A vulnerability was discovered in Management component of Avaya Equinox Conferencing that could potentially allow an una
AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are a
Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and d
Improper access control vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrar
WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a n
Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control table
An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessi
A vulnerability in the fabric infrastructure VLAN connection establishment of Cisco Nexus 9000 Series Fabric Switches in
An authentication bypass vulnerability in the Juniper Networks Paragon Active Assurance Control Center may allow an atta
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulne
Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wir
A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have th
Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Opera
An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, th
An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. Any SIM card used with the device canno
A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execut
Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data expos
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETG
Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User
A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users exter
The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not ensure that the requested property to be de
The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user maki
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-5
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known a
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software all
A skilled attacker with physical access to the affected device can gain access to the hard disk drive of the device to c
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrie
kimai2 is vulnerable to Improper Access Control
An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable t
The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status
Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges.
A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were
Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RC
A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileg
A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all version
When the "Intrusion Detection Service" (IDS) feature is configured on Juniper Networks MX series with a dynamic firewall
A vulnerability in the IPv6 traffic processing of Cisco IOS XR Software and Cisco NX-OS Software for certain Cisco devic
A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthent
A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remot
A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Ro
Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower T
Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, wh
An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 al
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins
Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action wi
An improper access control vulnerability in ScreenOffActivity in Samsung Notes prior to version 4.2.04.27 allows untrust
Improper access control vulnerability in Cameralyzer prior to versions 3.2.1041 in 3.2.x, 3.3.1040 in 3.3.x, and 3.4.421
The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constr
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started