Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-284

MITRE ↗

CWE-284

877
CRITICAL
2,593
HIGH
2,830
MEDIUM
289
LOW
6,696 CVEs · Page 104/134
8.1
CVE-2023-22618

If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users

8.1
CVE-2023-26205

An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions,

7.9
CVE-2022-40964

Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user

7.8
CVE-2022-36443

An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The device allows the administrator to lock some communi

7.8
CVE-2023-20927

In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypas

7.8
CVE-2023-24485

Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM o

7.8
CVE-2023-1489

A vulnerability has been found in Lespeed WiseCleaner Wise System Monitor 1.5.3.54 and classified as critical. Affected

7.8
CVE-2023-20065

A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, lo

7.8
CVE-2023-28051

Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attack

7.8
CVE-2023-28246

Windows Registry Elevation of Privilege Vulnerability

7.8
CVE-2023-26406

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Acce

7.8
CVE-2023-26408

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Acce

7.8
CVE-2023-25496

A privilege escalation vulnerability was reported in Lenovo Drivers Management Lenovo Driver Manager that could allow a

7.8
CVE-2023-24905

Remote Desktop Client Remote Code Execution Vulnerability

7.8
CVE-2021-25749

Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.

7.8
CVE-2023-21670

Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.

7.8
CVE-2023-33155

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

7.8
CVE-2022-43702

When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can mod

7.8
CVE-2023-20224

A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an a

7.8
CVE-2023-32477

Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-

7.8
CVE-2023-36725

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2023-36790

Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability

7.8
CVE-2023-41772

Win32k Elevation of Privilege Vulnerability

7.8
CVE-2023-31019

NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation

7.8
CVE-2023-28397

Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated to potential

7.8
CVE-2023-49694

A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed c

7.8
CVE-2023-7025

A vulnerability was found in KylinSoft hedron-domain-hook up to 3.8.0.12-0k0.5. It has been declared as critical. This v

7.7
CVE-2023-22487

Flarum is a forum software for building communities. Using the mentions feature provided by the flarum/mentions extensio

7.7
CVE-2023-21985

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affecte

7.7
CVE-2023-30768

Improper access control in the Intel(R) Server Board S2600WTT belonging to the Intel(R) Server Board S2600WT Family with

7.7
CVE-2023-31199

Improper access control in the Intel(R) Solid State Drive Toolbox(TM) before version 3.4.5 may allow a privileged user t

7.7
CVE-2023-39962

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 19.0.0 and prio

7.6
CVE-2022-47648

An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring an

7.6
CVE-2022-39946

An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions

7.6
CVE-2023-35927

NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform

7.6
CVE-2022-34453

Dell XtremIO X2 XMS versions prior to 6-4-1.11 contain an improper access control vulnerability. A remote read only use

7.5
CVE-2022-43494

An unauthorized user could be able to read any file on the system, potentially exposing sensitive information.

7.5
CVE-2022-46331

An unauthorized user could possibly delete any file on the system.

7.5
CVE-2023-21849

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java utils). Supported vers

7.5
CVE-2023-21850

Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: E-Business Collections

7.5
CVE-2023-21851

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Support

7.5
CVE-2023-21852

Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Setup). Supported versio

7.5
CVE-2023-21853

Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Synchronization). Suppo

7.5
CVE-2023-21854

Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Core Components). Supported ve

7.5
CVE-2023-21855

Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Pocket Outlook Sync(Pocke

7.5
CVE-2023-21857

Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Auomated Test Suite).

7.5
CVE-2023-21893

Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server. Supported versions that are aff

7.5
CVE-2023-22339

Improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticate

7.5
CVE-2020-22655

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n

7.5
CVE-2023-22960

Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.

Frequently Asked Questions

What is CWE-284?

CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-284?

There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.

How can I protect against CWE-284 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.

Detect CWE-284 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.

Get Started