Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-285

MITRE ↗

CWE-285

120
CRITICAL
432
HIGH
860
MEDIUM
81
LOW
1,527 CVEs · Page 11/31
CVE-2025-59100

The web interface offers a functionality to export the internal SQLite database. After executing the database export, an

CVE-2026-42875

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete

CVE-2026-44504

Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared

CVE-2026-45371

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Con

CVE-2026-45297

OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assi

CVE-2026-33398

NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/pages/forum/get_quotes.php` only

CVE-2026-41522

Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior

CVE-2026-46668

SpiceDB is an open source database system for creating and managing security-critical application permissions. From vers

CVE-2026-44208

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "su

CVE-2026-48089

DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instanc

CVE-2026-12673

Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalati

CVE-2026-50279

Craft CMS is a content management system (CMS). IN versions 5.0.0-RC1 and above prior to 5.9.21, theEntriesController::a

CVE-2026-27823

A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an auth

CVE-2026-34239

Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax

CVE-2026-47726

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern

CVE-2026-48499

Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code

CVE-2026-48115

Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but

CVE-2026-70472

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-

CVE-2026-47663

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-73421

NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate

CVE-2026-21584

This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.

CVE-2026-76243

stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments

CVE-2026-35445

Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend d

CVE-2026-54766

Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operati

10.0
CVE-2025-65041

Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

9.9
CVE-2025-30390

Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.

9.9
CVE-2025-29827

Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.

9.9
CVE-2025-49746

Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

9.8
CVE-2024-56323

OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19,

9.8
CVE-2025-25196

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z

9.8
CVE-2025-2345

A vulnerability, which was classified as very critical, was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. T

9.8
CVE-2025-29926

XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager

9.8
CVE-2025-29659

Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" bi

9.8
CVE-2025-30392

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

9.8
CVE-2025-3918

The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the reg

9.8
CVE-2025-4104

The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t

9.8
CVE-2025-4631

The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stockt

9.8
CVE-2025-7778

The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and im

9.8
CVE-2025-31255

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26 and iPadOS 26, macOS

9.8
CVE-2025-63218

The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Contr

9.8
CVE-2025-64063

Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specif

9.8
CVE-2025-58386

In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper serv

9.8
CVE-2023-53895

PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts

9.6
CVE-2025-29922

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior t

9.6
CVE-2025-63691

In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the

9.6
CVE-2025-66301

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical

9.1
CVE-2024-13241

Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue

9.1
CVE-2025-20125

A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to

9.1
CVE-2025-29927

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions

9.1
CVE-2025-53792

Azure Portal Elevation of Privilege Vulnerability

Frequently Asked Questions

What is CWE-285?

CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-285?

There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.

How can I protect against CWE-285 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.

Detect CWE-285 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.

Get Started