Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-51650 Unauthorized access vulnerability on three interfaces — hertzbeat 7.5 High2023-12-22
CVE-2023-22674 WordPress Dashicons + Custom Post Types Plugin <= 1.0.2 is vulnerable to Broken Access Control — Dashicons + Custom Post Types 5.4 Medium2023-12-21
CVE-2023-25715 WordPress GamiPress Plugin <= 2.5.6 is vulnerable to Broken Access Control — GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress 5.4 Medium2023-12-19
CVE-2023-46212 WordPress WP EXtra Plugin <= 6.2 is vulnerable to Broken Access Control — WP EXtra 6.3 Medium2023-12-18
CVE-2023-47754 WordPress Delete Duplicate Posts Plugin <= 4.8.9 is vulnerable to Broken Access Control — Delete Duplicate Posts 4.3 Medium2023-12-18
CVE-2023-48751 WordPress Participants Database Plugin <= 2.5.5 is vulnerable to Broken Access Control — Participants Database 4.3 Medium2023-12-18
CVE-2023-5056 Skupper-operator: privelege escalation via config map — Service Interconnect 1 for RHEL 9 6.8 Medium2023-12-18
CVE-2023-5061 Missing Authorization in GitLab — GitLab 4.3 Medium2023-12-15
CVE-2023-48375 SmartStar Software CWS Web-Base - Broken Access Control — CWS Web-Base 8.8 High2023-12-15
CVE-2023-48676 Acronis Cyber Protect 安全漏洞 — Acronis Cyber Protect Cloud Agent 9.1AICriticalAI2023-12-14
CVE-2023-6394 Quarkus: graphql operations over websockets bypass — Red Hat build of Quarkus 2.13.9.Final 7.4 High2023-12-09
CVE-2023-39167 SENEC: Storage Box V1,V2 and V3 affected by improper access control vulnerability — Storage Box V1 7.5 High2023-12-07
CVE-2023-5710 System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_constants) — System Dashboard 4.3 Medium2023-12-07
CVE-2023-5712 System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_global_value) — System Dashboard 4.3 Medium2023-12-07
CVE-2023-5713 System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_option_value) — System Dashboard 4.3 Medium2023-12-07
CVE-2023-5714 System Dashboard <= 2.8.7 - Missing Authorization to Information Disclosure (sd_db_specs) — System Dashboard 4.3 Medium2023-12-07
CVE-2023-5711 System Dashboard <= 2.8.8 - Missing Authorization to Information Disclosure (sd_php_info) — System Dashboard 4.3 Medium2023-12-07
CVE-2023-37890 WordPress KB Support Plugin <= 1.5.88 is vulnerable to Broken Access Control — KB Support – WordPress Help Desk and Knowledge Base 4.3 Medium2023-11-30
CVE-2023-49620 Apache DolphinScheduler: Authenticated users could delete UDFs in resource center they were not authorized for — Apache DolphinScheduler 4.3 -2023-11-30
CVE-2023-5385 Funnelforms Free <= 3.4 - Missing Authorization to Arbitrary Post Duplication — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 4.3 Medium2023-11-22
CVE-2023-5387 Funnelforms Free <= 3.4 - Missing Authorization to Enable/Disable Dark Mode — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 4.3 Medium2023-11-22
CVE-2023-5314 WP EXtra <= 6.2 - Missing Authorization to Arbitrary Email Sending — WP EXtra – One Click Optimize 4.3 Medium2023-11-22
CVE-2023-5416 Funnelforms Free <= 3.4 - Missing Authorization to Category Deletion — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 4.3 Medium2023-11-22
CVE-2023-5411 Funnelforms Free <= 3.4 - Missing Authorization to Post Modification — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 4.3 Medium2023-11-22
CVE-2023-2448 UserPro <= 5.1.4 - Missing Authorization to Arbitrary Shortcode Execution via userpro_shortcode_template — UserPro - Community and User Profile WordPress Plugin 6.5 Medium2023-11-22
CVE-2023-5415 Funnelforms Free <= 3.4 - Missing Authorization to New Category Creation — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 4.3 Medium2023-11-22
CVE-2023-6007 UserPro <= 5.1.1 - Missing Authorization via multiple functions — UserPro - Community and User Profile WordPress Plugin 7.3 High2023-11-22
CVE-2023-5419 Funnelforms Free <= 3.4 - Missing Authorization to Test Email Sending — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 4.3 Medium2023-11-22
CVE-2023-5386 Funnelforms Free <= 3.4 - Missing Authorization to Arbitrary Post Deletion — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 6.5 Medium2023-11-22
CVE-2023-4686 WP Customer Reviews <= 3.6.6 - Authenticated (Subscriber+) Sensitive Information Exposure — WP Customer Reviews 4.3 Medium2023-11-22

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.