VulnSea

CWE-285

CVEs classified under CWE-285, newest first.

247 CVEsRSS

CVE-2025-13808High· 7.3
10mo ago

A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1

A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerability is the function update of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/UserContro…

▾ Twilightorionsec · orion-opsEPSS 0.48%via NVD
CVE-2025-13807Medium· 4.3
10mo ago

A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1

A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected is the function MachineKeyController of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/MachineKeyC…

▾ Sunlitorionsec · orion-opsEPSS 0.36%via NVD
CVE-2025-10209Medium· 5.4
1y ago

A security flaw has been discovered in Papermerge DMS up to 3.5.3

A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the component Authorization Token Handler. Performing manipulation results in improper authorization. The attack can be init…

▾ SunlitEPSS 0.29%via NVD
CVE-2024-8676High· 7.4
1y ago

A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it

A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it does that restoration, it attempts to restore the mounts from the restore archive instead…

▾ TwilightEPSS 0.76%via NVD
CVE-2024-23670High· 7.8
2y ago

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands …

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands …

▾ Twilightfortinet · fortiwebmanagerEPSS 0.44%via NVD
CVE-2024-23667High· 7.8
2y ago

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands …

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands …

▾ Twilightfortinet · fortiwebmanagerEPSS 0.44%via NVD
CVE-2025-29927Critical· 9.1PoC

Next.js middleware authorization bypass via x-middleware-subrequest

A crafted x-middleware-subrequest header lets an attacker skip Next.js middleware execution entirely, bypassing authentication/authorization checks implemented in middleware.

▾ AbyssalNext.js · Next.jsNode.js, WebEPSS 99%via GHSA
CWE-285 vulnerabilities (CVEs) — page 9 · VulnSea