Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-285

MITRE ↗

CWE-285

120
CRITICAL
432
HIGH
860
MEDIUM
81
LOW
1,527 CVEs · Page 19/31
7.5
CVE-2024-41670

In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior

7.5
CVE-2024-42490

authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentica

7.5
CVE-2024-8509

A vulnerability was found in Forklift Controller.  There is no verification against the authorization header except to e

7.5
CVE-2024-38129

Windows Kerberos Elevation of Privilege Vulnerability

7.5
CVE-2024-36467

An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the u

7.5
CVE-2024-51479

Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is

7.4
CVE-2023-50363

An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploite

7.4
CVE-2022-31668

Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p p

7.4
CVE-2022-31671

Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution

7.4
CVE-2024-8676

A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be a

7.3
CVE-2024-30061

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

7.3
CVE-2024-36438

eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check

7.3
CVE-2024-7578

A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified as critical. Affected i

7.3
CVE-2024-12782

A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 an

7.2
CVE-2024-39597

In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B si

7.2
CVE-2024-52287

authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was pos

7.1
CVE-2024-21402

Microsoft Outlook Elevation of Privilege Vulnerability

7.1
CVE-2024-27916

Minder is a software supply chain security platform. Prior to version 0.0.33, a Minder user can use the endpoints `GetRe

7.1
CVE-2024-23576

Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data

7.1
CVE-2024-6000

The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improp

7.1
CVE-2024-40814

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.6, mac

6.9
CVE-2024-32359

An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through design

6.7
CVE-2023-38135

Improper authorization in some Intel(R) PM software may allow a privileged user to potentially enable escalation of priv

6.6
CVE-2024-6840

An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S A

6.5
CVE-2024-1043

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missi

6.5
CVE-2024-27930

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an

6.5
CVE-2024-27937

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an

6.5
CVE-2024-1289

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all vers

6.5
CVE-2023-5675

A flaw was found in Quarkus. When a Quarkus RestEasy Classic or Reactive JAX-RS endpoint has its methods declared in the

6.5
CVE-2024-3959

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 p

6.5
CVE-2024-6347

* Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Alti

6.5
CVE-2024-38231

Windows Remote Desktop Licensing Service Denial of Service Vulnerability

6.5
CVE-2024-43482

Microsoft Outlook for iOS Information Disclosure Vulnerability

6.5
CVE-2024-46942

In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can co

6.5
CVE-2024-20414

A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, re

6.5
CVE-2024-11860

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This af

6.5
CVE-2024-43729

Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Authorization vulnerability that could

6.4
CVE-2024-26193

Azure Migrate Remote Code Execution Vulnerability

6.4
CVE-2024-3027

The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c

6.4
CVE-2022-31667

Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authentic

6.4
CVE-2022-31669

Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update

6.3
CVE-2024-3013

A flaw has been found in Teledyne FLIR AX8 up to 1.46.16. The impacted element is an unknown function of the file /tools

6.3
CVE-2024-7851

A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This vul

6.3
CVE-2024-9082

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this iss

6.3
CVE-2024-9297

A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been declared as critical. Aff

6.3
CVE-2020-3539

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authent

6.2
CVE-2024-51525

Permission control vulnerability in the clipboard module Impact: Successful exploitation of this vulnerability may affec

6.1
CVE-2024-21018

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV

6.1
CVE-2024-21026

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV

6.1
CVE-2024-21031

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV

Frequently Asked Questions

What is CWE-285?

CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-285?

There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.

How can I protect against CWE-285 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.

Detect CWE-285 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.

Get Started