Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (compo
Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thun
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a
Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for function
WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently ap
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (p
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS de
Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are
Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars). Su
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Conne
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to
Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to
Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell end
Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers t
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the deskto
Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. In versions prior to 0.6.5,
Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypas
In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code ove
Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this
Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Proces
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway AP
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. E
Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported vers
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. E
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 3,013 CVE records associated with CWE-284 in our database. Of these, 482 are critical severity, 1369 are high severity, and 947 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started