An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filenam
XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Starting in version 2.17.1 and prior to ver
Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at pet
Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficien
Azure CycleCloud Remote Code Execution Vulnerability
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with
Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized e
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows
casgate is an Open Source Identity and Access Management system. In affected versions `casgate` allows remote unauthenti
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker w
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at pet
DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.
The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via craft
The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficien
A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A spec
D-Link D-View showUser Improper Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attac
D-Link D-View showUsers Improper Authorization Privilege Escalation Vulnerability. This vulnerability allows remote atta
Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vuln
SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in version
Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is
A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is use
A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN
Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed thro
Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users crea
The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e
The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data
authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when usin
Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin v
Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPer
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulner
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authe
It was identified that under certain specific preconditions, an API key that was originally created with a specific priv
The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and
Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacke
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Ser
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, where it allows a guest OS to allocate resources
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,
Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and
Harbor fails to validate the user permissions when updating tag retention policies. By sending a request to update a t
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected ve
Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users ca
Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain a
OAuthenticator provides plugins for JupyterHub to use common OAuth providers, as well as base classes for writing one's
Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impact: Successful explo
Permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may
Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to b
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started