LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint
The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarc
A vulnerability was found in Fanli2012 native-php-cms 1.0 and classified as critical. This issue affects some unknown pr
A vulnerability, which was classified as critical, was found in pbrong hrms up to 1.0.1. This affects the function HrmsD
A vulnerability has been found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by th
A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function Set
A vulnerability classified as critical was found in D-Link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Managing Settings and Obtaining Sensitive Dat
A vulnerability was found in ageerle ruoyi-ai up to 2.0.1 and classified as critical. Affected by this issue is some unk
A vulnerability classified as critical has been found in ageerle ruoyi-ai up to 2.0.0. Affected is an unknown function o
A vulnerability classified as critical was found in Casdoor up to 1.811.0. This vulnerability affects the function Handl
A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rate
A weakness has been identified in Vaelsys VaelsysV4 4.1.0. This vulnerability affects unknown code of the file /grid/vgr
A security flaw has been discovered in Shenzhen Sixun Business Management System 7/11. This affects an unknown part of t
A vulnerability was detected in Tutorials-Website Employee Management System up to 611887d8f8375271ce8abc704507d46340837
A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of
A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerabili
Microsoft SharePoint Server Remote Code Execution Vulnerability
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and bef
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to acces
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the comment
Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticate
The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intend
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does no
kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies.
TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthor
Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a speci
A vulnerability was found in Tutorials-Website Employee Management System 1.0 and classified as critical. Affected by th
When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing
The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access deb
GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attac
Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization chec
Authorization Bypass Through User-Controlled Key, Externally Controlled Reference to a Resource in Another Sphere, Impro
Kazaar 1.25.12 allows /api/v1/org-id/orders/order-id/documents calls with a modified order-id.
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all
The GenerateBlocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check o
A vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou paramet
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization flaw in th
Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from
A vulnerability was determined in SourceCodester Online Student Clearance System 1.0. The affected element is an unknown
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade
A vulnerability classified as critical has been found in CampCodes School Management Software 1.0. Affected is an unknow
A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as critical. This issue affects some unknown proc
A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0 and classified as critical. Affected by this is
A vulnerability classified as critical was found in ZeroWdd/code-projects studentmanager 1.0. This vulnerability affects
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started