Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5527

5527 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2022-23945 Apache ShenYu missing authentication allows gateway registration — Apache ShenYu (incubating) 9.1 -2022-01-25
CVE-2022-23944 Apache ShenYu 2.4.1 Improper access control — Apache ShenYu (incubating) 9.1 -2022-01-25
CVE-2021-25013 Qubely < 1.7.8 - Subscriber+ Arbitrary Post Deletion — Qubely – Advanced Gutenberg Blocks 6.5 -2022-01-24
CVE-2021-24968 Ultimate FAQ < 2.1.2 - Subscriber+ Arbitrary FAQ Creation — Ultimate FAQ – WordPress FAQ and Accordion Plugin 3.5 -2022-01-24
CVE-2021-24906 Protect WP Admin < 3.6.2 - Unauthenticated Plugin Deactivation — Protect WP Admin 7.5 -2022-01-24
CVE-2022-0236 WP Import Export (Lite) <= 3.9.15 Unauthenticated Sensitive Data Disclosure — WP Import Export 7.5 High2022-01-18
CVE-2022-0178 Missing Authorization in snipe/snipe-it — snipe/snipe-it 6.3 Medium2022-01-13
CVE-2022-0179 Missing Authorization in snipe/snipe-it — snipe/snipe-it 5.4 -2022-01-12
CVE-2022-22111 DayByDay CRM - Missing Authorization when Changing Password — DaybydayCRM 8.8 High2022-01-05
CVE-2022-22108 DayByDay CRM - Missing Authorization when Viewing Absences — DaybydayCRM 4.3 Medium2022-01-05
CVE-2022-22107 DayByDay CRM - Missing Authorization when Viewing Appointments — DaybydayCRM 4.3 Medium2022-01-05
CVE-2021-24831 Tab - Accordion, FAQ < 1.3.2 - Unauthenticated AJAX Calls — Tab – Accordion, FAQ 7.5 -2022-01-03
CVE-2021-24997 WP Guppy < 1.3 - Sensitive Information Disclosure — WP Guppy 6.5 -2021-12-27
CVE-2021-40853 TCMAN GIM missing authorization vulnerability — GIM 7.2 High2021-12-17
CVE-2021-27859 Missing authorization vulnerability in FatPipe software — WARP 8.8 High2021-12-15
CVE-2021-27857 FatPipe software allows unauthenticated configuration download — WARP 7.5 High2021-12-15
CVE-2021-27858 Missing authorization vulnerability in FatPipe software — WARP 5.3 Medium2021-12-15
CVE-2021-27855 FatPipe software allows privilege escalation — WARP 8.8 High2021-12-15
CVE-2021-44233 SAP GRC Access Control 安全漏洞 — SAP GRC Access Control 8.8 -2021-12-14
CVE-2021-24836 Temporary Login Without Password < 1.7.1 - Subscriber+ Plugin's Settings Update — Temporary Login Without Password 4.3 -2021-12-13
CVE-2021-24790 Contact Form Advanced Database <= 1.0.8 - Unauthorised AJAX Calls — Contact Form Advanced Database 4.3 -2021-12-13
CVE-2021-43781 Permissions not properly checked in Invenio-Drafts-Resources — invenio-drafts-resources 6.4 Medium2021-12-06
CVE-2021-24914 Tawk.to Live Chat < 0.6.0 - Subscriber+ Visitor Monitoring & Chat Removal — Tawk.To Live Chat 7.3 -2021-12-06
CVE-2021-24842 Bulk Datetime Change < 1.12 - Missing Authorisation — Bulk Datetime Change 5.4 -2021-11-29
CVE-2021-39236 Owners of the S3 tokens are not validated — Apache Ozone 8.1 -2021-11-19
CVE-2021-39232 Missing admin check for SCM related admin commands — Apache Ozone 8.8 -2021-11-19
CVE-2021-39231 Missing authentication/authorization on internal RPC endpoints — Apache Ozone 9.1 -2021-11-19
CVE-2021-42062 SAP ERP HCM 安全漏洞 — SAP ERP HCM Portugal--2021-11-10
CVE-2021-40502 SAP Commerce 授权问题漏洞 — SAP Commerce 8.8 -2021-11-10
CVE-2021-40501 SAP AS ABAP 授权问题漏洞 — SAP ABAP Platform Kernel 8.1 -2021-11-10

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5527 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.