A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file
A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function d
A flaw has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. Affected by this vulnerabilit
Capgo before 12.128.2 contains an authorization flaw in transfer_app() that fails to update deploy_history.owner_org whe
SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. Prior to 3.1.0, Docum
bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb w
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Suppo
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Suppo
Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Suppor
A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impact
A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown pro
A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted element is the funct
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permiss
A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file htdocs/user/card.php o
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function
The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for Wo
Collabora Online is a collaborative online office suite based on LibreOffice technology. Prior to Collabora Online Devel
A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /
A security flaw has been discovered in Freedom Factory dGEN1 up to 20260221. The impacted element is the function FakeAp
A security vulnerability has been detected in Freedom Factory dGEN1 up to 20260221. This impacts the function AlarmServi
A vulnerability was detected in Freedom Factory dGEN1 up to 20260221. Affected is an unknown function of the component c
A vulnerability was found in Freedom Factory dGEN1 up to 20260221. Affected by this vulnerability is the function FakeAp
A vulnerability was determined in Freedom Factory dGEN1 up to 20260221. Affected by this issue is the function FakeAppRe
A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects som
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Ta
baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
A vulnerability was identified in SourceCodester Leave Application System 1.0. Impacted is an unknown function of the fi
A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the fil
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization i
A vulnerability was detected in toeverything AFFiNE up to 0.26.3. This issue affects the function allowDocPreview of the
Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a pub
A vulnerability has been found in Industrial Application Software IAS Canias ERP 8.03. The affected element is the funct
WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to be
A flaw has been found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown part of the component
A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of
Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.get_current_plan_max_org RPC function
A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor
A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of t
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protect
A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained a
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /as
A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file model
OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any au
A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the f
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started