A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affec
A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailController/AliPayContro
A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. This issue affects the function FlwInstanceControl
A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown fu
A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vuln
A flaw has been found in Open5GS 2.8.0. This vulnerability affects unknown code of the component AMF UEContextReleaseReq
A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing o
A vulnerability was detected in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affe
Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported vers
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, shared-base sessions were granted the sam
monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity f
A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of
A security vulnerability has been detected in Collabora KodExplorer up to 4.52. Affected by this issue is some unknown f
A security vulnerability has been detected in o2oa up to 10.0. This impacts the function syncFile of the file NodeAgent.
A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown cod
A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS
An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.3. An app may
An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may
A privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Tahoe 26.4. An app may be able to a
A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macO
SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerp
A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8,
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequ
A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of th
A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-t
A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/
A security flaw has been discovered in detronetdip E-commerce 1.0.0. The impacted element is the function Delete/Update
The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to
A flaw has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processin
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior
A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
A vulnerability has been found in TransformerOptimus SuperAGI up to 0.0.14. This affects the function delete_api_key/edi
A vulnerability was found in TransformerOptimus SuperAGI up to 0.0.14. This vulnerability affects the function update_us
A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This issue affects the function update_organ
A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/C
A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function s
A vulnerability was found in code-projects Online Hospital Management System 1.0. The impacted element is an unknown fun
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, an i
A vulnerability has been found in nextlevelbuilder GoClaw up to 3.11.3. This affects the function auth of the file inter
A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the functio
A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the functi
A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd48
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started