Skip to main content

CWE archive

CWE-285 CVEs

Programmatic archive

1,432 CVEs tagged with CWE-285121 Critical, 391 High, 637 Medium, 283 Low, 0 Unrated.

CVE-2025-20125

Published Feb 5, 2025

A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations,…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2025-24784

Published Jan 30, 2025

kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. The policy group feature, added to by the 1.17.0 release. B…

CVSS 4.3 · Medium

CVE-2025-24376

Published Jan 30, 2025

kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. By design, AdmissionPolicy and AdmissionPolicyGroup can eva…

CVSS 6.5 · Medium

CVE-2024-13646

Published Jan 30, 2025

The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on the 'single_use…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-13694

Published Jan 30, 2025

The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all vers…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-0849

Published Jan 30, 2025

A vulnerability classified as critical has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /edit-staff/ of the component Staff…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-0580

Published Jan 20, 2025

A vulnerability was found in Shiprocket Module 3 on OpenCart. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?route=exte…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2024-55954

Published Jan 16, 2025

OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Admin" role user to remove a "Roo…

CVSS 8.7 · High

CVE-2025-0484

Published Jan 15, 2025

A vulnerability was found in Fanli2012 native-php-cms 1.0 and classified as critical. This issue affects some unknown processing of the file /fladmin/sysconfig_doedit.php of the c…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-23042

Published Jan 14, 2025

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Gradio's Access…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56323

Published Jan 13, 2025

OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13241

Published Jan 9, 2025

Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.0.5.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-21611

Published Jan 6, 2025

tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API methods were incorrectly OR'd instead of AND'ed with the role…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56320

Published Jan 3, 2025

GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-56802

Published Dec 31, 2024

Tapir is a private Terraform registry. Tapir versions 0.9.0 and 0.9.1 are facing a critical issue with scope-able Deploykeys where attackers can guess the key to get write access…

CVSS 8.7 · High

CVE-2024-13058

Published Dec 30, 2024

An issue exists in SoftIron HyperCloud where authenticated, but non-admin users can create data pools, which could potentially impact the performance and availability of the back…

CVSS 4.8 · Medium

CVE-2020-9081

Published Dec 27, 2024

There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Succes…

CVSS 3.5 · Low

CVE-2024-45805

Published Dec 26, 2024

OpenCTI is an open-source cyber threat intelligence platform. Before 6.3.0, general users can access information that can only be accessed by users with access privileges to admin…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45387

Published Dec 23, 2024

An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "st…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-12901

Published Dec 23, 2024

A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/Site.php of the co…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12782

Published Dec 19, 2024

A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 and classified as critical. This vulnerability affects unknow…

CVSS 6.9 · Medium
Showing 726-750 of 1,432 CVEsPage 30 of 58