Skip to main content

CWE archive

CWE-285 CVEs

Programmatic archive

1,444 CVEs tagged with CWE-285123 Critical, 393 High, 643 Medium, 285 Low, 0 Unrated.

CVE-2025-14089

Published Dec 5, 2025

A vulnerability was identified in Himool ERP up to 2.2. Affected by this issue is the function update_account of the file /api/admin/update_account/ of the component AdminActionVi…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2025-14088

Published Dec 5, 2025

A vulnerability was determined in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is an unknown functionality of the file /je/load. This manipulation of the argument Autho…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2025-14016

Published Dec 4, 2025

A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/delete. Such manipulation of the a…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-58386

Published Dec 2, 2025

In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks. A Power User can intercept an…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66301

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an ed…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-13808

Published Dec 1, 2025

A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerability is the function update of the file orion-ops-api/orion-o…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-13807

Published Dec 1, 2025

A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected is the function MachineKeyController of the file orion-ops-api/orion-op…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-13806

Published Dec 1, 2025

A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-s…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2025-66291

Published Nov 29, 2025

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment retrieval endpoint in the Recruitment module serves files ba…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66290

Published Nov 29, 2025

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitment attachment retrieval endpoint does not enforce the requ…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-65966

Published Nov 26, 2025

OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API request instead of bei…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-65963

Published Nov 26, 2025

Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow non-member users to create new…

CVSS 5.4 · Medium

CVE-2025-64065

Published Nov 25, 2025

The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The administrative LoginAs or user impersonation feature is vu…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64063

Published Nov 25, 2025

Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specifically, a standard user can exploit this flaw by sending di…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-64062

Published Nov 25, 2025

The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the authenticated session. By manipul…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-13576

Published Nov 24, 2025

A vulnerability was detected in code-projects Blog Site 1.0. The affected element is an unknown function of the file /admin.php. Performing manipulation results in improper author…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2025-65107

Published Nov 21, 2025

Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in SSO provider configurations w…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11815

Published Nov 21, 2025

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2025-64751

Published Nov 21, 2025

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( openfga-0.1.34 <= Helm…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-65094

Published Nov 19, 2025

WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrators group by manipulating the gr…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-65033

Published Nov 19, 2025

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll management feature allows any authenticated user to pause or…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-65031

Published Nov 19, 2025

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization flaw in the comment creation endpoint allows authenticated users to i…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-65030

Published Nov 19, 2025

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the comment deletion API allows any authenticated user to delete comme…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-65029

Published Nov 19, 2025

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows any authenticated user to delet…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 451-475 of 1,444 CVEsPage 19 of 58