 High2021-06-28
CVE-2021-23845 B426 Web Configuration Authentication Bypass — B426 Firmware 8.0 High2021-06-18
CVE-2020-8300 Citrix Systems Citrix Application Delivery Controller 安全漏洞 — Citrix ADC, Citrix Gateway 8.1 -2021-06-16
CVE-2021-24359 The Plus Addons for Elementor Page Builder < 4.1.11 - Arbitrary Reset Pwd Email Sending — The Plus Addons for Elementor Page Builder 7.1 -2021-06-14
CVE-2021-25405 Samsung Notes 安全漏洞 — Samsung Notes 5.0 -2021-06-11
CVE-2021-25412 Samsung SMR 安全漏洞 — Samsung Mobile Devices 7.8 -2021-06-11
CVE-2020-14388 Red Hat 3scale API Management Platform 安全漏洞 — Red Hat 3scale API Management 6.3 -2021-06-02
CVE-2021-32656 Trusted servers exchange can be triggered by attacker — security-advisories 8.6 High2021-06-01
CVE-2021-32652 Missing permission check on email metadata retrieval — security-advisories 8.8 High2021-06-01
CVE-2021-24318 Listeo < 1.6.11 - Multiple Authenticated IDOR Vulnerabilities — Listeo 6.5 -2021-06-01
CVE-2020-10145 Adobe ColdFusion 安全漏洞 — ColdFusion 7.8 High2021-05-27
CVE-2021-22907 Citrix Systems Workspace App 安全漏洞 — Citrix Workspace App for Windows 8.8 -2021-05-27
CVE-2020-27831 Red Hat Quay 访问控制错误漏洞 — quay 4.3 -2021-05-26
CVE-2020-25634 Red Hat 访问控制错误漏洞 — 3scale-system 5.4 -2021-05-26
CVE-2021-28798 Relative Path Traversal Vulnerability in QTS and QuTS hero — QTS 8.8 High2021-05-21
CVE-2020-15279 Scanning exclusion paths disclosure in BEST for Windows — Endpoint Security Tools for Windows 4.0 Medium2021-05-18
CVE-2020-36197 Improper Access Control Vulnerability in Music Station — Music Station 7.1 High2021-05-13

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.