OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to an improper access con
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval
A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be do
In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to c
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETG
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem
A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allo
A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that cou
A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal informat
Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allow
Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authentic
Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 an
Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and e
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module
A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated,
Philips SureSigns VS4, A.07.107 and prior does not restrict or incorrectly restricts access to a resource from an unaut
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow a
A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time
Baxter ExactaMix EM 2400 versions 1.10, 1.11, 1.13, 1.14 and ExactaMix EM1200 Versions 1.1, 1.2, 1.4 and 1.5 does not re
A vulnerability in the file system permissions of Cisco IOS XE Software could allow an authenticated, local attacker to
In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated discl
A vulnerability in an access control mechanism of Cisco Cyber Vision Center Software could allow an unauthenticated, rem
A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unaut
If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP h
Improper access control vulnerability in masvc.exe in McAfee Agent (MA) prior to 5.6.4 allows local users with administr
Adobe Acrobat Reader for Android version 20.6.2 (and earlier) does not properly restrict access to directories created b
There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9
A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow
A vulnerability in the web application of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthentica
A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Ci
A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Thr
A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation ha
Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.
If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabl
A vulnerability in the 802.1X feature of Cisco Catalyst 2960-L Series Switches and Cisco Catalyst CDB-8P Switches could
A vulnerability in Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9800 Series Routers could allow an unaut
The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings suc
A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share
This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.
A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Direc
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote a
A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote a
A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticat
Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earli
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authentic
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identi
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started