Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5527

5527 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2022-39100 UNISOC chipset 安全漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 7.8 -2022-12-06
CVE-2022-39101 UNISOC chipset 安全漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 7.8 -2022-12-06
CVE-2022-39102 UNISOC chipset 安全漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 7.8 -2022-12-06
CVE-2022-42776 UNISOC chipset 安全漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 7.8 -2022-12-06
CVE-2022-42777 UNISOC chipset 安全漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 7.8 -2022-12-06
CVE-2022-42778 UNISOC chipset 安全漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 7.8 -2022-12-06
CVE-2022-32966 Realtek RTL8111FP-CG - Missing Authorization — RTL8111FP-CG 6.5 Medium2022-11-29
CVE-2022-4169 Theme and plugin translation for Polylang <= 3.2.16 - Missing Authorization — Theme and plugin translation for Polylang (TTfP) 6.5 Medium2022-11-28
CVE-2022-41929 Missing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcore — xwiki-platform 4.9 Medium2022-11-23
CVE-2022-41930 org.xwiki.platform:xwiki-platform-user-profile-ui missing authorization to enable or disable users — xwiki-platform 7.5 High2022-11-23
CVE-2022-41937 Missing Authorization in XWiki Platform — xwiki-platform 9.6 Critical2022-11-22
CVE-2022-43482 WordPress Appointment Booking Calendar plugin <= 1.3.69 - Missing Authorization vulnerability — Appointment Booking Calendar (WordPress plugin) 4.3 Medium2022-11-18
CVE-2022-41692 WordPress Appointment Hour Booking plugin <= 1.3.71 - Missing Authorization vulnerability — Appointment Hour Booking (WordPress plugin) 4.3 Medium2022-11-18
CVE-2022-3920 Consul Peering Imported Nodes/Services Leak — Consul 5.3 Medium2022-11-15
CVE-2022-2450 reSmush.it Image Optimizer < 0.4.4 - Subscriber+ AJAX Calls — reSmush.it : the only free Image Optimizer & compress plugin 4.3 -2022-11-14
CVE-2022-3538 Webmaster Tools Verification <= 1.2 - Unauthenticated Arbitrary Plugin Deactivation — Webmaster Tools Verification 7.5 -2022-11-14
CVE-2022-40223 WordPress SearchWP premium plugin <= 4.2.5 - Broken Authentication vulnerability — SearchWP 5.4 Medium2022-11-08
CVE-2022-3451 Product Stock Manager < 1.0.5 - Subscriber+ Unauthorised AJAX Calls — Product Stock Manager 4.3 -2022-11-07
CVE-2022-3489 WP Hide <= 0.0.2 - Unauthenticated Settings Update — Wp-Hide 5.3 -2022-11-07
CVE-2022-36404 WordPress Simple SEO plugin <= 1.8.12 - Broken Access Control vulnerability — Simple SEO (WordPress plugin) 5.4 Medium2022-11-03
CVE-2022-2696 Restaurant Menu – Food Ordering System – Table Reservation <= 2.3.0 - Missing Authorization on AJAX Actions — Restaurant Menu – Food Ordering System – Table Reservation 6.3 Medium2022-11-03
CVE-2022-3096 WP Total Hacks <= 4.7.2 - Subscriber+ Arbitrary Options Update to Stored XSS — WP Total Hacks 5.4 -2022-10-31
CVE-2022-3320 Bypassing Cloudflare Zero Trust policies using warp-cli set-custom-endpoint command — WARP 6.7 Medium2022-10-28
CVE-2022-3322 Lock WARP switch bypass on WARP mobile client using iOS quick action — WARP 6.7 Medium2022-10-28
CVE-2022-3337 Lock WARP switch bypass by removing VPN profile on iOS mobile client — WARP 6.7 Medium2022-10-28
CVE-2022-3321 Lock WARP switch feature bypass on WARP mobile client for iOS — WARP 6.7 Medium2022-10-28
CVE-2022-3512 Lock WARP switch bypass using warp-cli 'add-trusted-ssid' command — WARP 6.7 Medium2022-10-28
CVE-2022-24669 Anonymous users can register / de-register for configuration change notifications — Access Management 6.5 Medium2022-10-27
CVE-2022-39233 Tuleap subject to Missing Authorization allowing for branch prefix modification — tuleap 4.3 Medium2022-10-19
CVE-2022-3244 Import all XML, CSV & TXT into WordPress < 6.5.8 - Missing Authorisation — Import all XML, CSV & TXT into WordPress 4.2 -2022-10-17

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5527 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.