Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-732 (关键资源的不正确权限授予) — Vulnerability Class 443

443 vulnerabilities classified as CWE-732 (关键资源的不正确权限授予). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2021-35248 Unrestricted access to Orion.UserSettings SWIS entity for low-privilege users — Orion 6.8 Medium2021-12-20
CVE-2021-43359 Sunnet eHRD - Broken Access Control — eHRD 8.8 High2021-12-01
CVE-2021-24703 Download Plugin < 1.6.1 - Subscriber+ Arbitrary Plugin Activation — Download Plugin 6.5 -2021-11-23
CVE-2021-43019 Adobe Creative Cloud Incorrect Permission Assignment Privilege Escalation Vulnerability — Creative Cloud (desktop component) 7.8 -2021-11-23
CVE-2021-39235 Access mode of block tokens are not enforced — Apache Ozone 8.1 -2021-11-19
CVE-2021-37207 Siemens Sentron Powermanager 安全漏洞 — SENTRON powermanager V3 7.8 -2021-11-09
CVE-2021-38475 AUVESY Versiondog — Versiondog 7.3 High2021-10-22
CVE-2021-31377 Junos OS: A local authenticated attacker can cause RPD to core — Junos OS 5.5 Medium2021-10-19
CVE-2021-34758 Cisco TelePresence Collaboration Endpoint and RoomOS Software Denial of Service Vulnerability — Cisco RoomOS Software 4.4 Medium2021-10-06
CVE-2021-3747 MacOS version of Multipass incorrect owner for application directory — Multipass 8.8 High2021-10-01
CVE-2021-22148 Elasticsearch Elastic Enterprise Search 安全漏洞 — Elastic Enterprise Search 8.8 -2021-09-15
CVE-2021-22149 Elasticsearch Elastic Enterprise Search 安全漏洞 — Elastic Enterprise Search 8.1 -2021-09-15
CVE-2021-22147 Elasticsearch 安全漏洞 — Elasticsearch 6.5 -2021-09-15
CVE-2021-36280 Dell EMC PowerScale 安全漏洞 — PowerScale OneFS 7.8 High2021-08-16
CVE-2021-36279 EMC PowerScale 安全漏洞 — PowerScale OneFS 7.8 High2021-08-16
CVE-2021-21567 Dell Technologies Dell PowerScale OneFS访问控制错误漏洞 — PowerScale OneFS 7.8 High2021-08-10
CVE-2021-25318 rancher: API group not properly specified when creating Kubernetes RBAC resources — Rancher 8.8 High2021-07-15
CVE-2021-31894 Siemens SIMATIC PCS 7 安全漏洞 — SIMATIC PCS 7 V8.2 and earlier 7.8 -2021-07-13
CVE-2021-22921 Nodejs 安全漏洞 — Node 7.8 -2021-07-12
CVE-2021-32526 QSAN Storage Manager - Incorrect Permission Assignment for Critical Resource — Storage Manager 6.5 Medium2021-07-07
CVE-2021-23021 F5 NGINX Controller 安全漏洞 — Nginx Controller 5.5 -2021-06-01
CVE-2020-1701 KubeVirt 安全漏洞 — virt-handler 6.5 -2021-05-27
CVE-2021-31475 SolarWinds Orion Job Scheduler 安全漏洞 — Orion Job Scheduler 8.8 -2021-05-21
CVE-2021-20996 WAGO: Managed Switches: Unsecure Cookie settings — 0852-0303 5.3 Medium2021-05-13
CVE-2021-22669 Advantech WebAccess SCADA 安全漏洞 — Advantech WebAccess/SCADA 8.8 -2021-04-26
CVE-2021-22716 Schneider Electric C-Bus Toolkit 权限许可和访问控制问题漏洞 — C-Bus Toolkit 7.8 High2021-04-13
CVE-2019-18243 GE Digital HMI/SCADA iFIX 权限许可和访问控制问题漏洞 — HMI/SCADA iFIX 5.5 -2021-02-18
CVE-2019-18255 GE Digital HMI/SCADA iFIX 权限许可和访问控制问题漏洞 — HMI/SCADA iFIX 5.5 -2021-02-18
CVE-2020-8029 skuba: Insecure handling of private key — SUSE CaaS Platform 4.5 2.9 Low2021-02-11
CVE-2020-26196 DELL EMC PowerScale 安全漏洞 — PowerScale OneFS 5.5 Medium2021-02-09

Vulnerabilities classified as CWE-732 (关键资源的不正确权限授予) represent 443 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.