Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV
A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local a
Information disclosure while sending implicit broadcast containing APP launch information.
Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below,
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain an improper authorization vulnerability. An adja
A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attac
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access r
The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Monterey 12.7.6
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that a
SnapCenter versions 4.8 prior to 5.0 are susceptible to a vulnerability which could allow an authenticated SnapCenter S
Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Internal Operations). S
A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management Syste
A vulnerability classified as critical was found in CP Plus Wi-Fi Camera up to 20240401. Affected by this vulnerability
The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capabil
A command for refining a collection shard key is missing an authorization check. This may cause the command to run direc
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul
Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **CORS origin vali
The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i
Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device
A vulnerability was found in kishor-23 Food Waste Management System 1.0. It has been declared as critical. This vulnerab
A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been classified as critical. Affected is an unk
The YITH WooCommerce Gift Cards plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not y
"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifi
A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by
The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability che
A vulnerability classified as critical was found in Tongda OA 11.2/11.3/11.4/11.5/11.6. This vulnerability affects unkno
A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerab
GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to downlo
A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. Th
A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This
The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to im
A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown funct
BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The p
An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploite
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Bostr is an nostr relay aggregator proxy that acts like a regular nostr relay. bostr let everyone in even having authori
Access permission verification vulnerability in the Contacts module Impact: Successful exploitation of this vulnerabilit
A vulnerability was found in Apollo 2.0.0/2.0.1 and classified as problematic. Affected by this issue is some unknown fu
In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed
Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retri
An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may
A vulnerability in the web-based management interface of Cisco Catalyst Center, formerly Cisco DNA Center, could allow a
The WP Show Posts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on
A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as problematic. Affe
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started