Improper Authorization in GitHub repository webmin/webmin prior to 1.990.
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to
XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 13.1.0.5 and 14
Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Ac
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal s
Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.
Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely
Implicit Intent hijacking vulnerability in Samsung Cloud prior to version 5.2.0 allows attacker to get sensitive informa
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp
The application management module has a vulnerability in permission verification. Successful exploitation of this vulner
A vulnerability classified as critical was found in SourceCodester Prison Management System 1.0. Affected by this vulner
Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with a
Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users
A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. An applic
Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.
XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with
Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains an Improper Access Control vulnerability within the
Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 vers
Improper Authorization in Packagist librenms/librenms prior to 22.2.0.
Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware ver
A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to
Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive inform
The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions
Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass us
Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keygu
Intent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to ge
Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.
openwhyd is vulnerable to Improper Authorization
Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporar
Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications
OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass un
OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass un
Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant pe
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-bas
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11
Huawei Aslan Children's Watch has an improper authorization vulnerability. Successful exploit could allow the attacker t
Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a membe
When a password reset or password change flow with an authentication policy is configured and the adapter in the reset o
Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0
Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S
An issue was discovered in wolfSSL before 5.5.0. A fault injection attack on RAM via Rowhammer leads to ECDSA key disclo
OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not vali
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticate
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate whe
Improper Authorization in GitHub repository usememos/memos prior to 0.9.1.
Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to ca
Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started