The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access
A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attac
The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the
A vulnerability in the Local Packet Transport Services (LPTS) programming of the SNMP with the management plane protecti
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an access control
The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline
SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read som
A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) a
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause a
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause l
Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in w
A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adapt
Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically prox
A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated,
A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric
NVIDIA camera firmware contains a difficult to exploit vulnerability where a highly privileged attacker can cause unauth
In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other use
A vulnerability in the fabric infrastructure file system access control of Cisco Nexus 9000 Series Fabric Switches in Ap
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to re
A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar o
A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software could allow an authen
A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to gain access to sen
A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addr
Adobe Connect version 11.2.1 (and earlier) is affected by an Improper access control vulnerability that can lead to the
A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenti
A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-leve
Improper Access Control vulnerability in web service of Secomea SiteManager allows local attacker without credentials to
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthor
The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a times
The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrar
The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumb
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX act
The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX
The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector se
Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1
bookstack is vulnerable to Improper Access Control
snipe-it is vulnerable to Improper Access Control
The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as c
An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP information without prope
An Improper Access Control vulnerability in the logging component of Bitdefender Endpoint Security Tools for Windows ver
Improper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview.
Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which
Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can u
Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.
An open port used for debugging in SWARCOs CPU LS4000 Series with versions starting with G4... grants root access to the
A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SEL
This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers
IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and p
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV1
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started