Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-285

MITRE ↗

CWE-285

120
CRITICAL
432
HIGH
860
MEDIUM
81
LOW
1,527 CVEs · Page 18/31
CVE-2024-26291

An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filenam

CVE-2025-49594

XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Starting in version 2.17.1 and prior to ver

CVE-2025-61928

Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated

9.9
CVE-2024-24830

OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at pet

9.9
CVE-2024-25108

Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficien

9.9
CVE-2024-43602

Azure CycleCloud Remote Code Execution Vulnerability

9.9
CVE-2024-45387

An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with

9.8
CVE-2024-32881

Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access

9.8
CVE-2024-34257

TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized e

9.8
CVE-2024-28285

A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows

9.8
CVE-2024-36108

casgate is an Open Source Identity and Access Management system. In affected versions `casgate` allows remote unauthenti

9.8
CVE-2024-36130

An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker w

9.1
CVE-2024-25106

OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at pet

9.1
CVE-2024-33749

DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.

8.8
CVE-2023-48252

The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via craft

8.8
CVE-2023-6878

The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing

8.8
CVE-2023-40683

IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficien

8.8
CVE-2023-47166

A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A spec

8.8
CVE-2023-32168

D-Link D-View showUser Improper Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attac

8.8
CVE-2023-44410

D-Link D-View showUsers Improper Authorization Privilege Escalation Vulnerability. This vulnerability allows remote atta

8.8
CVE-2024-25949

Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vuln

8.8
CVE-2024-45307

SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in version

8.8
CVE-2024-45044

Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is

8.8
CVE-2024-20381

A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is use

8.8
CVE-2024-20393

A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN

8.8
CVE-2023-50780

Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed thro

8.8
CVE-2024-47876

Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users crea

8.8
CVE-2024-9235

The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e

8.8
CVE-2024-10729

The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data

8.6
CVE-2024-38371

authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when usin

8.3
CVE-2024-47084

Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin v

8.2
CVE-2024-36399

Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPer

8.2
CVE-2024-34104

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulner

8.1
CVE-2024-2441

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authe

8.1
CVE-2024-37282

It was identified that under certain specific preconditions, an API key that was originally created with a specific priv

8.1
CVE-2024-7624

The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and

8.1
CVE-2024-43460

Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacke

8.1
CVE-2024-47183

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Ser

7.8
CVE-2024-0077

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, where it allows a guest OS to allocate resources

7.8
CVE-2024-23667

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,

7.8
CVE-2024-23670

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,

7.7
CVE-2022-31666

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and

7.7
CVE-2022-31670

Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a t

7.6
CVE-2024-56335

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected ve

7.5
CVE-2024-23649

Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users ca

7.5
CVE-2024-25063

Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain a

7.5
CVE-2024-29033

OAuthenticator provides plugins for JupyterHub to use common OAuth providers, as well as base classes for writing one's

7.5
CVE-2023-52359

Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impact: Successful explo

7.5
CVE-2023-52539

Permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may

7.5
CVE-2024-3840

Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to b

Frequently Asked Questions

What is CWE-285?

CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-285?

There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.

How can I protect against CWE-285 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.

Detect CWE-285 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.

Get Started