Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2044

2044 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-0377 LifterLMS – WordPress LMS Plugin for eLearning <= 7.5.1 - Missing Authorization via process_review — LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes 5.3 Medium2024-03-13
CVE-2024-0369 Bulk Edit Post Titles <= 5.0.0 - Missing Authorization via bulkUpdatePostTitles — Bulk Edit Post Titles 4.3 Medium2024-03-13
CVE-2024-0631 Duitku Payment Gateway <= 2.11.6 - Missing Authorization via check_duitku_response — Duitku Payment Gateway 5.3 Medium2024-03-13
CVE-2023-6785 Download Manager <= 3.2.84 - Missing Authorization — Download Manager 5.3 Medium2024-03-13
CVE-2024-1462 Maintenance Page <= 1.0.8 - Security Mechanism Bypass via REST API — Maintenance Page 5.3 Medium2024-03-13
CVE-2024-1370 Maintenance Page <= 1.0.8 - Missing Authorization to Sensitive Information Exposure — Maintenance Page 5.3 Medium2024-03-13
CVE-2024-21436 Windows Installer Elevation of Privilege Vulnerability — Windows 10 Version 1809 7.8 High2024-03-12
CVE-2024-26203 Azure Data Studio Elevation of Privilege Vulnerability — Azure Data Studio 7.3 High2024-03-12
CVE-2024-26201 Microsoft Intune Linux Agent Elevation of Privilege Vulnerability — Intune Company Portal for Android 6.6 Medium2024-03-12
CVE-2024-21418 Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability — Software for Open Networking in the Cloud (SONiC) 7.8 High2024-03-12
CVE-2023-36554 Fortinet FortiManager 访问控制错误漏洞 — FortiManager 7.7 High2024-03-12
CVE-2022-32257 Siemens SINEMA Remote Connect Server 访问控制错误漏洞 — SINEMA Remote Connect Server 9.8 Critical2024-03-12
CVE-2024-21483 Siemens SENTRON 7KM PAC 访问控制错误漏洞 — SENTRON 7KM PAC3120 AC/DC 4.6 Medium2024-03-12
CVE-2024-28120 API key leak in codeium-chrome — codeium-chrome 6.5 Medium2024-03-11
CVE-2024-2281 boyiddha Automated-Mess-Management-System Setting index.php access control — Automated-Mess-Management-System 6.3 Medium2024-03-08
CVE-2024-28115 Privilege Escalation in FreeRTOS Kernel ARMv7-M MPU ports and ARMv8-M ports with MPU support enabled — FreeRTOS-Kernel 8.8 High2024-03-07
CVE-2024-1088 Password Protected Store for WooCommerce <= 2.2 - Information Exposure via REST API — Password Protected Store for WooCommerce 5.3 Medium2024-03-05
CVE-2024-1478 Maintenance Mode <= 3.0.1 - Information Exposure — Maintenance Mode 5.3 Medium2024-03-05
CVE-2024-0795 Create user API role not enforced — mintplex-labs/anything-llm 9.8 -2024-03-02
CVE-2024-21767 Commend WS203VICM Improper Access Control — WS203VICM 9.4 Critical2024-03-01
CVE-2024-1942 Mattermost 安全漏洞 — Mattermost 4.3 Medium2024-02-29
CVE-2024-1888 Existing server guests invited to the team by members without "invite_guest" permission — Mattermost 4.3 Medium2024-02-29
CVE-2024-1887 Public channel post content accessible without membership when compliance export is enabled — Mattermost 4.3 Medium2024-02-29
CVE-2024-23488 Files of archived channels accessible with the “Allow users to view archived channels” option disabled — Mattermost 3.1 Low2024-02-29
CVE-2024-20291 Cisco Nexus 3000 Series Switches 安全漏洞 — Cisco NX-OS Software 5.8 Medium2024-02-28
CVE-2024-1632 Incorrect access control in the Sitefinity backend — Sitefinity 8.8 High2024-02-28
CVE-2024-1476 Under Construction / Maintenance Mode from Acurax <= 2.6 - Information Exposure — Under Construction / Maintenance Mode from Acurax 5.3 Medium2024-02-28
CVE-2024-0766 Envo's Elementor Templates & Widgets for WooCommerce <= 1.4.4 - Missing Authorization via templates_ajax_request — Envo's Templates & Widgets for Elementor and WooCommerce 4.3 Medium2024-02-28
CVE-2024-0975 WordPress Access Control <= 4.0.13 - Improper Access Control to Sensitive Information Exposure via REST API — WordPress Access Control 5.3 Medium2024-02-28
CVE-2024-22459 Dell ECS 访问控制错误漏洞 — ECS 6.8 Medium2024-02-28

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2044 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.