Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5532

5532 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-4630 Missing Authorization in GitLab — GitLab 5.0 Medium2023-09-11
CVE-2023-4792 Duplicate Post Page Menu & Custom Post Type <= 2.3.1 - Missing Authorization to Post Duplication — Duplicate Post Page Menu & Custom Post Type 4.3 Medium2023-09-07
CVE-2023-41046 Velocity execution without script rights in Xwiki platform — xwiki-platform 6.3 Medium2023-09-01
CVE-2023-41750 Acronis Agent 安全漏洞 — Acronis Agent 7.5 -2023-08-31
CVE-2023-2174 BadgeOS <= 3.7.1.6 - Missing Authorization in delete_badgeos_log_entries — BadgeOS 4.3 Medium2023-08-31
CVE-2023-2353 CHP Ads Block Detector <= 3.9.4 - Missing Authorization to Plugin Settings Update — CHP Ads Block Detector 4.3 Medium2023-08-31
CVE-2023-3999 Waiting: One-click countdowns <= 0.6.2 - Missing Authorization — Waiting: One-click countdowns 6.3 Medium2023-08-31
CVE-2023-4245 WooCommerce PDF Invoice Builder <= 1.2.89 - Missing Authorization to Sensitive Information Exposure — PDF Builder for WooCommerce. Create invoices,packing slips and more 4.3 Medium2023-08-31
CVE-2023-4302 Missing permission checks in Fortify Plugin allow capturing credentials — Jenkins Fortify Plugin 4.2 Medium2023-08-21
CVE-2023-4434 Missing Authorization in hamza417/inure — hamza417/inure 8.8 -2023-08-20
CVE-2023-3244 Comments Like Dislike <= 1.2.0 - Missing Authorization to Authenticated (Subscriber+) Plugin Setting Reset — Comments Like Dislike 4.3 Medium2023-08-17
CVE-2023-4374 WP Remote Users Sync <= 1.2.11 - Missing Authorization to Authenticated (Subscriber+) Log View — WP Remote Users Sync 4.3 Medium2023-08-16
CVE-2023-40027 Conditionally missing authorization in @keystone-6/core — keystone 3.7 Low2023-08-15
CVE-2023-39438 Missing Authorization check allows certain operations on CLA Assistant data — CLA Assistant 8.1 High2023-08-15
CVE-2023-4106 A guest user can perform various actions on public playbooks — Mattermost 6.3 Medium2023-08-11
CVE-2023-4105 Attachment of deleted message in a thread remains accessible and downloadable — Mattermost 3.1 Low2023-08-11
CVE-2023-39966 1Panel arbitrary file write vulnerability exists in the background — 1Panel 7.5 High2023-08-10
CVE-2023-4282 EmbedPress <= 3.8.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Delete via admin_post_remove and remove_private_data — EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more 5.4 Medium2023-08-10
CVE-2023-37862 PHOENIX CONTACT: Missing Authorization in WP 6xxx Web panels — WP 6070-WVPS 8.2 High2023-08-09
CVE-2023-37860 PHOENIX CONTACT: Missing Authorization in WP 6xxx Web panels — WP 6070-WVPS 7.5 High2023-08-09
CVE-2023-4124 Missing Authorization in answerdev/answer — answerdev/answer--2023-08-03
CVE-2023-0958 Inisev Plugins (Various Versions) - Missing Authorization on handle_installation function — Redirection 4.3 Medium2023-07-28
CVE-2023-38510 Tolgee Lacks Permission Check for API Key for some endpoints — tolgee-platform 8.1 High2023-07-27
CVE-2023-3956 InstaWP Connect <= 0.0.9.18 - Missing Authorization to Unauthenticated Post/Taxonomy/User Add/Change/Delete, Customizer Setting Change, Plugin Installation/Activation/Deactication via events_receiver — InstaWP Connect – 1-click WP Staging & Migration 9.8 Critical2023-07-27
CVE-2023-3442 Missing Authorization in Jenkins plug-in for ServiceNow DevOps — Jenkins plug-in for ServiceNow DevOps 7.7 High2023-07-26
CVE-2023-3714 ProfileGrid <= 5.5.2 - Missing Authorization to Arbitrary Group Option Modification and Privilege Escalation — ProfileGrid – User Profiles, Groups and Communities 7.5 High2023-07-18
CVE-2023-3403 ProfileGrid <= 5.5.1 - Missing Authorization to User Import — ProfileGrid – User Profiles, Groups and Communities 5.4 Medium2023-07-18
CVE-2023-3713 ProfileGrid <= 5.5.1 - Authenticated (Subscriber+) Arbitrary Option Update — ProfileGrid – User Profiles, Groups and Communities 8.8 High2023-07-18
CVE-2023-3587 Inconsistent state in UI after boards permission change by system admin — Mattermost 2.7 Low2023-07-17
CVE-2023-2268 Plane v0.7.1 - Unauthorized access to files — Plane 7.1 High2023-07-15

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5532 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.