In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior
authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentica
A vulnerability was found in Forklift Controller. There is no verification against the authorization header except to e
Windows Kerberos Elevation of Privilege Vulnerability
An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the u
Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is
An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploite
Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p p
Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution
A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be a
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check
A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified as critical. Affected i
A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 an
In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B si
authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was pos
Microsoft Outlook Elevation of Privilege Vulnerability
Minder is a software supply chain security platform. Prior to version 0.0.33, a Minder user can use the endpoints `GetRe
Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data
The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improp
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.6, mac
An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through design
Improper authorization in some Intel(R) PM software may allow a privileged user to potentially enable escalation of priv
An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S A
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missi
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all vers
A flaw was found in Quarkus. When a Quarkus RestEasy Classic or Reactive JAX-RS endpoint has its methods declared in the
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 p
* Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Alti
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Microsoft Outlook for iOS Information Disclosure Vulnerability
In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can co
A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, re
A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This af
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Authorization vulnerability that could
Azure Migrate Remote Code Execution Vulnerability
The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c
Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authentic
Harbor fails to validate the user permissions when updating tag immutability policies. By sending a request to update
A flaw has been found in Teledyne FLIR AX8 up to 1.46.16. The impacted element is an unknown function of the file /tools
A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This vul
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this iss
A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been declared as critical. Aff
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authent
Permission control vulnerability in the clipboard module Impact: Successful exploitation of this vulnerability may affec
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started