CWE-285

CWE-285 · 4 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-285, highest CVSS first.

  1. MEDIUM 6.3CVE-2026-18818

    A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views.py of the component Support Ticket Handler. Executing a manipulation can lead to authorization bypass. The att

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 6.3CVE-2026-18773public PoC

    A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The att

    AI risk analysis on Exploit-DB.ai →

  3. LOW 2.2CVE-2026-18817public PoC

    A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py of the component Inactive Non-Staff User Handler. Performing

    AI risk analysis on Exploit-DB.ai →

  4. UNSCOREDCVE-2026-70472public PoC

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without checking whether that c

    AI risk analysis on Exploit-DB.ai →