Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-49874 WordPress Arconix FAQ plugin <= 1.9.6 - Broken Access Control Vulnerability — Arconix FAQ 4.3 Medium2025-06-17
CVE-2025-49880 WordPress CubeWP Forms plugin <= 1.1.5 - Broken Access Control Vulnerability — CubeWP Forms 4.3 Medium2025-06-17
CVE-2025-48916 Bookable Calendar - Less critical - Access bypass - SA-CONTRIB-2025-070 — Bookable Calendar 7.5AIHighAI2025-06-13
CVE-2025-5282 WP Travel Engine <= 6.5.1 - Missing Authorization to Unauthenticated Arbitrary Post Deletion — WP Travel Engine – Tour Booking Plugin – Tour Operator Software 7.5 High2025-06-13
CVE-2025-5815 Traffic Monitor <= 3.2.2 - Missing Authorization to Unauthenticated Settings Update — Traffic Monitor 5.3 Medium2025-06-13
CVE-2025-5288 REST API | Custom API Generator For Cross Platform And Import Export In WP 1.0.0 - 2.0.3 - Missing Authorization to Unauthenticated Privilege Escalation via process_handler Function — REST API | Custom API Generator For Cross Platform And Import Export In WP 9.8 Critical2025-06-13
CVE-2025-49181 Configurations endpoint does not require authorization — SICK Media Server 8.6 High2025-06-12
CVE-2025-48013 Quick Node Block - Moderately critical - Access bypass - SA-CONTRIB-2025-065 — Quick Node Block 7.5AIHighAI2025-06-11
CVE-2025-48444 Quick Node Block - Moderately critical - Access bypass - SA-CONTRIB-2025-064 — Quick Node Block 7.5AIHighAI2025-06-11
CVE-2025-29756 MQTT implementation in Sungrow iSolarCloud allowed users to subscribe to all data of all connected inverters — iSolarCloud 7.4AIHighAI2025-06-11
CVE-2025-1055 K7 Security Anti-Malware: IOCTL in K7RKScan.sys Allows Arbitrary Termination of High-Privilege and System Processes by a Low-Privilege User — K7 Security Anti-Malware 5.6 Medium2025-06-10
CVE-2025-27505 GeoServer Missing Authorization on REST API Index — geoserver 5.3 Medium2025-06-10
CVE-2025-49509 WordPress Audio Editor & Recorder plugin <= 2.2.1 - Broken Access Control vulnerability — Audio Editor & Recorder 5.3 Medium2025-06-10
CVE-2025-42993 Missing Authorization Check in SAP S/4HANA (Enterprise Event Enablement) — SAP S/4HANA (Enterprise Event Enablement) 6.7 Medium2025-06-10
CVE-2025-42991 Missing Authorization check in SAP S/4HANA (Bank Account Application) — SAP S/4HANA (Bank Account Application) 4.3 Medium2025-06-10
CVE-2025-42989 Missing Authorization check in SAP NetWeaver Application Server for ABAP — SAP NetWeaver Application Server for ABAP 9.6 Critical2025-06-10
CVE-2025-42987 Missing Authorization Check in SAP S/4HANA (Manage Processing Rules - For Bank Statement) — SAP S/4HANA (Manage Processing Rules - For Bank Statement) 4.3 Medium2025-06-10
CVE-2025-42984 Missing Authorization check in SAP S/4HANA (Manage Central Purchase Contract application) — SAP S/4HANA (Manage Central Purchase Contract application) 5.4 Medium2025-06-10
CVE-2025-42983 Missing Authorization check in SAP Business Warehouse and SAP Plug-In Basis — SAP Business Warehouse and SAP Plug-In Basis 8.5 High2025-06-10
CVE-2025-42982 Information Disclosure in SAP GRC (AC Plugin) — SAP GRC (AC Plugin) 8.8 High2025-06-10
CVE-2025-49651 Missing Authorization for Interactive Sessions — BackendAI 8.1 High2025-06-09
CVE-2025-32308 WordPress Team Builder plugin <= 1.5.7 - Broken Access Control Vulnerability — Team Builder 7.6 High2025-06-09
CVE-2025-47463 WordPress Stock Locations for WooCommerce plugin <= 2.8.6 - Broken Access Control Vulnerability — Stock Locations for WooCommerce 7.1 High2025-06-09
CVE-2025-47527 WordPress Icegram Collect – Easy Form, Lead Collection and Subscription plugin <= 1.3.18 - Broken Access Control Vulnerability — Icegram Collect 7.1 High2025-06-09
CVE-2025-48139 WordPress StyleAI plugin <= 1.0.4 - Broken Access Control Vulnerability — StyleAI 6.5 Medium2025-06-09
CVE-2025-48147 WordPress CryptoCloud - Crypto Payment Gateway plugin <= 2.1.2 - Broken Access Control vulnerability — CryptoCloud - Crypto Payment Gateway 6.5 Medium2025-06-09
CVE-2025-49265 WordPress Membership For WooCommerce plugin <= 2.8.1 - Broken Access Control Vulnerability — Membership For WooCommerce 7.5 High2025-06-09
CVE-2025-5894 Honding Technology Smart Parking Management System - Missing Authorization — Smart Parking Management System 8.8 High2025-06-09
CVE-2025-47601 WordPress MaxiBlocks plugin <= 2.1.0 - Arbitrary Option Update to Privilege Escalation vulnerability — MaxiBlocks 8.8 High2025-06-07
CVE-2025-5814 Profiler – What Slowing Down Your WP <= 1.0.0 - Missing Authentication to Unauthenticated Arbitrary Plugin Reactivation via State Restoration — Profiler – What Slowing Down Your WP 5.3 Medium2025-06-07

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.