Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-6883 Event Espresso 4 Decaf – Event Registration Event Ticketing <= 4.10.46.decaf- Authenticated (Subscriber+) Missing Authorization to Limited Plugin Settings Modification — Event Espresso – Event Registration & Ticketing Sales 4.3 Medium2024-08-21
CVE-2024-5940 GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings Update — GiveWP – Donation Plugin and Fundraising Platform 6.5 Medium2024-08-20
CVE-2024-5939 GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Limited Information Exposure — GiveWP – Donation Plugin and Fundraising Platform 5.3 Medium2024-08-20
CVE-2024-5941 GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Missing Authorization to Authenticated (Subscriber+) Limited File Deletion — GiveWP – Donation Plugin and Fundraising Platform 5.4 Medium2024-08-20
CVE-2024-43326 WordPress Plugin Notes Plus plugin <= 1.2.7 - Arbitrary Content Deletion vulnerability — Plugin Notes Plus 5.4 Medium2024-08-19
CVE-2024-43256 WordPress Leopard plugin <= 2.0.36 - Subscriber+ Plugin Settings Change vulnerability — Leopard - WordPress offload media 7.1 High2024-08-19
CVE-2024-43247 WordPress WHMpress plugin <= 6.2-revision-5 - Subscriber+ Arbitrary Settings Change vulnerability — WHMpress 8.8 High2024-08-19
CVE-2024-35686 WordPress Sensei LMS plugin <= 4.23.1 - Broken Access Control vulnerability — Sensei LMS 5.3 Medium2024-08-18
CVE-2023-4025 Radio Player <= 2.0.73 - Missing Authorization to Player Update — Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player 5.3 Medium2024-08-17
CVE-2023-4730 LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.3 - Missing Authorization via init_endpoint — LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… 5.3 Medium2024-08-17
CVE-2023-4024 Radio Player <= 2.0.73 - Missing Authorization to Player Deletion — Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player 5.3 Medium2024-08-17
CVE-2023-4027 Radio Player <= 2.0.73 - Missing Authorization to Settings Update — Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player 5.3 Medium2024-08-17
CVE-2024-6500 InPost for WooCommerce <= 1.4.0 and InPost PL <= 1.4.4 - Missing Authorization to Unauthenticated Arbitrary File Read and Delete — InPost for WooCommerce 10.0 Critical2024-08-17
CVE-2024-42434 Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers - Missing Authorization — Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers 4.9 Medium2024-08-14
CVE-2024-39824 Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers - Missing Authorization — Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers 4.9 Medium2024-08-14
CVE-2024-39823 Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers - Missing Authorization — Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers 4.9 Medium2024-08-14
CVE-2024-38699 WordPress Wallet System for WooCommerce plugin <= 2.5.13 - Sensitive Data Exposure via Exported File vulnerability — Wallet System for WooCommerce 7.5 High2024-08-13
CVE-2024-37935 WordPress Woocommerce OpenPos plugin <= 6.4.4 - Unauthenticated Sensitive Data Exposure vulnerability — Woocommerce OpenPos 7.5 High2024-08-13
CVE-2024-39591 Missing Authorization check in SAP Document Builder — SAP Document Builder 4.3 Medium2024-08-13
CVE-2024-42373 Missing Authorization Check in SAP Student Life Cycle Management (SLcM) — SAP Student Life Cycle Management (SLcM) 4.3 Medium2024-08-13
CVE-2024-41734 Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform — SAP NetWeaver Application Server ABAP and ABAP Platform 4.3 Medium2024-08-13
CVE-2024-33005 Missing Authorization check in SAP NetWeaver Application Server (ABAP and Java),SAP Web Dispatcher and SAP Content Server — SAP NetWeaver Application Server (ABAP and Java),SAP Web Dispatcher and SAP Content Server 6.3 Medium2024-08-13
CVE-2024-42377 Multiple Missing Authorization Check vulnerabilities in SAP Shared Service Framework — SAP Shared Service Framework 4.3 Medium2024-08-13
CVE-2024-42376 Multiple Missing Authorization Check vulnerabilities in SAP Shared Service Framework — SAP Shared Service Framework 6.5 Medium2024-08-13
CVE-2024-41730 Missing Authentication check in SAP BusinessObjects Business Intelligence Platform — SAP BusinessObjects Business Intelligence Platform 9.8 Critical2024-08-13
CVE-2024-7648 Opal Membership <= 1.2.4 - Authenticated (Subscriber+) Information Disclosure — Opal Membership 4.3 Medium2024-08-10
CVE-2024-7621 Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update — Atarim – Visual Feedback, Review & AI Collaboration 5.4 Medium2024-08-10
CVE-2024-42470 CometVisu Backend for openHAB has a sensitive information disclosure vulnerability — openhab-webui 6.5 Medium2024-08-09
CVE-2024-42035 Huawei EMUI和Huawei HarmonyOS 安全漏洞 — HarmonyOS 8.4 High2024-08-08
CVE-2024-6824 Premium Addons for Elementor <= 4.10.38 - Missing Authorization to Authenticated (Contributor+) Arbitrary Content Deletion and Arbitrary Title Update — Premium Addons for Elementor – Powerful Elementor Templates & Widgets 4.3 Medium2024-08-08

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.