Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Cond
LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKno
MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignme
@adonisjs/lucid is an SQL ORM for AdonisJS built on top of Knex. Prior to 21.8.2 and 22.0.0-next.6, there is a Mass Assi
The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on th
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is
Flowise before 3.1.2 contains a mass assignment vulnerability in the PUT /api/v1/user endpoint that allows authenticated
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a
c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can c
Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass
9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body t
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthentic
Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/clie
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code ex
The frontend management plugin attributed a newly created event to the submitting user's organizer record only when the
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban all
An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call
Frequently Asked Questions
What is CWE-915?
CWE-915 (CWE-915) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-915?
There are 122 CVE records associated with CWE-915 in our database. Of these, 18 are critical severity, 51 are high severity, and 33 are medium severity.
How can I protect against CWE-915 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-915 using AI-powered security agents.
Detect CWE-915 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-915 vulnerabilities across your infrastructure.
Get Started