Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-284

MITRE ↗

CWE-284

877
CRITICAL
2,593
HIGH
2,830
MEDIUM
289
LOW
6,696 CVEs · Page 110/134
4.4
CVE-2023-3099

A vulnerability classified as critical was found in KylinSoft youker-assistant on KylinOS. Affected by this vulnerabilit

4.4
CVE-2023-21518

Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications

4.4
CVE-2023-43072

Dell SmartFabric Storage Software v1.4 (and earlier) contains an improper access control vulnerability in the CLI. A lo

4.4
CVE-2023-36722

Active Directory Domain Services Information Disclosure Vulnerability

4.4
CVE-2023-44248

An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007

4.4
CVE-2023-43089

Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malic

4.3
CVE-2014-125054

A vulnerability classified as critical was found in koroket RedditOnRails. This vulnerability affects unknown code of th

4.3
CVE-2022-4703

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_

4.3
CVE-2022-4705

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_

4.3
CVE-2022-4708

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_c

4.3
CVE-2022-4709

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_

4.3
CVE-2022-4711

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_mega_menu_

4.3
CVE-2022-45164

An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user

4.3
CVE-2022-46890

Weak access control in NexusPHP before 1.7.33 allows a remote authenticated user to edit any post in the forum (this is

4.3
CVE-2023-24058

Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId

4.3
CVE-2022-2259

In affected versions of Octopus Deploy it is possible for a user to view Workerpools without being explicitly assigned p

4.3
CVE-2023-23575

Improper access control vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker to bypass

4.3
CVE-2021-44465

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated att

4.3
CVE-2023-2674

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.

4.3
CVE-2023-2901

A vulnerability was found in NFine Rapid Development Platform 20230511. It has been declared as problematic. Affected by

4.3
CVE-2023-2902

A vulnerability was found in NFine Rapid Development Platform 20230511. It has been rated as problematic. Affected by th

4.3
CVE-2023-2903

A vulnerability classified as problematic has been found in NFine Rapid Development Platform 20230511. This affects an u

4.3
CVE-2020-36699

The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks

4.3
CVE-2021-4364

The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check

4.3
CVE-2023-28810

Some access control/intercom products have unauthorized modification of device network configuration vulnerabilities. At

4.3
CVE-2023-3786

A vulnerability classified as problematic has been found in Aures Komet up to 20230509. This affects an unknown part of

4.3
CVE-2023-4183

A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as problematic. This vul

4.3
CVE-2023-20237

A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access intern

4.3
CVE-2023-39972

Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized users to cre

4.3
CVE-2023-39973

Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal

4.3
CVE-2023-36638

An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0

4.3
CVE-2023-5916

A vulnerability classified as critical has been found in Lissy93 Dashy 2.1.1. This affects an unknown part of the file /

4.3
CVE-2023-5976

Improper Access Control in GitHub repository microweber/microweber prior to 2.0.

4.3
CVE-2023-47865

Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post.

4.3
CVE-2023-6202

Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker w

4.3
CVE-2023-45210

Pleasanter 1.3.47.0 and earlier contains an improper access control vulnerability, which may allow a remote authenticate

4.3
CVE-2023-49874

Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest t

4.3
CVE-2023-6761

A vulnerability, which was classified as problematic, has been found in Thecosy IceCMS up to 2.0.1. This issue affects s

4.3
CVE-2023-6773

A vulnerability has been found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affec

4.3
CVE-2019-25157

A vulnerability was found in Ethex Contracts. It has been classified as critical. This affects an unknown part of the fi

4.3
CVE-2023-7055

A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. Affected is an u

4.2
CVE-2023-28443

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_

4.1
CVE-2023-21457

Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Blu

4.1
CVE-2023-2183

Grafana is an open-source platform for monitoring and observability. The option to send a test alert is not available

4.1
CVE-2023-50706

A user without administrator permissions with access to the UC500 windows system could perform a memory dum

4.0
CVE-2023-21442

Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.0

4.0
CVE-2023-21447

Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access info

4.0
CVE-2023-21463

Improper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in A

4.0
CVE-2023-21495

Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install

4.0
CVE-2023-20267

A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially by

Frequently Asked Questions

What is CWE-284?

CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-284?

There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.

How can I protect against CWE-284 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.

Detect CWE-284 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.

Get Started