Skip to main content

CWE archive

CWE-285 CVEs

Programmatic archive

1,442 CVEs tagged with CWE-285123 Critical, 393 High, 643 Medium, 283 Low, 0 Unrated.

CVE-2026-3671

Published Mar 7, 2026

A flaw has been found in Freedom Factory dGEN1 up to 20260221. Affected by this vulnerability is the function TokenBalanceContentProvider of the component org.ethereumphone.wallet…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-3670

Published Mar 7, 2026

A vulnerability was detected in Freedom Factory dGEN1 up to 20260221. Affected is an unknown function of the component com.dgen.alarm. Performing a manipulation results in imprope…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-3669

Published Mar 7, 2026

A security vulnerability has been detected in Freedom Factory dGEN1 up to 20260221. This impacts the function AlarmService of the component com.dgen.alarm. Such manipulation leads…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-3667

Published Mar 7, 2026

A security flaw has been discovered in Freedom Factory dGEN1 up to 20260221. The impacted element is the function FakeAppService of the component org.ethosmobile.ethoslauncher. Th…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-30847

Published Mar 6, 2026

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publication in Wekan publishes user documents with no field filtering…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-28685

Published Mar 6, 2026

Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks the role-based view_invoice permission but does not verify…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-28448

Published Mar 5, 2026

OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enabled) in which it fails to enforce the allowFrom allowlist whe…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-27803

Published Mar 4, 2026

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given coll…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0017

Published Mar 2, 2026

In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could lead to local escalation of privilege with…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3265

Published Feb 26, 2026

A vulnerability was identified in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. This affects an unknown part of the file /api/Security/ of the component Secur…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-2694

Published Feb 25, 2026

The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_del…

CVSS 5.4 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-24890

Published Feb 25, 2026

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an authorization bypass vulnerability in the patie…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-3185

Published Feb 25, 2026

A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /api/admin/sys-message/ of the component API Endpoint. The m…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
31.8
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-2974

Published Feb 23, 2026

A vulnerability was identified in AliasVault App up to 0.25.3 on Android/iOS. This vulnerability affects unknown code of the file shared_prefs/aliasvault.xml of the component Back…

CVSS 1.1 · Low
evidence mentions
9
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2026-2896

Published Feb 22, 2026

A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the component Configuration Handler.…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-2860

Published Feb 21, 2026

A security vulnerability has been detected in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. Impacted is an unknown function of the…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2025-15582

Published Feb 20, 2026

A security flaw has been discovered in detronetdip E-commerce 1.0.0. The impacted element is the function Delete/Update of the component Product Management Module. Performing a ma…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-71242

Published Feb 19, 2026

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-2733

Published Feb 19, 2026

A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even after a Docker registry client has been administratively disabl…

CVSS 3.8 · Low
evidence mentions
4
Buzz score
26.1

CVE-2026-2693

Published Feb 19, 2026

A vulnerability was determined in CoCoTeaNet CyreneAdmin up to 1.3.0. This vulnerability affects unknown code of the file /api/system/dashboard/getCount of the component System In…

CVSS 2.1 · Low
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-4521

Published Feb 19, 2026

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonate_donor…

CVSS 8.8 · High

CVE-2026-2676

Published Feb 18, 2026

A weakness has been identified in GoogTech sms-ssm up to e8534c766fd13f5f94c01dab475d75f286918a8d. Affected by this issue is the function preHandle of the file LoginInterceptor.ja…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-26020

Published Feb 12, 2026

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.48, an authenticated…

CVSS 9.4 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort
Showing 351-375 of 1,442 CVEsPage 15 of 58