Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-732 (关键资源的不正确权限授予) — Vulnerability Class 445

445 vulnerabilities classified as CWE-732 (关键资源的不正确权限授予). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-30208 Siemens 多款产品 安全漏洞 — SIMATIC RTLS Locating Manager 6.3 Medium2024-05-14
CVE-2023-47712 IBM Security Guardium privilege escalation — Security Guardium 7.8 High2024-05-11
CVE-2023-51579 Voltronic Power ViewPower Incorrect Permission Assignment Local Privilege Escalation Vulnerability — ViewPower 7.8 -2024-05-03
CVE-2023-40516 LG Simple Editor Incorrect Permission Assignment Local Privilege Escalation Vulnerability — Simple Editor 7.8 -2024-05-03
CVE-2024-24912 Local privilege escalation in Harmony Endpoint Security Client for Windows via crafted DLL file — Harmony Endpoint Security Client for Windows 6.7 -2024-05-01
CVE-2024-3375 Broken Access Control in Havelsan's Dialogue — Dialogue 9.4 Critical2024-04-29
CVE-2024-2905 Rpm-ostree: world-readable /etc/shadow file 6.2 Medium2024-04-25
CVE-2024-32478 Git Credential Manager (GCM)'s Debian package does not set root ownership on installed files — git-credential-manager 6.9 Medium2024-04-19
CVE-2024-29964 Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files — Brocade SANnav 5.7 Medium2024-04-19
CVE-2024-24910 LocalprivilegeescalationinCheckPointZoneAlarmExtremeSecurityNextGen,IdentityAgentforWindows,andIdentityAgentforWindowsTerminalServerviacraftedDLLfile — ZoneAlarmExtremeSecurityNextGen,IdentityAgentforWindows,IdentityAgentforWindowsTerminalServer 6.7 -2024-04-18
CVE-2024-22334 IBM UrbanCode Deploy improper privilege control — UrbanCode Deploy 4.4 Medium2024-04-12
CVE-2024-25646 Information Disclosure vulnerability in SAP BusinessObjects Web Intelligence — SAP BusinessObjects Web Intelligence 7.7 High2024-04-09
CVE-2024-25956 Dell Grab 安全漏洞 — Grab for Windows 5.5 Medium2024-03-26
CVE-2024-29187 WiX based installers are vulnerable to binary hijack when run as SYSTEM — issues 7.3 High2024-03-24
CVE-2024-21431 Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability — Windows Server 2022 7.8 High2024-03-12
CVE-2024-25645 Information Disclosure vulnerability in SAP NetWeaver (Enterprise Portal) — SAP NetWeaver (Enterprise Portal) 5.3 Medium2024-03-12
CVE-2024-28163 Information Disclosure vulnerability in SAP NetWeaver Process Integration (Support Web Pages) — SAP NetWeaver Process Integration (Support Web Pages) 5.3 Medium2024-03-12
CVE-2024-25644 Information Disclosure vulnerability in NetWeaver (WSRM) — NetWeaver (WSRM) 5.3 Medium2024-03-12
CVE-2024-27294 dp-golang Go installation could be owned by wrong user — puppet-golang 7.3 High2024-02-29
CVE-2024-21915 Rockwell Automation FactoryTalk® Service Platform Elevated Privileges Vulnerability Through Web Service Functionality — FactoryTalk® Service Platform 9.0 Critical2024-02-16
CVE-2024-24740 Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (SAP Kernel) — SAP NetWeaver Application Server ABAP (SAP Kernel) 5.3 Medium2024-02-13
CVE-2023-50292 Apache Solr: Solr Schema Designer blindly "trusts" all configsets, possibly leading to RCE by unauthenticated users — Apache Solr 9.8 -2024-02-09
CVE-2023-47564 Qsync Central — Qsync Central 8.0 High2024-02-02
CVE-2020-24681 Automation Studio and PVI Multiple incorrect permission assignments for services — Automation Studio 8.2 High2024-02-02
CVE-2024-22016 Incorrect Permission Assignment for Critical Resource in Rapid SCADA — Rapid SCADA 7.8 High2024-02-01
CVE-2023-49257 Command execution using the certificate upload utility — H8951-4G-ESP 8.8 -2024-01-12
CVE-2024-21305 Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability — Windows 10 Version 1809 4.4 Medium2024-01-09
CVE-2023-44120 Siemens Spectrum Power 安全漏洞 — Spectrum Power 7 7.8 High2024-01-09
CVE-2023-41776 Local Privilege Escalation Vulnerability of ZTE's ZXCLOUD iRAI — ZXCLOUD iRAI 6.7 Medium2024-01-03
CVE-2023-46142 PHOENIX CONTACT: Insufficient Read and Write Protection to Logic and Runtime Data in PLCnext Control — AXC F 1152 8.8 High2023-12-14

Vulnerabilities classified as CWE-732 (关键资源的不正确权限授予) represent 445 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.