Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-56195 Apache Traffic Server: Intercept plugins are not access controlled — Apache Traffic Server--2025-03-06
CVE-2024-56196 Apache Traffic Server: ACL is not fully compatible with older versions — Apache Traffic Server--2025-03-06
CVE-2025-1260 On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. — EOS 9.1 Critical2025-03-04
CVE-2025-1259 On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. — EOS 7.7 High2025-03-04
CVE-2020-3122 Cisco Content Security Management Appliance Information Disclosure Vulnerability — Cisco IronPort Security Management Appliance 5.3 -2025-03-04
CVE-2025-1881 i-Drive i11/i12 Video Footage/Live Video Stream access control — i11 4.3 Medium2025-03-03
CVE-2024-51954 Unauthorized access to secure services in ArcGIS Server — ArcGIS Server 8.5 High2025-03-03
CVE-2024-36259 Odoo 访问控制错误漏洞 — Odoo Community 7.5 High2025-02-25
CVE-2024-12368 Odoo 访问控制错误漏洞 — Odoo Community 8.1 High2025-02-25
CVE-2024-13693 Enfold <= 6.0.9 - Missing Authorization to Sensitive Information Disclosure in avia-export-class.php — Enfold - Responsive Multi-Purpose Theme 5.3 Medium2025-02-25
CVE-2025-21105 Dell RecoverPoint for Virtual Machines 访问控制错误漏洞 — RecoverPoint for VMs 6.6 Medium2025-02-20
CVE-2024-13855 Prime Addons for Elementor <= 2.0.1 - Authenticated (Contributor+) Insecure Direct Object Reference via pae_global_block Shortcode — Prime Addons for Elementor 4.3 Medium2025-02-20
CVE-2025-24989 Microsoft Power Pages Elevation of Privilege Vulnerability — Microsoft Power Pages 8.2 High2025-02-19
CVE-2025-20153 Cisco ESA mail Bypass — Cisco Secure Email 5.8 Medium2025-02-19
CVE-2025-0968 ElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content Function — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor 5.3 Medium2025-02-19
CVE-2024-13854 Education Addon for Elementor <= 1.3.1 - Authenticated (Contributor+) Insecure Direct Object Reference via naedu_elementor_template Shortcode — Education Addon for Elementor 4.3 Medium2025-02-19
CVE-2025-1390 pam_cap: Fix potential configuration parsing error — Anolis OS 6.1 Medium2025-02-18
CVE-2025-1391 Keycloak-services: improper authorization in keycloak organization mapper allows unauthorized organization claims 5.4 Medium2025-02-17
CVE-2024-13229 Rank Math SEO <= 1.0.235 - Missing Authorization to Authenticated (Contributor+) Arbitrary Schema Deletion — Rank Math SEO – AI SEO Tools to Dominate SEO Rankings 4.3 Medium2025-02-13
CVE-2025-24042 Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability — Visual Studio Code - JS Debug Extension 7.3 High2025-02-11
CVE-2025-21359 Windows Kernel Security Feature Bypass Vulnerability — Windows 10 Version 1507 7.8 High2025-02-11
CVE-2025-21337 Windows NTFS Elevation of Privilege Vulnerability — Windows 10 Version 1507 3.3 Low2025-02-11
CVE-2025-24422 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 6.5 Medium2025-02-11
CVE-2025-24411 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 8.1 High2025-02-11
CVE-2025-24424 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 6.5 Medium2025-02-11
CVE-2025-24429 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 3.5 Low2025-02-11
CVE-2025-24423 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 4.3 Medium2025-02-11
CVE-2025-24427 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 6.5 Medium2025-02-11
CVE-2025-24426 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 6.5 Medium2025-02-11
CVE-2025-24435 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 4.3 Medium2025-02-11

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.