Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network.
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference
GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to i
tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API me
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t
XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a doc
OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfg
The WP-GeoMeta plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wp_aj
The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization plac
Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent bina
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escala
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their pr
Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privile
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z
The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-si
The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The
OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/use
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Authorization vulnerability that could
Redis Enterprise Elevation of Privilege Vulnerability
HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcm
The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authori
The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial o
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Au
Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.
Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to se
Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4
The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to i
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll ma
OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can crea
Microsoft SharePoint Server Remote Code Execution Vulnerability
Windows App Package Installer Elevation of Privilege Vulnerability
In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the
This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw c
An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization d
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6
Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.
Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated use
Gradio is an open-source Python package that allows quick building of demos and web application for machine learning mod
The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is
The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to
NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.
Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started