Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-284 (访问控制不恰当) — Vulnerability Class 2041

2041 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-25519 OpenSlides has incorrect access control vulnerability in authentication service — OpenSlides 8.1 High2026-02-04
CVE-2026-24668 Open eClass Broken Access Control Allows Students to Add Content to Course Units — openeclass 6.5 Medium2026-02-03
CVE-2026-24670 Open eClass Has Broken Access Control in Course Units Module Allows Students to Create Units — openeclass 6.5 Medium2026-02-03
CVE-2020-37116 GUnet OpenEclass 1.7.3 E-learning platform - phpMyAdmin Remote Access — GUnet OpenEclass 8.8 High2026-02-03
CVE-2026-1117 Improper Access Control in parisneo/lollms — parisneo/lollms 8.1AIHighAI2026-02-02
CVE-2026-24904 TrustTunnel has `client_random_prefix` rule bypass via fragmented or partial TLS ClientHello — TrustTunnel 5.3 Medium2026-01-29
CVE-2025-7016 Improper Access Control in Akinsoft's QR Menu — QR Menu 8.0 High2026-01-29
CVE-2025-46691 Dell PremierColor Panel Driver 访问控制错误漏洞 — PremierColor 7.8 High2026-01-28
CVE-2026-0844 Simple User Registration <= 6.7 - Authenticated (Subscriber+) Privilege Escalation via profile_save_field — Simple User Registration 8.8 High2026-01-28
CVE-2025-67645 OpenEMR Vulnerable to Broken Access Control in Profile Edit Endpoint — openemr 8.8 High2026-01-27
CVE-2026-24740 Dozzle Agent Label-Based Access Control Bypass Allows Unauthorized Container Shell Access — dozzle 8.1AIHighAI2026-01-27
CVE-2026-1411 Beetel 777VR1 UART access control — 777VR1 6.1 Medium2026-01-26
CVE-2026-24420 phpMyFAQ: Attachment download allowed without dlattachment right (broken access control) — phpMyFAQ 6.5 Medium2026-01-24
CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability — Azure Resource Manager 9.9 Critical2026-01-23
CVE-2026-24306 Azure Front Door Elevation of Privilege Vulnerability — Azure Front Door 9.8 Critical2026-01-22
CVE-2026-20897 Gitea Git LFS Lock Deletion Broken Access Control (Cross-Repo IDOR) — Gitea Open Source Git Server 6.5AIMediumAI2026-01-22
CVE-2026-20904 Gitea: Broken access control in OpenID visibility toggle enables cross-user visibility changes — Gitea Open Source Git Server 4.3AIMediumAI2026-01-22
CVE-2026-20912 Gitea: Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment Disclosure — Gitea Open Source Git Server 7.5AIHighAI2026-01-22
CVE-2026-20888 Gitea Pull Requests Auto-Merge: Read-Only Users Can Cancel Scheduled Auto-Merge via Web Endpoint (Authorization Bypass) — Gitea Open Source Git Server 4.3AIMediumAI2026-01-22
CVE-2026-20883 Gitea Stopwatch API Missing Authorization Check Leads to Post-Revocation Information Disclosure — Gitea Open Source Git Server 5.3AIMediumAI2026-01-22
CVE-2026-20736 Gitea Web Attachment Deletion: Cross-Repository Unauthorized Deletion via Missing Repo Ownership Check — Gitea Open Source Git Server 6.5AIMediumAI2026-01-22
CVE-2026-20750 Gitea Organization Projects Cross-Organization Authorization Bypass via Project ID (IDOR) — Gitea Open Source Git Server 6.5AIMediumAI2026-01-22
CVE-2026-0798 Gitea Release Email Notifications Leak Private Repository Release Details After Access Revocation — Gitea Open Source Git Server 3.5AILowAI2026-01-22
CVE-2026-24039 Horilla's Improper Access Control Allows Employees to Auto-Approve Documents — horilla 4.3 Medium2026-01-22
CVE-2026-24036 Horilla Exposes Unpublished Job Disclosures through Unauthenticated API — horilla 5.3 Medium2026-01-22
CVE-2026-24055 Langfuse Slack OAuth Installation Endpoint Lacks Authentication, Enabling Arbitrary Project Linking — langfuse 6.5AIMediumAI2026-01-22
CVE-2026-24035 Horilla has Improper Access Control Issue that Allows Unauthorized Document Upload on Behalf of Another Employee — horilla 4.3 Medium2026-01-22
CVE-2025-14083 Keycloak-server: keycloak: improper access control in admin rest api leads to information disclosure — Red Hat build of Keycloak 26.4 2.7 Low2026-01-21
CVE-2025-14977 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy 8.1 High2026-01-20
CVE-2026-23522 Lobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File Deletion — lobe-chat 3.7 Low2026-01-19

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2041 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.