Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, the GET /forms endpoint read table
Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows o
A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functiona
A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci
A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the f
A security flaw has been discovered in Eleveo Call Recording Software 9.7.0. Impacted is an unknown function of the file
tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on
A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat
A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the funct
A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the fil
SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the
An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to upd
Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credenti
A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affe
A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unk
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper
A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This affects the function DBUpdate of the file Disciplin
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality
A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the
The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized acc
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from
Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authent
A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function P
Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeep
A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even afte
A flaw has been found in JeecgBoot 3.9.1. The impacted element is an unknown function of the file jeecg-module-system/je
A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourne
A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document
A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the l
A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of th
A logic issue was addressed with improved validation. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5,
A flaw has been found in Freedom Factory dGEN1 up to 20260221. Affected by this vulnerability is the function TokenBalan
A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPor
A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.s
The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking
A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversa
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_
The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized modification of data due to an i
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source accepts chan
A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file
A vulnerability was identified in AliasVault App up to 0.25.3 on Android/iOS. This vulnerability affects unknown code of
A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown proc
Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attacker
A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAut
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown
A Improper Authorization vulnerability in Foomuuri llows arbitrary users to influence the firewall configuration.This is
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started