SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap
Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and e
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.
Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privileg
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Po
SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modu
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled s
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal Alternativ
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field a
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate th
Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP ob
FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerabi
Budibase is an open-source low-code platform. Prior to 3.39.0, /api/public/v1/roles/assign is guarded by the builderOrAd
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to
Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registrat
APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed fo
Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Stud
Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignme
Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed e
Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in
Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary
Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated
LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint c
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, assista
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomT
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, dataset
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, Dataset
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluat
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluat
A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the sp
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code ex
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vuln
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0,
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3,
A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed clu
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 1
Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepa
Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits o
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe r
Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly acce
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauth
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mas
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
Frequently Asked Questions
What is CWE-915?
CWE-915 (CWE-915) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-915?
There are 121 CVE records associated with CWE-915 in our database. Of these, 18 are critical severity, 50 are high severity, and 33 are medium severity.
How can I protect against CWE-915 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-915 using AI-powered security agents.
Detect CWE-915 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-915 vulnerabilities across your infrastructure.
Get Started