Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
In Splunk Enterprise versions below 8.1.13 and 8.2.10, the ‘createrss’ external search command overwrites existing Resou
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated
In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigat
Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated
In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Bu
In Splunk Enterprise versions below 9.0.5, 8.2.11. and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a
On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100,
The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' funct
The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_options' function in ver
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insuffic
Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view P
The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficie
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed
Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without auth
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.11.15, 1.
Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.
Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows l
Improper access control in Samsung Core Service prior to version 2.1.00.36 allows attacker to write arbitrary file in sa
Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access u
A vulnerability, which was classified as problematic, was found in jvvlee MerlinsBoard. This affects an unknown part of
Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.
Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of con
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forg
The Gotham video-application-server service contained a race condition which would cause it to not apply certain acls ne
Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the websi
Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker to access users text
An attacker with local access to the machine could record the traffic, which could allow them to resend requests witho
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device ve
Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.
Sequi PortBloque S has an improper authorization vulnerability, which may allow a low-privileged user to perform adminis
Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and Ter
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and Ter
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentic
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role
@keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0
A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x b
Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authentica
Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single em
Elcomplus SmartPTT is vulnerable when a low-authenticated user can access higher level administration authorization by i
RoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which coul
A vulnerability in the API implementation of Cisco ACI Multi-Site Orchestrator (MSO) could allow an authenticated, remot
Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged
A vulnerability in the MiCollab Client API of Mitel MiCollab 9.1.3 through 9.5.0.101 could allow an authenticated attack
Improper Authorization in GitHub repository usememos/memos prior to 0.9.0.
Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started