CWE-285
CVEs classified under CWE-285, newest first.
247 CVEsRSS
CVE-2025-13808High· 7.3A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1
A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerability is the function update of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/UserContro…
CVE-2025-13807Medium· 4.3A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1
A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected is the function MachineKeyController of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/MachineKeyC…
CVE-2025-10209Medium· 5.4A security flaw has been discovered in Papermerge DMS up to 3.5.3
A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the component Authorization Token Handler. Performing manipulation results in improper authorization. The attack can be init…
CVE-2024-8676High· 7.4A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it
A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it does that restoration, it attempts to restore the mounts from the restore archive instead…
CVE-2024-23670High· 7.8An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands …
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands …
CVE-2024-23667High· 7.8An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands …
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands …
CVE-2025-29927Critical· 9.1PoCNext.js middleware authorization bypass via x-middleware-subrequest
A crafted x-middleware-subrequest header lets an attacker skip Next.js middleware execution entirely, bypassing authentication/authorization checks implemented in middleware.