The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in ve
Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated at
The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a miss
EisBaer Scada - CWE-285: Improper Authorization
Incorrect authorisation in ekorCCP and ekorRCI, which could allow a remote attacker to obtain resources with sensitive i
Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a re
A vulnerability was found in KylinSoft kylin-activation on KylinOS and classified as critical. Affected by this issue is
Improper authorization in the Intel(R) NUC Pro Software Suite for Windows before version 2.0.0.9 may allow a privileged
Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1.
An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belongin
A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS X
A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software function
Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applic
A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root
A user with non-Admin access can change a configuration file on the client to modify the Server URL.
A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization
A vulnerability exists in the SDM600 API web services authorization validation implementation. An attacker who successf
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2,
Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacke
The Gallery Images Ape plugin for WordPress is vulnerable to Arbitrary Plugin Deactivation in versions up to, and includ
Windows Server Service Security Feature Bypass Vulnerability
Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage. This
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authe
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authe
A vulnerability exists in the SDM600 software. The software operates at a privilege level that is higher than the minim
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xx
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Ac
Transient DOS due to improper authorization in Modem
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing cap
Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcem
Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel
Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE.
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is s
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earl
XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, a
A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token fro
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_admin
KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate productio
An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious use
A vulnerability, which was classified as critical, has been found in Xiamen Four Letter Video Surveillance Management Sy
An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a l
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file u
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to
Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view C
Cryptographic issue in HLOS during key management.
An improper authorization vulnerability [CWE-285] in Fortinet FortiADC version 7.4.0 and before 7.2.2 may allow a low pr
Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locall
An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 thr
Improper authorization in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authe
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started