An issue was discovered in Rawchen blog-ssm v1.0 allows an attacker to obtain sensitive user information by bypassing pe
Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for
Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.
LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature. T
A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This aff
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a
XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-L
Azure Machine Learning Information Disclosure Vulnerability
Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to l
Improper Access Control in GitHub repository francoisjacquet/rosariosis prior to 10.9.3.
Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deacti
DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.3
Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a us
Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Acti
GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8
GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.
Microsoft SharePoint Server Information Disclosure Vulnerability
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 22.0.0 and prio
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of Op
The controller responsible for setting the logging level does not include any authorization checks to ensure the user is
SiberianCMS - CWE-284 Improper Access Control Authorized user may disable a security feature over the network
A flaw exists in FlashBlade Purity (OE) Version 4.1.0 whereby a user with privileges to extend an object’s retention per
A flaw exists in FlashArray Purity wherein under limited circumstances, an array administrator can alter the retention l
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.
An improper access control vulnerability in Fortinet FortiOS 7.2.0 - 7.2.4 and 7.4.0 allows an attacker to access a rest
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve
The application suffers from improper access control when editing users. A user with read permissions can manipulate
Azure DevOps Server Spoofing Vulnerability
journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability
Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the vari
In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be abl
The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_r
A vulnerability has been found in ghostlander Halcyon and classified as critical. Affected by this vulnerability is the
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: Internal Operations). Supported version
A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. Affected by this v
A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been rated as critical. Affected by this issue
A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been declared as critical. Thi
A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been declared as critical. Thi
Users with only access to launch VDA applications can launch an unauthorized desktop
A vulnerability was found in Ruijie RG-EW1200G 1.0(1)B1P5. It has been declared as critical. Affected by this vulnerabil
Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (compon
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an unprivileged regular u
Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to poten
Improper access control in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of s
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit openin
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.34), Mendix Applications
Improper access control for some Intel Unison software may allow a privileged user to potentially enable escalation of p
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started