Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privil
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a
Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow an authenti
The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and includi
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check
Windows Collaborative Translation Framework Elevation of Privilege Vulnerability
LAN-W451NGR all versions provided by LOGITEC CORPORATION contains an improper access control vulnerability, which allows
The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation
A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108.
Improper Access Control in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.
Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access contr
Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentia
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin u
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
Improper Access to the VM resource manager can lead to Memory Corruption.
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Acces
A vulnerability in Cisco DNA Center could allow an unauthenticated, remote attacker to read and modify data in a reposit
Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write ar
An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 throu
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio
Memory corruption due to improper access control in Qualcomm IPC.
Memory corruption in Automotive Android OS due to improper validation of array index.
Memory corruption in HAB Memory management due to broad system privileges via physical address.
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported vers
Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range.
Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentia
Improper Access Control in SMI handler vulnerability in Phoenix SecureCore™ Technology™ 4 allows SPI flash modification.
Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities.
Wasmer is a WebAssembly runtime that enables containers to run anywhere: from Desktop to the Cloud, Edge and even the br
Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Su
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are aff
The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote
Improper access control in the Intel(R) SUR software before version 2.4.8989 may allow an authenticated user to potentia
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user
Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF
Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary file
The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authen
Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0
M-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access an
Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (compon
Improper access control vulnerability in Buffalo network devices allows a network-adjacent attacker to obtain specific f
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authentica
Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision co
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incor
Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2,
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 20.0.0 and prio
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started