Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora i
An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting fr
Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of
A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR
OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order t
Nextcloud is an Open Source private cloud software. Versions 24.0.4 and above, prior to 24.0.7, and 25.0.0 and above, pr
An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting
Nextcloud richdocuments is a Nextcloud app integrating the office suit Collabora Online. In affected versions the secure
Nextcloud server is an open source home cloud implementation. In affected versions users that should not be able to down
Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client sid
Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of
Improper access control in the Intel(R) Ethernet Controller RDMA driver for linux before version 1.9.30 may allow an una
An issue was discovered in Zebra Enterprise Home Screen 4.1.19. By using the embedded Google Chrome application, it is p
Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12
A malicious user can cause log files to be written to a directory that they do not have permission to write to.
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6
The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2,
Improper access control vulnerability in BixbyTouch prior to version 3.2.02.5 in China models allows untrusted applicati
A vulnerability exists in the ClearPass OnGuard Ubuntu agent that allows for an attacker with local Ubuntu instance acc
Code Sector TeraCopy 3.9.7 does not perform proper access validation on the source folder during a copy operation. This
A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious loca
Windows Group Policy Security Feature Bypass Vulnerability
A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this
A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this iss
Windows Kernel Information Disclosure Vulnerability
Improper access control in the Intel Support android application all verions may allow an authenticated user to potentia
ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows bef
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constr
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_requir
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compa
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_template
Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without u
Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
Improper Access Control in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (
vantage6 is privacy preserving federated learning infrastructure. The endpoint /api/collaboration/{id}/task is used to c
Improper access control for some Intel Unison software may allow an authenticated user to potentially enable escalation
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is a
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versio
An issue was discovered in Siren Investigate before 12.1.7. There is an ACL bypass on global objects.
Discourse is an open source discussion platform. The embeddable comments can be exploited to create new topics as any us
Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp. By sending a spe
An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registr
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservic
Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerabili
A vulnerability was found in Twister Antivirus 8.17. It has been declared as critical. This vulnerability affects the fu
Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authenticatio
SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowi
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started