Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorizat
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Suppor
Ech0 version 4.3.4 and earlier fails to reliably enforce scoped access token (least-privilege) restrictions on several p
Claude Code is an agentic coding tool. Prior to version 2.1.7, Claude Code failed to strictly enforce deny rules configu
PolarLearn is a free and open-source learning program. In 0-PRERELEASE-16 and earlier, the group chat WebSocket at wss:/
Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to
Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but p
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.2, the `LinkSharing.ReadAll()` meth
An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
free5GC is an open-source implementation of the 5G core network. In versions 1.4.2 and below of the UDR service, the han
free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the han
free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the han
Vulnerability in the Oracle Financial Services Customer Screening product of Oracle Financial Services Applications (com
The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information o
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/
OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enable
A flaw has been found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the fi
A vulnerability has been found in SourceCodester Client Database Management System 1.0/3.1. Impacted is an unknown funct
A vulnerability was determined in SourceCodester Client Database Management System 1.0. The impacted element is an unkno
A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element
A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the
A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Th
A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function
A security vulnerability has been detected in perfree go-fastdfs-web up to 1.3.7. This affects an unknown part of the fi
A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. The affected element is an unknown function of
A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the co
A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the fil
A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown pr
A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function ca
A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/Pa
A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the fun
A vulnerability was detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. This impacts an unkn
A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This af
A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of
A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file cla
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can el
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.
Podman Desktop is a graphical tool for developing on containers and Kubernetes. A critical authentication bypass vulnera
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper acces
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In versions 0.16.2 and be
Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorizat
gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subso
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open
Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied org_i
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started