Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network
Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to del
A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500
Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted reque
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator f
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the
Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, w
SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the Enforcer incorrectly va
SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, the /api/av/removeUnusedAttr
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, Th
A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Or
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network
Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can
Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped A
Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that al
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
Vulnerability in the Oracle Customer Support product of Oracle E-Business Suite (component: Update Service Request). Su
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as r
Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in
Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:projec
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission che
Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privi
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the c
OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Googl
An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18
Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId
Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authen
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 524 CVE records associated with CWE-285 in our database. Of these, 31 are critical severity, 122 are high severity, and 324 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started