Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-285

MITRE ↗

CWE-285

120
CRITICAL
432
HIGH
860
MEDIUM
81
LOW
1,527 CVEs · Page 21/31
4.3
CVE-2024-1803

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gute

4.3
CVE-2024-37167

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see b

4.3
CVE-2024-39404

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul

4.3
CVE-2024-39405

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul

4.3
CVE-2024-39407

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul

4.3
CVE-2024-39411

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul

4.3
CVE-2024-39412

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul

4.3
CVE-2024-39413

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul

4.3
CVE-2024-39415

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul

4.3
CVE-2024-39416

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul

4.3
CVE-2024-39417

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul

4.3
CVE-2024-39419

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul

4.3
CVE-2024-42039

Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect ser

4.3
CVE-2024-20497

A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as a

4.3
CVE-2024-9531

The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unaut

4.3
CVE-2024-11073

A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects

4.3
CVE-2021-3991

An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricte

4.3
CVE-2024-48897

A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds th

4.3
CVE-2024-48901

A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a re

4.3
CVE-2024-43731

Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Authorization vulnerability that could

4.3
CVE-2024-45805

OpenCTI is an open-source cyber threat intelligence platform. Before 6.3.0, general users can access information that ca

4.2
CVE-2024-5053

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner

3.9
CVE-2024-30260

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization hea

3.8
CVE-2024-2317

A vulnerability was found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This issue affect

3.7
CVE-2024-12483

A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of t

3.5
CVE-2024-37159

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. This vulnerability allowed a user to create a val

3.5
CVE-2020-9081

There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of opera

3.3
CVE-2023-35022

IBM InfoSphere Information Server 11.7 could allow a local user to update projects that they do not have the authorizati

2.7
CVE-2024-48921

Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can b

2.5
CVE-2024-42036

Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability

CVE-2024-52528

Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for

CVE-2024-13058

An issue exists in SoftIron HyperCloud where authenticated, but non-admin users can create data pools, which could pote

CVE-2024-56802

Tapir is a private Terraform registry. Tapir versions 0.9.0 and 0.9.1 are facing a critical issue with scope-able Deploy

10.0
CVE-2023-33189

Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisio

9.8
CVE-2022-3229

Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication

9.8
CVE-2022-3748

Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affect

9.1
CVE-2022-38375

An improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 all

9.1
CVE-2023-2227

Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.

9.1
CVE-2023-39398

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san

9.1
CVE-2023-39399

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san

9.1
CVE-2023-39400

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san

9.1
CVE-2023-39401

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san

9.1
CVE-2023-39402

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san

9.1
CVE-2023-39403

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san

9.0
CVE-2023-52139

Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endp

8.8
CVE-2023-21549

Windows SMB Witness Service Elevation of Privilege Vulnerability

8.8
CVE-2022-34446

PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated r

8.8
CVE-2023-0822

The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an u

8.8
CVE-2023-28634

GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.

8.8
CVE-2023-32707

In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100,

Frequently Asked Questions

What is CWE-285?

CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-285?

There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.

How can I protect against CWE-285 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.

Detect CWE-285 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.

Get Started