Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-40252 Broken Access Control (IDOR) Leading to Cross-Tenant Application Access in FastGPT — FastGPT 8.8 -2026-04-10
CVE-2026-39942 Directus has a Path Traversal and Broken Access Control in File Management API — directus 8.5 High2026-04-09
CVE-2026-34723 Zammad has incorrect access control in getting_started_controller — zammad 7.5AIHighAI2026-04-08
CVE-2026-34248 Zammad has an information disclosure in ticket detail view of customers in shared organizations — zammad 3.5AILowAI2026-04-08
CVE-2026-35533 mise has a local settings bypass config trust checks — mise 7.8 High2026-04-07
CVE-2026-39346 OrangeHRM has Improper Access Control Allowing Access to Disabled Modules via URL Encoding — orangehrm 8.8AIHighAI2026-04-07
CVE-2026-39339 ChurchCRM has an API Authentication Bypass — CRM 9.1 Critical2026-04-07
CVE-2026-1079 A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Automation who have installed Pega Browser Extension. — Pega Browser Extension (PBE) 5.4AIMediumAI2026-04-07
CVE-2026-1078 An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R25 users who are running automations that work with Google Chrome or Microsoft Edge. — Pega Robot Studio 8.1AIHighAI2026-04-07
CVE-2026-1114 Improper Access Control via Weak JWT Token in parisneo/lollms — parisneo/lollms 9.8AICriticalAI2026-04-07
CVE-2026-35185 HAX CMS's public /server-status endpoint exposes authentication tokens, user activity, and client IP addresses — HAXiam 7.5AIHighAI2026-04-06
CVE-2026-35172 Distribution has stale blob access resurrection via repo-scoped redis descriptor cache invalidation — distribution 7.5 High2026-04-06
CVE-2026-34444 Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr — lupa 9.8 -2026-04-06
CVE-2026-5569 Technostrobe HI-LED-WR120-G2 Endpoint access control — HI-LED-WR120-G2 7.3 High2026-04-05
CVE-2026-5526 Tenda 4G03 Pro httpd access control — 4G03 Pro 7.3 High2026-04-04
CVE-2026-35616 Fortinet FortiClientEms 安全漏洞 — FortiClientEMS 9.1 Critical2026-04-04
CVE-2017-20233 Hirschmann HiLCOS Layer-2 Firewall Multicast Broadcast Traffic Bypass — Hirschmann HiLCOS OpenBAT, BAT450, WLC 5.4 Medium2026-04-03
CVE-2021-4477 Hirschmann HiLCOS OpenBAT BAT450 IPv6 IPsec Firewall Bypass — Hirschmann HiLCOS OpenBAT 9.1 Critical2026-04-03
CVE-2026-5484 BookStackApp BookStack Chapter Export ExportFormatter.php chapterToMarkdown access control — BookStack 5.3 Medium2026-04-03
CVE-2026-33951 signalk-server: Unauthenticated Source Priorities Manipulation — signalk-server 7.5AIHighAI2026-04-02
CVE-2026-5330 SourceCodester/mayuri_k Best Courier Management System User Delete ajax.php access control — Best Courier Management System 6.5 Medium2026-04-02
CVE-2026-34572 CI4MS: Account Deactivation Module Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw) — ci4ms 8.8 High2026-04-01
CVE-2026-34570 CI4MS: Account Deletion Module Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw) — ci4ms 8.8 High2026-04-01
CVE-2026-5312 D-Link DNS-1550-04 dsk_mgr.cgi Get_current_raidtype access control — DNS-120 5.3 Medium2026-04-01
CVE-2026-34456 Reviactyl: OAuth account takeover via auto-linking — panel 9.1 Critical2026-04-01
CVE-2026-5311 D-Link DNS-1550-04 file_center.cgi Webdav_Access_List access control — DNS-120 5.3 Medium2026-04-01
CVE-2026-21629 Joomla! Core - [20260301] - ACL hardening in com_ajax — Joomla! CMS 9.8AICriticalAI2026-04-01
CVE-2026-23899 Joomla! Core - [20260306] - Improper access check in webservice endpoints — Joomla! CMS 8.1AIHighAI2026-04-01
CVE-2026-4947 Insecure Direct Object Reference (IDOR) Leading to Signature Forgery in Foxit eSign — na1.foxitesign.foxit.com 7.1 High2026-04-01
CVE-2026-5215 D-Link DNS-1550-04 network_mgr.cgi cgi_get_ipv6 access control — DNS-120 4.3 Medium2026-03-31

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.