Skip to main content

CWE archive

CWE-285 CVEs

Programmatic archive

1,432 CVEs tagged with CWE-285121 Critical, 391 High, 637 Medium, 283 Low, 0 Unrated.

CVE-2025-24053

Published Mar 13, 2025

Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27602

Published Mar 11, 2025

Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1, via manipulation of backoffi…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27601

Published Mar 11, 2025

Umbraco is a free and open source .NET content management system. An improper API access control issue has been identified Umbraco's API management package prior to versions 15.2.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2114

Published Mar 9, 2025

A vulnerability, which was classified as problematic, has been found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 7. This issue affects some unknown…

CVSS 6.3 · Medium

CVE-2024-13552

Published Mar 7, 2025

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.0 via…

CVSS 4.3 · Medium

CVE-2025-27509

Published Mar 6, 2025

fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to forge authenticat…

CVSS 9.3 · Critical

CVE-2024-13724

Published Mar 4, 2025

The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to unauthorized access to functionalit…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1847

Published Mar 3, 2025

A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper authorization. T…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1815

Published Mar 2, 2025

A vulnerability, which was classified as critical, was found in pbrong hrms up to 1.0.1. This affects the function HrmsDB of the file \resource\resource.go. The manipulation of th…

CVSS 6.9 · Medium

CVE-2025-1806

Published Mar 2, 2025

A vulnerability, which was classified as problematic, has been found in Eastnets PaymentSafe 2.5.26.0. Affected by this issue is some unknown functionality of the file /Default.as…

CVSS 5.3 · Medium

CVE-2025-27399

Published Feb 27, 2025

Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/reasons is set to "users" (local…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47053

Published Feb 26, 2025

This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data.…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-23024

Published Feb 25, 2025

GLPI is a free asset and IT management software package. Starting in version 0.72 and prior to version 10.0.18, an anonymous user can disable all the active plugins. Version 10.0.…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1361

Published Feb 22, 2025

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-25196

Published Feb 19, 2025

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, doc…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1007

Published Feb 19, 2025

In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Cont…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1226

Published Feb 12, 2025

A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation lea…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13821

Published Feb 12, 2025

The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to th…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24418

Published Feb 11, 2025

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege es…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-1078

Published Feb 6, 2025

A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical. This vulnerability affects the function shouldAcceptNewCon…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2024-57954

Published Feb 6, 2025

Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 701-725 of 1,432 CVEsPage 29 of 58