In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.
Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is so
StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute ar
Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
A vulnerability classified as critical was found in SourceCodester Book Store Management System 1.0. This vulnerability
Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vul
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler
Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remote malicious user co
Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability.
Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability.
Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclos
x86: unintended memory sharing between guests On Intel systems that support the "virtualize APIC accesses" feature, a gu
A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. T
Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earl
A vulnerability has been identified in Mendix Runtime V7 (All versions < V7.23.29), Mendix Runtime V8 (All versions < V8
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.5.0 but before
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access priv
Improper access controls in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactp
An authenticated user with admin privileges may be able to terminate any process on the system running Elcomplus SmartIC
A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resu
NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to
An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Mana
Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and
Improper access control vulnerability in ContactsDumpActivity of?Contacts Provider prior to version 12.7.59 allows attac
Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 al
AppLock version 7.9.29 allows an attacker with physical access to the device to bypass biometric authentication. This is
bookstack is vulnerable to Improper Access Control
An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC
Improper Access Control in Pypi calibreweb prior to 0.6.16.
The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclo
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29). When returning the
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.27), Mendix Applications
A denial of service vulnerability exists in the cgiserver.cgi Upgrade API functionality of Reolink RLC-410W v3.0.0.136_2
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when pub
fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams featu
Improper Access Control in GitHub repository publify/publify prior to 9.2.8.
richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.
A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified C
Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authentica
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.5. An app may be able to
IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they shou
Dell Hybrid Client below 1.8 version contains a guest user profile corruption vulnerability. A WMS privilege attacker co
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started