Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-732 (关键资源的不正确权限授予) — Vulnerability Class 445

445 vulnerabilities classified as CWE-732 (关键资源的不正确权限授予). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-31238 Siemens POWER METER SICAM 安全漏洞 — SICAM P850 5.5 Medium2023-06-13
CVE-2023-30897 Siemens SIMATIC WinCC 安全漏洞 — SIMATIC WinCC 7.8 High2023-06-13
CVE-2023-32114 Denial of Service in SAP NetWeaver — SAP NetWeaver (Change and Transport System) 2.7 Low2023-06-13
CVE-2023-31453 Apache InLong: IDOR make users can delete others' subscription — Apache InLong 7.5 -2023-05-22
CVE-2023-31454 Apache InLong: IDOR make users can bind any cluster — Apache InLong 9.8 -2023-05-22
CVE-2023-32303 Planet's secret file is created with excessive permissions — planet-client-python 5.2 Medium2023-05-12
CVE-2021-40331 Permissions problem in the Apache Ranger Hive Plugin — Apache Ranger Hive Plugin 6.5 -2023-05-05
CVE-2023-28068 Dell Command | Monitor 访问控制错误漏洞 — Dell Command Monitor (DCM) 7.3 High2023-05-05
CVE-2023-0834 HYPR 安全漏洞 — Workforce Access 7.0 High2023-04-28
CVE-2023-0207 NVIDIA DGX-2 安全漏洞 — NVIDIA DGX servers 7.5 High2023-04-22
CVE-2023-28123 UI Desktop 安全漏洞 — UI Desktop for Windows 6.6 -2023-04-19
CVE-2023-30606 Multisite denial of service through unsanitized dynamic dispatch to SiteSetting in Discourse — discourse 4.2 Medium2023-04-18
CVE-2023-22294 Privilege escalation in Checkmk Appliance — Checkmk Appliance 8.8 High2023-04-18
CVE-2023-28960 Junos OS Evolved: Docker repository is world-writeable, allowing low-privileged local user to inject files into Docker containers — Junos OS Evolved 8.2 High2023-04-17
CVE-2022-43946 Fortinet FortiClientWindows 安全漏洞 — FortiClientWindows 7.3 High2023-04-11
CVE-2022-43773 Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resource — Pentaho Business Analytics Server 8.8 High2023-04-03
CVE-2023-0225 Samba 安全漏洞 — Samba 6.5 -2023-04-03
CVE-2023-1516 RoboDK 安全漏洞 — RoboDK 7.9 High2023-03-28
CVE-2023-1135 Delta Electronics InfraSuite Device Master 安全漏洞 — InfraSuite Device Master 7.8 High2023-03-27
CVE-2023-23939 Azure/setup-kubectl: Escalation of privilege vulnerability for v3 and lower — setup-kubectl 3.9 Low2023-03-06
CVE-2023-22326 iControl REST and tmsh vulnerability — BIG-IP 4.9 Medium2023-02-01
CVE-2022-42972 Schneider Electric Easy UPS Online Monitoring Software 安全漏洞 — APC Easy UPS Online Monitoring Software 7.8 High2023-02-01
CVE-2022-43517 Siemens Simcenter STAR-CCM+ 安全漏洞 — Simcenter STAR-CCM+ 7.8 High2022-12-13
CVE-2022-41926 Nextcloud Talk Android broadcast incorrect permission handling — security-advisories 3.3 Low2022-11-25
CVE-2022-3258 HYPR 安全漏洞 — Workforce Access 3.7 Low2022-11-03
CVE-2022-22248 Junos OS Evolved: Incorrect file permissions can allow low-privileged user to cause another user to execute arbitrary commands — Junos OS Evolved 7.3 High2022-10-18
CVE-2022-2332 Honeywell SoftMaster Incorrect Permission Assignment for Critical Resource — SoftMaster 6.2 Medium2022-09-16
CVE-2022-36103 Talos worker join token can be used to get elevated access level to the Talos API — talos 7.2 High2022-09-13
CVE-2022-37435 Apache ShenYu Admin Improper Privilege Management — Apache ShenYu 8.8 -2022-09-01
CVE-2022-32778 WWBN AVideo 安全漏洞 — AVideo 7.5 -2022-08-22

Vulnerabilities classified as CWE-732 (关键资源的不正确权限授予) represent 445 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.