Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-4065 ScriptAndTools Online-Travling-System addadvertisement.php access control — Online-Travling-System 7.3 High2025-04-29
CVE-2025-4064 ScriptAndTools Online-Travling-System viewenquiry.php access control — Online-Travling-System 5.3 Medium2025-04-29
CVE-2025-4036 201206030 Novel Chapter AuthorController.java updateBookChapter access control — Novel 6.3 Medium2025-04-28
CVE-2025-32470 Unauthenticated change of IP adress — SICK FLX0-GPNT100 7.5 High2025-04-28
CVE-2025-43862 Dify Allows Unauthorized Access and Modification of APP Orchestration — dify 7.6 High2025-04-25
CVE-2024-30148 HCL Leap is affected by improper access control — HCL Leap 4.1 Medium2025-04-24
CVE-2025-32796 Dify Allows Unauthorized APP Enable/Disable via API — dify 6.5 Medium2025-04-18
CVE-2025-32795 Dify Allows Insecure User Role Access Control for APP Editing — dify 6.5 Medium2025-04-18
CVE-2025-3790 baseweb JSite Apache Druid Monitoring Console index.html access control — JSite 5.3 Medium2025-04-18
CVE-2025-32790 Dify Allows Insecure User Role Access Control for APP DSL Exporting — dify 6.3 Medium2025-04-18
CVE-2025-3113 Improper Access Control in Delphix Masking Engine — Delphix 5.3AIMediumAI2025-04-17
CVE-2025-3675 TOTOLINK A3700R cstecgi.cgi setL2tpServerCfg access control — A3700R 5.3 Medium2025-04-16
CVE-2025-3674 TOTOLINK A3700R cstecgi.cgi setUrlFilterRules access control — A3700R 5.3 Medium2025-04-16
CVE-2025-3668 TOTOLINK A3700R cstecgi.cgi setScheduleCfg access control — A3700R 5.3 Medium2025-04-16
CVE-2025-3667 TOTOLINK A3700R cstecgi.cgi setUPnPCfg access control — A3700R 5.3 Medium2025-04-16
CVE-2025-3666 TOTOLINK A3700R cstecgi.cgi setDdnsCfg access control — A3700R 5.3 Medium2025-04-16
CVE-2025-3665 TOTOLINK A3700R cstecgi.cgi setSmartQosCfg access control — A3700R 5.3 Medium2025-04-16
CVE-2025-3664 TOTOLINK A3700R cstecgi.cgi setWiFiEasyGuestCfg access control — A3700R 5.3 Medium2025-04-16
CVE-2025-3663 TOTOLINK A3700R Password cstecgi.cgi setWiFiEasyGuestCfg access control — A3700R 5.3 Medium2025-04-16
CVE-2025-30100 Dell Alienware Command Center 访问控制错误漏洞 — Alienware Command Center (AWCC) 6.7 Medium2025-04-16
CVE-2025-29984 Dell Trusted Device 访问控制错误漏洞 — Dell Trusted Device Client 6.7 Medium2025-04-15
CVE-2025-32726 Visual Studio Code Elevation of Privilege Vulnerability — Visual Studio Code 6.8 Medium2025-04-12
CVE-2025-23389 Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login — rancher 8.4 High2025-04-11
CVE-2025-27190 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 5.3 Medium2025-04-08
CVE-2025-27191 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce 5.3 Medium2025-04-08
CVE-2025-30288 ColdFusion | Improper Access Control (CWE-284) — ColdFusion 8.2 High2025-04-08
CVE-2025-30281 ColdFusion | Improper Access Control (CWE-284) — ColdFusion 9.1 Critical2025-04-08
CVE-2025-29810 Active Directory Domain Services Elevation of Privilege Vulnerability — Windows 10 Version 1507 7.5 High2025-04-08
CVE-2025-29804 Visual Studio Elevation of Privilege Vulnerability — Microsoft Visual Studio 2022 version 17.10 7.3 High2025-04-08
CVE-2025-27738 Windows Resilient File System (ReFS) Information Disclosure Vulnerability — Windows 10 Version 1507 6.5 Medium2025-04-08

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.