Improper authorization in some Intel Battery Life Diagnostic Tool installation software before version 2.2.1 may allow a
Visual Studio Code Spoofing Vulnerability
An improper authorization check of local device settings in TeamViewer Remote between version 15.41 and 15.42.7 for Win
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15
HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer met
An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid param
Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBa
Kyverno is a policy engine designed for Kubernetes. In versions of Kyverno prior to 1.10.0, resources which have the `de
A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gat
Microsoft SharePoint Server Elevation of Privilege Vulnerability
The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could all
Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1.
Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edi
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used
The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in
The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1
A vulnerability was found in SourceCodester Service Provider Management System 1.0 and classified as critical. Affected
The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin
Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a
By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vufo
The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/
The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache
Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attacke
Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infra
Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91.
PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that t
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read i
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read i
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read i
The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'tw
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allo
Improper Authorization in GitHub repository pixelfed/pixelfed prior to 0.11.4.
A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse co
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4.
Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 be
A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing th
A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory o
NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the defau
Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE a
Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Re
Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 softwa
Improper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable d
Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentiall
Wyse Management Suite versions prior to 4.0 contain an improper authorization vulnerability. An authenticated malicious
A vulnerability exists in a SDM600 endpoint. An attacker could exploit this vulnerability by running multiple parallel r
Tauri is a framework for building binaries for all major desktop platforms. The 1.4.0 release includes a regression on t
A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vuln
Dell BIOS contains an Improper Authorization vulnerability. An unauthenticated physical attacker may potentially exploi
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_requir
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started