The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gute
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see b
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul
Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect ser
A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as a
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unaut
A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects
An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricte
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds th
A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a re
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Authorization vulnerability that could
OpenCTI is an open-source cyber threat intelligence platform. Before 6.3.0, general users can access information that ca
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization hea
A vulnerability was found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This issue affect
A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of t
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. This vulnerability allowed a user to create a val
There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of opera
IBM InfoSphere Information Server 11.7 could allow a local user to update projects that they do not have the authorizati
Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can b
Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability
Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for
An issue exists in SoftIron HyperCloud where authenticated, but non-admin users can create data pools, which could pote
Tapir is a private Terraform registry. Tapir versions 0.9.0 and 0.9.1 are facing a critical issue with scope-able Deploy
Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisio
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affect
An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 all
Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san
Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endp
Windows SMB Witness Service Elevation of Privilege Vulnerability
PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated r
The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an u
GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.
In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100,
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started