HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized use
Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommende
Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore
Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versi
Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be re
Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentiall
Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly al
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.3, macOS Big
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonom
Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable
Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with
Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in chan
Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members
Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with a
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allo
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a Rem
Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels
Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected a
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows
vantage6 is an open-source infrastructure for privacy preserving analysis. Collaboration administrators can add extra or
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 p
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are
Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the co
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vuln
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v
A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /d
Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected a
Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenti
A permissions issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker
The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.5 and iPadOS 17
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS
An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) a
Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version
VIMESA VHF/FM Transmitter Blue Plus is suffering from a Denial-of-Service (DoS) vulnerability. An unauthenticated attack
Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delet
Stardust is a platform for streaming isolated desktop containers. With this exploit, inter container communication (ICC)
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r
Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded c
XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the
XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing docu
The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including,
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper acces
api/views/user.py in LibrePhotos before e19e539 has incorrect access control.
An issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessibl
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started