The server permits communication without any authentication procedure, allowing the attacker to initiate a session with
Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effe
bookstack is vulnerable to Improper Access Control
Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versio
Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI
Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Applicat
An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal
FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to Jupy
Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for
An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform versi
A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1). The Forgot Passwo
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQ
A vulnerability in the web-based messaging service interface of Cisco SD-WAN vManage Software could allow an unauthentic
A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, th
Nextcloud Mail is a mail app for the Nextcloud platform. A missing permission check in Nextcloud Mail before 1.4.3 and 1
ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct a
The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket t
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authen
An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the I
Nextcloud Server is a Nextcloud package that handles data storage. A vulnerability in federated share exists in versions
When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed o
EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vu
Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to acce
Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to acce
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privil
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privil
Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing
The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce whic
An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProte
This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. Thi
A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 an
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied Pos
Adobe Genuine Service version 6.6 (and earlier) is affected by an Improper Access control vulnerability when handling sy
Cscape (All versions prior to 9.90 SP4) is configured by default to be installed for all users, which allows full permis
An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalat
The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, su
An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to
Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.
Improper access control vulnerability in FactoryCameraFB prior to version 3.4.74 allows untrusted applications to access
A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authe
While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but ins
In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI w
sopel-channelmgnt is a channelmgnt plugin for sopel. In versions prior to 2.0.1, on some IRC servers, restrictions aroun
On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capab
While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Ap
An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SM
Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not proper
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started