Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-21627 Extension - tassos.gr - SQL injection and Unauthenticated File Read in Novarain/Tassos Framework v4.10.14 – v6.0.37 for Joomla — Novarain/Tassos Framework (plg_system_nrframework) 9.1AICriticalAI2026-02-20
CVE-2026-26328 OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities — openclaw 6.5 Medium2026-02-19
CVE-2026-26325 OpenClaw Node host system.run rawCommand/command mismatch can bypass allowlist/approvals — openclaw 7.2 High2026-02-19
CVE-2026-21535 Microsoft Teams Information Disclosure Vulnerability — Microsoft Teams 8.2 High2026-02-19
CVE-2025-12884 Advanced Ads – Ad Manager & AdSense <= 2.0.14 - Missing Authorization to Authenticated (Subscriber+) Ad Placements Update — Advanced Ads – Ad Manager & AdSense 4.3 Medium2026-02-19
CVE-2026-25229 Gogs Authorization Bypass Allows Cross-Repository Label Modification — gogs 4.3 -2026-02-19
CVE-2026-2669 Rongzhitong Visual Integrated Command and Dispatch Platform User delete access control — Visual Integrated Command and Dispatch Platform 6.5 Medium2026-02-18
CVE-2026-2668 Rongzhitong Visual Integrated Command and Dispatch Platform User add access control — Visual Integrated Command and Dispatch Platform 7.3 High2026-02-18
CVE-2026-2667 Rongzhitong Visual Integrated Command and Dispatch Platform api access control — Visual Integrated Command and Dispatch Platform 5.3 Medium2026-02-18
CVE-2023-38005 Improper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak System[, ] — Cloud Pak System 4.3 Medium2026-02-17
CVE-2026-2592 Zarinpal Gateway for WooCommerce <= 5.0.16 - Improper Access Control to Payment Status Update — Zarinpal Gateway 7.7 High2026-02-17
CVE-2026-2549 zhanghuanhao LibrarySystem 图书馆管理系统 BookController.java access control — LibrarySystem 图书馆管理系统 7.3 High2026-02-16
CVE-2026-23856 Dell iDRAC Service Module 访问控制错误漏洞 — iDRAC Service Module 7.8 High2026-02-12
CVE-2026-2250 Unauthenticated Data Export and Source Code Disclosure via /dbviewer/ in METIS WIC — METIS WIC 7.5 High2026-02-11
CVE-2025-29939 AMD Processors 安全漏洞 — AMD EPYC™ 9004 Series Processors 5.1AIMediumAI2026-02-10
CVE-2026-21238 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability — Windows 10 Version 1607 7.8 High2026-02-10
CVE-2026-21255 Windows Hyper-V Security Feature Bypass Vulnerability — Windows 10 Version 1607 8.8 High2026-02-10
CVE-2026-0653 Insecure Access Control on TP-Link Tapo D235 and C260 — Tapo C260 v1 8.1AIHighAI2026-02-10
CVE-2026-25231 FileRise affected by an Unauthenticated File Read Due to Insufficient Access Control — FileRise 7.5 High2026-02-09
CVE-2026-2206 WeKan Administrative Repair fixDuplicateLists.js FixDuplicateBleed access control — WeKan 6.3 Medium2026-02-08
CVE-2026-2075 yeqifu warehouse Role-Permission Binding RoleController.java saveRolePermission access control — warehouse 6.3 Medium2026-02-07
CVE-2026-2009 SourceCodester Gas Agency Management System createUser.php access control — Gas Agency Management System 6.3 Medium2026-02-06
CVE-2026-24300 Azure Front Door Elevation of Privilege Vulnerability — Azure Front Door 9.8 Critical2026-02-05
CVE-2026-24302 Azure Arc Elevation of Privilege Vulnerability — Azure ARC 8.6 High2026-02-05
CVE-2026-1964 WeKan REST Endpoint boards.js BoardTitleRESTBleed access control — WeKan 4.3 Medium2026-02-05
CVE-2026-1963 WeKan Attachment Storage attachments.js MoveStorageBleed access control — WeKan 6.3 Medium2026-02-05
CVE-2026-1962 WeKan Attachment Migration attachmentMigration.js AttachmentMigrationBleed access control — WeKan 6.3 Medium2026-02-05
CVE-2026-1898 WeKan LDAP User Sync syncUser.js SyncLDAPBleed access control — WeKan 6.3 Medium2026-02-05
CVE-2026-1896 WeKan Migration Operation comprehensiveBoardMigration.js ComprehensiveBoardMigration MigrationBleed access control — WeKan 6.3 Medium2026-02-04
CVE-2026-1895 WeKan Attachment Storage lists.js applyWipLimit ListWIPBleed access control — WeKan 6.3 Medium2026-02-04

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.