Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-29060 Gokapi: Privilege escalation with auth token — Gokapi 5.0 Medium2026-03-06
CVE-2026-28682 Gokapi: Data Leak in Upload Status Stream — Gokapi 6.4 Medium2026-03-06
CVE-2026-25877 Chartbrew: Insecure Direct Object Reference (IDOR) in Chart Operations — chartbrew 6.5 Medium2026-03-06
CVE-2026-29077 Frappe: Broken Access Control in DocShare — frappe 7.1 High2026-03-05
CVE-2026-28410 The Graph: Revocable vesting contracts allows early access to locked tokens — contracts 8.1 -2026-03-05
CVE-2026-28790 OliveTin: Unauthenticated Action Termination via KillAction When Guests Must Login — OliveTin 7.5 High2026-03-05
CVE-2026-27723 OpenProject: Insufficient access control leads to create Wiki objects belongs unpermitted projects — openproject 4.3 Medium2026-03-05
CVE-2026-25702 nftables disabled due to incorrect kernel backport — SUSE Linux Enterprise Server 7.3 High2026-03-05
CVE-2026-20073 Cisco Secure Firewall Adaptive Security Appliance Software and Cisco Secure Firewall Threat Defense Software Access Control List Bypass Vulnerability — Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 5.8 Medium2026-03-04
CVE-2026-20007 Cisco Secure Firewall Threat Defense Software Snort Deep Inspection Bypass Vulnerability — Cisco Secure Firewall Threat Defense (FTD) Software 5.8 Medium2026-03-04
CVE-2025-15597 Dataease SQLBot API Endpoint assistant.py access control — SQLBot 6.3 Medium2026-03-02
CVE-2026-3268 psi-probe PSI Probe Session Attribute RemoveSessAttributeController.java access control — PSI Probe 5.4 Medium2026-02-26
CVE-2026-28230 In SteVe, any authenticated charger can terminate any other charger's active transaction (missing ownership verification on StopTransaction) — steve 5.7AIMediumAI2026-02-26
CVE-2026-28215 hoppscotch Vulnerable to Unauthenticated Onboarding Config Takeover — hoppscotch 9.1 Critical2026-02-26
CVE-2026-27449 Umbraco.Engage.Forms Allows Unauthorized Access to Multiple API Endpoints — Umbraco.Engage.Forms 7.5 High2026-02-26
CVE-2026-28218 Discourse's Fail-Open Access Control in Data Explorer Plugin Allows Unauthorized SQL Query Execution — discourse 8.8AIHighAI2026-02-26
CVE-2026-27152 DIscourse has DM communication-preference bypass when adding members — discourse 4.3AIMediumAI2026-02-26
CVE-2026-27975 Ajenti has a potential Remote Code Execution — ajenti 9.8AICriticalAI2026-02-26
CVE-2026-2356 User Registration & Membership <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion — User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder 5.3 Medium2026-02-26
CVE-2026-22728 sealed-secrets /v1/rotate can widen sealing scope to cluster-wide via attacker-controlled template annotations — sealed-secrets 4.9 Medium2026-02-26
CVE-2026-3209 fosrl Pangolin Role verifyApiKeyRoleAccess access control — Pangolin 6.3 Medium2026-02-25
CVE-2026-27624 Coturn: IPv4-mapped IPv6 (::ffff:0:0/96) bypasses denied-peer-ip ACL — coturn 7.2 High2026-02-25
CVE-2026-24896 OpenEMR has Broken Access Control that allows unauthorized access to EDI Logs — openemr 6.5 Medium2026-02-25
CVE-2026-25966 ImageMagick's Security Policy Bypass through config/policy-secure.xml via "fd handler" leads to stdin/stdout access — ImageMagick 5.9 Medium2026-02-24
CVE-2026-2983 SourceCodester Student Result Management System Bulk Import import_users.php access control — Student Result Management System 7.3 High2026-02-23
CVE-2026-2938 SourceCodester Student Result Management System update_smtp.php access control — Student Result Management System 7.3 High2026-02-22
CVE-2026-2852 yeqifu warehouse Sales Endpoint SalesController.java deleteSales access control — warehouse 6.3 Medium2026-02-20
CVE-2026-2851 yeqifu warehouse Inport Endpoint InportController.java deleteInport access control — warehouse 6.3 Medium2026-02-20
CVE-2026-2850 yeqifu warehouse Customer Endpoint CustomerController.java deleteCustomer access control — warehouse 6.3 Medium2026-02-20
CVE-2026-2849 yeqifu warehouse Cache Sync CacheController.java syncCache access control — warehouse 5.4 Medium2026-02-20

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.