Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-34733 AVideo: Unauthenticated File Deletion via PHP Operator Precedence Bug in CLI Guard — AVideo 6.5 Medium2026-03-31
CVE-2026-34381 Admidio: Unauthenticated Access to Role-Restricted documents via neutralized .htaccess — admidio 7.5 High2026-03-31
CVE-2026-33415 Discourse: Improper Access Control in discourse-ai Allows Unauthorized Category Content Exposure — discourse 2.7 -2026-03-31
CVE-2026-5124 osrg GoBGP BGP Header bgp.go BGPHeader.DecodeFromBytes access control — GoBGP 3.7 Low2026-03-30
CVE-2026-5122 osrg GoBGP BGP OPEN Message bgp.go DecodeFromBytes access control — GoBGP 3.7 Low2026-03-30
CVE-2026-5107 FRRouting FRR EVPN Type-2 Route bgp_evpn.c process_type2_route access control — FRR 4.2 Medium2026-03-30
CVE-2026-31950 LibreChat's IDOR in SSE Stream Subscription Allows Reading Other Users' Chats — LibreChat 5.3 Medium2026-03-27
CVE-2026-33890 MyTube has an Unauthenticated Admin Privilege Escalation via Passkey Registration — MyTube 9.8 -2026-03-27
CVE-2026-33726 Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic — cilium 5.4 Medium2026-03-27
CVE-2026-0748 Access bypass in Drupal 7 i18n_node translation UI — Internationalization (i18n) - i18n_node submodule 4.3 -2026-03-26
CVE-2025-55261 HCL Aftermarket DPC is affected by Missing Functional Level Access Control — Aftermarket DPC 8.1 High2026-03-26
CVE-2026-33316 Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement — vikunja 8.1 High2026-03-24
CVE-2026-33484 Langflow has Unauthenticated IDOR on Image Downloads — langflow 7.5 High2026-03-24
CVE-2026-32299 Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature — connect-cms 7.5 High2026-03-23
CVE-2026-0898 An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Microsoft Edge using either version 22.1 or R25. — Pega Robot Studio 8.1 -2026-03-23
CVE-2026-4628 Keycloak: org.keycloak.authorization: keycloak: unauthorized resource modification due to improper access control — Red Hat Build of Keycloak 4.3 Medium2026-03-23
CVE-2026-4514 PbootCMS Backend UserController.php access control — PbootCMS 6.3 Medium2026-03-21
CVE-2026-32768 Chall-Manager's invalid NetworkPolicy enables a malicious actor to pivot into another namespace — chall-manager 9.1 -2026-03-20
CVE-2026-33062 free5GC NRF Discovery EncodeGroupId Function Panics on Malformed group-id-list Parameter — nrf 7.5 -2026-03-20
CVE-2026-32769 Fullchain's Invalid NetworkPolicy enables a malicious actor to pivot into another namespace — fullchain 7.3 -2026-03-20
CVE-2026-32761 File Browser has an Authorization Policy Bypass in its Public Share Download Flow — filebrowser 6.5 Medium2026-03-19
CVE-2026-32038 OpenClaw - Sandbox Network Isolation Bypass via docker.network=container Parameter — OpenClaw 9.8 Critical2026-03-19
CVE-2026-33393 Discourse fixes loose hostname matching in spam host allowlist — discourse 4.3 Medium2026-03-19
CVE-2026-32752 FreeScout: Broken Access Control in ThreadPolicy — Any User Can Read/Edit All Customer Messages — freescout--2026-03-19
CVE-2026-32737 Romeo's invalid NetworkPolicy enables a malicious actor to pivot into another namespace — romeo 9.8 -2026-03-18
CVE-2025-41258 LibreChat RAG API Authentication Bypass — LibreChat 8.0 High2026-03-18
CVE-2026-32254 Kube-router Proxy Module Blindly Trusts ExternalIPs/LoadBalancer IPs Enabling Cluster-Wide Traffic Hijacking and DNS DoS — kube-router 7.1 High2026-03-18
CVE-2026-3111 Multiple vulnerabilities on the Educativa Campus — Campus 6.5AIMediumAI2026-03-16
CVE-2026-3110 Multiple vulnerabilities on the Educativa Campus — Campus 5.3AIMediumAI2026-03-16
CVE-2026-4194 D-Link DNS-1550-04 system_mgr.cgi cgi_set_wto access control — DNS-120 7.3 High2026-03-15

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.