Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-33318 Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers — actual 8.8 High2026-04-24
CVE-2026-29197 XX软件<8.4.0等版权限检查拼写漏洞致越权读日志 — Rocket.Chat 4.3AIMediumAI2026-04-23
CVE-2026-24303 Microsoft Partner Center Elevation of Privilege Vulnerability — Microsoft Partner Center 9.6 Critical2026-04-23
CVE-2026-41277 Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR) — Flowise 8.8AIHighAI2026-04-23
CVE-2026-41270 Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox — Flowise 7.1 High2026-04-23
CVE-2026-41243 OpenLearn's pending forum posts remain publicly readable by direct ID when moderation mode is enabled — OpenLearn 4.3AIMediumAI2026-04-23
CVE-2026-41166 OpenRemote has Improper Access Control via updateUserRealmRoles function — openremote 7.0 High2026-04-22
CVE-2026-40889 Frappe HR has Improper Access Control on Files — hrms 6.5 Medium2026-04-21
CVE-2026-40888 Frappe HR vulnerable to Improper Access Control — hrms 6.5AIMediumAI2026-04-21
CVE-2026-40874 mailcow: dockerized missing authorization on Forwarding Hosts delete action — mailcow-dockerized 5.4AIMediumAI2026-04-21
CVE-2026-40867 Horilla: Unauthorized Helpdesk Attachment Access via Attachment ID Manipulation — horilla 6.5AIMediumAI2026-04-21
CVE-2026-40866 Horilla: Unauthorized Document Overwrite via File Upload Endpoint — horilla 4.3AIMediumAI2026-04-21
CVE-2026-40865 Horilla: Insecure Direct Object Reference at `/employee/view-file/<int:id> — horilla 6.5AIMediumAI2026-04-21
CVE-2026-40569 FreeScout's Mass Assignment in Mailbox Connection Settings Enables Silent Email Exfiltration — freescout 9.0 Critical2026-04-21
CVE-2026-33031 Nginx-UI: Disabled users retain full API access through previously issued bearer tokens — nginx-ui 8.8AIHighAI2026-04-20
CVE-2026-40474 wger has Broken Access Control in the Global Gym Configuration Update Endpoint — wger 7.6 High2026-04-17
CVE-2026-40304 zrok's broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records — zrok 5.3 Medium2026-04-17
CVE-2026-35402 mcp-neo4j-cypher: SSRF and Data Modification via read_only Mode Bypass Through CALL Procedures — mcp-neo4j 9.8AICriticalAI2026-04-17
CVE-2026-31843 Для национальных платежных систем в Узбекистане 安全漏洞 — pay-uz 9.8 Critical2026-04-16
CVE-2026-33212 Weblate: Improper access control for pending tasks in API — weblate 3.1 Low2026-04-15
CVE-2026-20203 Improper Access Control in Data Model Acceleration in Splunk Enterprise — Splunk Enterprise 4.3 Medium2026-04-15
CVE-2026-32214 Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability — Windows 10 Version 1607 5.5 Medium2026-04-14
CVE-2026-33103 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability — Microsoft Dynamics 365 (on-premises) version 9.0 5.5 Medium2026-04-14
CVE-2026-27914 Microsoft Management Console Elevation of Privilege Vulnerability — Windows 10 Version 1607 7.8 High2026-04-14
CVE-2026-32220 UEFI Secure Boot Security Feature Bypass Vulnerability — Windows 11 Version 24H2 4.4 Medium2026-04-14
CVE-2026-26183 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability — Windows Server 2012 7.8 High2026-04-14
CVE-2026-22564 Ubiquiti UniFi Play PowerAmp和Ubiquiti UniFi Play Audio Port 安全漏洞 — UniFi Play PowerAmp 9.8 Critical2026-04-13
CVE-2026-22566 Ubiquiti UniFi Play PowerAmp和Ubiquiti UniFi Play Audio Port 安全漏洞 — UniFi Play PowerAmp 7.5 High2026-04-13
CVE-2026-6201 CodeAstro Online Job Portal Delete Job Posting job-delete.php access control — Online Job Portal 5.4 Medium2026-04-13
CVE-2026-34860 Huawei HarmonyOS 安全漏洞 — HarmonyOS 4.1 Medium2026-04-13

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.