Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions u
When adding a key to a remote agent constraint extensions such as [email protected] were not serializ
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permissio
A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient val
NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improp
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' e
Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions.
The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. Wh
Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation a
The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/E
When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2
in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected sy
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on pu
The mv utility in uutils coreutils fails to preserve file ownership during moves across different filesystem boundaries.
The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delet
The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting
A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. Ne
Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station befo
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and downl
A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain
Frequently Asked Questions
What is CWE-281?
CWE-281 (CWE-281) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-281?
There are 25 CVE records associated with CWE-281 in our database. Of these, 3 are critical severity, 5 are high severity, and 9 are medium severity.
How can I protect against CWE-281 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-281 using AI-powered security agents.
Detect CWE-281 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-281 vulnerabilities across your infrastructure.
Get Started