Skip to main content

CWE archive

CWE-285 CVEs

Programmatic archive

1,444 CVEs tagged with CWE-285123 Critical, 393 High, 643 Medium, 285 Low, 0 Unrated.

CVE-2025-15213

Published Dec 30, 2025

A vulnerability has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /download.php of the component File Dow…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-15126

Published Dec 28, 2025

A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position/getPositionUserList. This man…

CVSS 1.3 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-15125

Published Dec 28, 2025

A security flaw has been discovered in JeecgBoot up to 3.9.0. Affected is the function queryDepartPermission of the file /sys/permission/queryDepartPermission. The manipulation of…

CVSS 1.3 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-15124

Published Dec 28, 2025

A vulnerability was identified in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The manipulation of the argument depa…

CVSS 1.3 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-15123

Published Dec 28, 2025

A vulnerability was determined in JeecgBoot up to 3.9.0. This affects an unknown function of the file /sys/sysDepartPermission/datarule/. Executing manipulation can lead to improp…

CVSS 1.3 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-15122

Published Dec 28, 2025

A vulnerability was found in JeecgBoot up to 3.9.0. The impacted element is the function loadDatarule of the file /sys/sysDepartRole/datarule/. Performing manipulation of the argu…

CVSS 1.3 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-15120

Published Dec 28, 2025

A flaw has been found in JeecgBoot up to 3.9.0. Impacted is the function getDeptRoleList of the file /sys/sysDepartRole/getDeptRoleList. This manipulation of the argument departId…

CVSS 1.3 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-15119

Published Dec 28, 2025

A vulnerability was detected in JeecgBoot up to 3.9.0. This issue affects the function queryPageList of the file /sys/sysDepartRole/list. The manipulation of the argument deptId r…

CVSS 1.3 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-15118

Published Dec 28, 2025

A security vulnerability has been detected in macrozheng mall up to 1.0.3. This vulnerability affects unknown code of the file /member/address/update/ of the component Member Endp…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-15106

Published Dec 27, 2025

A weakness has been identified in getmaxun maxun up to 0.0.28. The affected element is the function router.get of the file server/src/routes/auth.ts of the component Authenticatio…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-15087

Published Dec 25, 2025

A security vulnerability has been detected in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function submitOrderPayment of the file mall-oms/oms-boot/src/main/java/com/youla…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-15085

Published Dec 25, 2025

A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-68481

Published Dec 19, 2025

FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login state tokens are completely s…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-14546

Published Dec 19, 2025

Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the improper validation of the OAuth state parameter during the authen…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2025-65041

Published Dec 18, 2025

Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-46296

Published Dec 16, 2025

An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative features such as viewing licen…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-53895

Published Dec 16, 2025

PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization through the configuration endpoint.…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-67715

Published Dec 16, 2025

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-65782

Published Dec 15, 2025

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling allows board members (and pote…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46289

Published Dec 12, 2025

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may be able to access protected…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-40830

Published Dec 9, 2025

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization checks for the file_transfer fe…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-14206

Published Dec 8, 2025

A vulnerability was determined in SourceCodester Online Student Clearance System 1.0. The affected element is an unknown function of the file /Admin/delete-fee.php of the componen…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-12720

Published Dec 6, 2025

The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization that can be spoofed in the handle_enqueue_only() function i…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
30.9

CVE-2025-12505

Published Dec 6, 2025

The weDocs plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.1.14. This is due to the plugin not properly verifying that a user is…

CVSS 5.4 · Medium
evidence mentions
5
Buzz score
29.4
Showing 426-450 of 1,444 CVEsPage 18 of 58