Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-285

MITRE ↗

CWE-285

31
CRITICAL
122
HIGH
324
MEDIUM
22
LOW
524 CVEs · Page 2/11
8.3
CVE-2026-58284

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

8.3
CVE-2026-56241

Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to del

8.3
CVE-2026-19979

A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500

8.2
CVE-2026-22022

Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to

8.2
CVE-2026-55428

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,

8.2
CVE-2026-64642

Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted reque

8.2
CVE-2026-10543

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted

8.2
CVE-2026-18509

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator f

8.2
CVE-2026-55571

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to

8.1
CVE-2026-24890

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio

8.1
CVE-2026-31836

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and

8.1
CVE-2026-32300

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the

8.1
CVE-2026-33668

Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, w

8.1
CVE-2026-32716

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the Enforcer incorrectly va

8.1
CVE-2026-40259

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, the /api/av/removeUnusedAttr

8.1
CVE-2026-42609

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows

8.1
CVE-2026-43983

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, Th

8.1
CVE-2026-9397

A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown

8.1
CVE-2026-47740

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Or

8.1
CVE-2026-46484

Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable

8.1
CVE-2026-45503

Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network

8.1
CVE-2026-49877

Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can

8.1
CVE-2026-56246

Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped A

8.1
CVE-2026-56313

Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that al

8.1
CVE-2026-32821

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

8.1
CVE-2026-60844

Vulnerability in the Oracle Customer Support product of Oracle E-Business Suite (component: Update Service Request). Su

8.1
CVE-2026-18499

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using

8.1
CVE-2026-66422

Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as r

8.1
CVE-2026-18985

Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in

8.1
CVE-2026-55065

Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:projec

8.0
CVE-2026-20960

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

8.0
CVE-2026-4248

The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl

8.0
CVE-2026-27912

Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.

8.0
CVE-2026-47298

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

7.8
CVE-2026-0072

In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission che

7.8
CVE-2026-42902

Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-45490

Improper authorization in .NET allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-49170

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privi

7.8
CVE-2026-58631

Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.

7.8
CVE-2026-50344

Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50346

Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-58540

Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

7.7
CVE-2026-0017

In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the c

7.7
CVE-2026-34056

OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access

7.7
CVE-2026-34222

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.

7.7
CVE-2026-32252

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c

7.7
CVE-2026-14538

An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Googl

7.6
CVE-2026-32692

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18

7.6
CVE-2026-56231

Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId

7.6
CVE-2026-56249

Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authen

Frequently Asked Questions

What is CWE-285?

CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-285?

There are 524 CVE records associated with CWE-285 in our database. Of these, 31 are critical severity, 122 are high severity, and 324 are medium severity.

How can I protect against CWE-285 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.

Detect CWE-285 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.

Get Started