Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-60705 Windows Client-Side Caching Elevation of Privilege Vulnerability — Windows 10 Version 1607 7.8 High2025-11-11
CVE-2025-59512 Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability — Windows 10 Version 1607 7.8 High2025-11-11
CVE-2025-12480 TrioFox 安全漏洞 — TrioFox 9.1 Critical2025-11-10
CVE-2025-64347 Apollo Router Improperly Enforces Renamed Access Control Directives — router 7.5 High2025-11-07
CVE-2025-12808 Devolutions Server 安全漏洞 — Server 6.5 -2025-11-06
CVE-2025-58337 Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode for doris-mcp-server MCP Server — Apache Doris-MCP-Server 4.3 -2025-11-05
CVE-2025-64110 Cursor: Authentication Bypass Possible via New Cursorignore Write — cursor 6.5AIMediumAI2025-11-04
CVE-2025-43027 Genetec Security Center 安全漏洞 — Genetec Security Center 9.8 Critical2025-10-30
CVE-2025-27093 Sliver does not restricted traffic between Wireguard clients. — sliver 6.3 Medium2025-10-28
CVE-2025-6680 Tutor LMS <= 3.8.3 - Missing Authorization to Sensitive Information Exposure — Tutor LMS – eLearning and online course solution 4.3 Medium2025-10-25
CVE-2025-59273 Azure Event Grid System Elevation of Privilege Vulnerability — Azure Event Grid System 7.3 High2025-10-23
CVE-2025-59500 Azure Notification Service Elevation of Privilege Vulnerability — Azure Notification Service 7.7 High2025-10-23
CVE-2025-62713 Kottster app reinitialization can be re-triggered allowing command injection in development mode — kottster 7.5AIHighAI2025-10-23
CVE-2025-62395 Moodle: external cohort search service leaks system cohort data 4.3 Medium2025-10-23
CVE-2025-62393 Moodle: course access permissions not properly checked in course_output_fragment_course_overview 4.3 Medium2025-10-23
CVE-2025-11853 Sismics Teedy API Endpoint file access control — Teedy 6.3 Medium2025-10-16
CVE-2025-59253 Windows Search Service Denial of Service Vulnerability — Windows 10 Version 1507 5.5 Medium2025-10-14
CVE-2025-59230 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability — Windows 10 Version 1507 7.8 High2025-10-14
CVE-2025-58726 Windows SMB Server Elevation of Privilege Vulnerability — Windows 10 Version 1507 7.5 High2025-10-14
CVE-2025-58724 Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability — Arc Enabled Servers - Azure Connected Machine Agent 7.8 High2025-10-14
CVE-2025-58714 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability — Windows 10 Version 1507 7.8 High2025-10-14
CVE-2025-55694 Windows Error Reporting Service Elevation of Privilege Vulnerability — Windows 11 Version 24H2 7.8 High2025-10-14
CVE-2025-55240 Visual Studio Elevation of Privilege Vulnerability — Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) 7.3 High2025-10-14
CVE-2025-25004 PowerShell Elevation of Privilege Vulnerability — PowerShell 7.4 7.3 High2025-10-14
CVE-2025-59494 Azure Monitor Agent Elevation of Privilege Vulnerability — Azure Monitor 7.8 High2025-10-14
CVE-2025-59201 Network Connection Status Indicator (NCSI) Elevation of Privilege Vulnerability — Windows 10 Version 1507 7.8 High2025-10-14
CVE-2025-59199 Software Protection Platform (SPP) Elevation of Privilege Vulnerability — Windows 10 Version 1809 7.8 High2025-10-14
CVE-2025-47989 Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability — Arc Enabled Servers - Azure Connected Machine Agent 7.0 High2025-10-14
CVE-2025-0033 AMD EPYC 安全漏洞 — AMD EPYC™ 7003 Series Processors (formerly codenamed "Milan") 6.0 Medium2025-10-14
CVE-2025-27258 Ericsson Network Manager: escalation of privilege vulnerability — Ericsson Network Manager(ENM) 8.8AIHighAI2025-10-13

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.