A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file
A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown func
A vulnerability has been found in TDuckCloud tduck-platform up to 5.1 and classified as critical. Affected by this vulne
A vulnerability was found in LitmusChaos Litmus up to 3.19.0. It has been rated as critical. This issue affects some unk
A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/
A security flaw has been discovered in LiuYuYang01 ThriveX-Blog up to 3.1.7. Affected by this vulnerability is the funct
A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. P
A vulnerability was found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /educac
A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Hi
A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Api/m
A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file
A weakness has been identified in YunaiV yudao-cloud up to 2025.09. This affects an unknown part of the file /crm/busine
A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown cod
A vulnerability was detected in YunaiV yudao-cloud up to 2025.09. This issue affects some unknown processing of the file
A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/tr
A weakness has been identified in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of th
A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of t
A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessage
A vulnerability was determined in YunaiV yudao-cloud up to 2025.09. Affected by this issue is some unknown functionality
A vulnerability was identified in YunaiV ruoyi-vue-pro up to 2025.09. This affects an unknown part of the file /crm/busi
A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the f
A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Ap
A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unkno
A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of
A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. E
A vulnerability was identified in macrozheng mall-swarm up to 1.0.3. This affects the function updateAttr of the file /c
A vulnerability was detected in macrozheng mall-swarm up to 1.0.3. Affected by this issue is the function paySuccess of
A vulnerability was detected in code-projects Blog Site 1.0. The affected element is an unknown function of the file /ad
A vulnerability was determined in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is an unknown functionality of
A vulnerability was identified in Himool ERP up to 2.2. Affected by this issue is the function update_account of the fil
Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the imprope
A weakness has been identified in getmaxun maxun up to 0.0.28. The affected element is the function router.get of the fi
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported v
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Object and Environment Tech
FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to ve
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyvern
A vulnerability was found in Shiprocket Module 3 on OpenCart. It has been rated as critical. Affected by this issue is s
Information disclosure while deriving keys for a session for any Widevine use case.
A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8. An app may be able to access
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.
The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Feature
A vulnerability was found in itwanger paicoding 1.0.3. It has been classified as critical. This affects an unknown part
A vulnerability classified as critical has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f
A vulnerability was found in Weitong Mall 1.0.0. It has been classified as critical. This affects an unknown part of the
A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue
Secure-upload is a data submission service that validates single-use tokens when accepting submissions to channels. The
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.
A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started