A vulnerability has been found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805 and clas
Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that al
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled,
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticat
An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a gu
autMan v2.9.6 was discovered to contain an access control issue.
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (
An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may all
A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects th
A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been rated as problematic. Aff
Lack of access control in ChallengeSolves (/api/v1/challenges/<challenge id>/solves) of CTFd v2.0.0 - v3.7.2 allows auth
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v
In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" S
In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform version
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a
The Zotpress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o
A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an un
Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM
An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without publi
A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authenticated, remote attac
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course ba
A vulnerability was found in Codezips Free Exam Hall Seating Management System 1.0. It has been declared as problematic.
Multiple access control vulnerabilities in Unifiedtransform version 2.0 and potentially earlier versions allow unauthori
A function-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows te
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by an Improper Access Control vulnerability that could resu
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Access Control vulnerability that could
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Access Control vulnerability that could
The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data
A vulnerability was found in Tsinghua Unigroup Electronic Archives Management System 3.2.210802(62532). It has been clas
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenti
An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Cert
NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a us
An Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_use
Secure Boot Security Feature Bypass Vulnerability
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification
Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being bloc
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenti
A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious r
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are a
Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing fre
Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silen
Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifi
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started